Customers of online fashion retailer ASOS have received a strange mobile notification claiming the company has been hacked via a Snowflake compromise.
Appearing as a legitimate ASOS push notification, the message, issued on October 6, read: “Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.”
The message was signed ‘xuanyewengateway’ and provided a link to a Telegram channel.

DPO stands for data protection officer, the person appointed by an organization to oversee how personal data is collected, stored, used and protected. The General Data Protection Regulation (GDPR) requires any organization operating in the UK or the EU to have a DPO.
Snowflake is a cloud-based data platform that companies use to store, manage, analyze and share large amounts of data. Rather than keeping data on a company’s own physical servers, Snowflake provides cloud infrastructure that allows organizations to centralize data and access it from different systems and locations.
Cyber threat actors frequently attempt to gain unauthorized access to companies via Snowflake compromises.
The latest large-scale known incident affecting Snowflake occurred in May 2024, when threat actors used stolen credentials – harvested by infostealer malware – to log directly into customer Snowflake tenants that did not have multifactor authentication (MFA) enforced.
More recently, in August 2026, security researchers at Wiz, part of Google Cloud, discovered a critical script injection vulnerability in one of Snowflake’s public repositories on GitHub through the cloud service provider’s HackerOne vulnerability disclosure program.
ASOS has not confirmed any compromise at the time of publication.
Experts Warn of Potentially Extensive ASOS Data Breach
Commenting on the alleged breach of ASOS, Jake Moore, global cybersecurity advisor at ESET, warned that, if confirmed, it could be “one of the most visible hacks in history” and could “put a lot of customer data at risk.”
“The fact the hackers managed to send a push notification to customers suggests they have gained access to at least some of ASOS’s connected systems, but it doesn’t prove their full claims about the extent of the data breach,” he added.
“By broadcasting their breach directly to ASOS app users, the threat actors are likely trying to apply pressure to ASOS, showing how extensive their access is so they can leverage some sort of ransom.”
Pieter Arntz, senior malware intelligence researcher at Malwarebytes, highlighted that ASOS uses Simon AI for marketing, which runs on Snowflake, making the connection indirect.
“It’s too early to say how much ASOS customer data attackers could get their hands on, but the potential scope is significant,” he said.
“Any exposure could reveal a detailed customer picture, from browsing and buying habits to location and loyalty status. That’s valuable profiling data, though the connection alone doesn’t establish what attackers could actually access,” he added.
Additionally, Michele Campobasso, senior security researcher at Forescout, said he estimates that the message, and especially “the lack of any additional information and the (short) presentation of a group,” suggests that the threat actor is planning to claim more attacks.
"ASOS app users ought not to click on the link in the notification and avoid the engaging in the Telegram account. ASOS customers should also change their passwords for an extra layer of protection," he said.
Experts Urge Immediate Investigation and Customer Precautions
While there remain a number of facts still to be verified about the incident, Kamran Bahdur, CIO at cybersecurity resilience firm FLR Spectron, said the claims in the notification “should be taken seriously and treated as a potential extortion attempt.”
Bahdur noted that the immediate priority for ASOS will be to establish whether there has been any unauthorised access, review Snowflake audit and authentication logs, assess any data exposure and follow the incident response process.
“Any decision on engaging with the threat actor should be made with input from legal, regulatory and law enforcement partners,” he said.
He also highlighted that ASOS personnel should avoid direct engagement with the threat actor outside of an agreed response strategy vetted by legal representatives.
Infosecurity has contacted ASOS and Snowflake for comment.
Image credits: Koshiro K / chrisdorney / Shutterstock.com
