Cyber Security Data Breach Cloud Security Incident Response

ASOS Cyber Incident: What We Know About the Snowflake Claim

An ASOS app notification claims attackers compromised a Snowflake instance. The story is still developing, so here is what is known, what remains unverified and what UK businesses should take from it.

Written by Jordan Stewart Cyber security and incident response
ASOS Cyber Incident: What We Know About the Snowflake Claim
Developing story · Status at the time of writing

This article was prepared just after 10:00 BST on the 6th of October 2026, and the position may change quickly. We will update it when ASOS or another authoritative source publishes further evidence.

The short answer

ASOS appears to be dealing with a cyber incident involving its customer notification channel, with a possible Snowflake data breach associated with it too. The notification is real, but at the time of writing the wider claims about access to ASOS data remain unverified.

Just before 10am, ASOS customers - and indeed, a few of the team in the office - appear to have received a push notification headed "ASOS HACKED". The message, addressed to the company's data protection and IT teams, claims that an attacker has "fully compromised" an ASOS Snowflake instance and threatens to leak information unless ASOS makes contact. It directs recipients to Telegram. We have deliberately not followed or reproduced that destination, and encourage anyone else who received it to exercise caution.

At the time of writing, the claim has yet to be publicly confirmed, although it appears genuine. We have found no statement about it in the ASOS corporate newsroom, and no authoritative evidence showing what was accessed, whether data was copied or whether any systems were encrypted. A number of public posts on social media from people who received the notification support that the message was distributed, but they don’t verify the attacker's wider claim.

So the honest answer is that ASOS appears to be dealing with a cyber incident involving its customer notification channel, with a possible Snowflake data breach associated with it too.

What happened

The first visible sign is perhaps an unusual one, but it leans into the authority and existing channels that ASOS utilise - it’s the fourth push notification that I’ve personally received since Saturday, so on first glance, it just appeared to be yet another promotion.

Screenshot of the ASOS HACKED push notification received by ASOS customers on 6 October 2026
The notification received by ASOS customers on the morning of 6 October 2026. We have not reproduced or followed the Telegram destination included in the message.

Often, the first sign is something such as a website being taken down, a leak-site post or a company statement, rather than an app push notification containing the attacker's message unfiltered. These notifications are normally sent through a trusted communications system, so if the alert came through ASOS's legitimate app channel, it appears likely that somebody may have gained access to the process, credentials or service used to send it.

That doesn’t, as yet, tell us how far that gained access extends, and that may unfold over the coming weeks and months ahead. The notification system could be the whole incident, one part of a wider compromise, or a separate route used to amplify an unproven claim. In a live investigation, those possibilities need evidence, not guesswork.

What the notification proves and what it does not

What appears confirmed

An unauthorised message appears to have reached customers through the ASOS notification channel.

What remains unverified

The notification alone does not prove that attackers control ASOS data, accessed every database in Snowflake or can carry out the threatened leak.

The notification alone is evidence enough that an unauthorised message appears to have reached customers. It is not, by itself, proof that the sender controls ASOS data, has accessed every database in a Snowflake account or can carry out the threatened leak.

Remember, also, attackers benefit from urgency. A dramatic message such as that can create public pressure before the victim has had time to establish what happened.

Is this ransomware?

Possibly, but the notification alone doesn’t provide enough evidence to say so. Traditional ransomware encrypts systems or files and demands payment for their release. Many modern extortion groups also steal data and threaten to publish it, sometimes without deploying encryption at all.

The message described by recipients is closer to a data theft and extortion claim. That may later form part of a ransomware incident, but nothing - as yet - currently shows encryption, operational lockout or a ransom amount. The site is still live at the time of writing, for instance, so for now, "cyber incident" and "alleged data extortion" are the more relevant descriptions.

What is Snowflake?

Snowflake is a cloud data platform used to store, analyse and share large volumes of business information. A compromise of a customer account could expose valuable data without taking a website offline, which is one reason data extortion can be difficult for customers to spot from the outside.

There is also somewhat relevant history, though it’s not related to ASOS. In 2024, Mandiant investigated a campaign targeting Snowflake customer accounts, finding that attackers used credentials stolen from customer environments. The incidents it examined were not traced to a breach of Snowflake's own enterprise systems, but rather accounts without multi-factor authentication, long-lived credentials and the absence of network allow lists contributed to successful compromises.

It’s still way too soon to understand whether the current ASOS incident involves stolen credentials, social engineering, an integration, a service account, a supplier, a product vulnerability or no Snowflake access at all.

A separate ASOS incident from July

ASOS US Sales LLC disclosed a separate incident involving customer accounts on the 28th and 29th of July 2026. In an official notice filed with the Washington Attorney General, ASOS said attackers used credentials obtained outside the company in a credential-stuffing attack. The filing states that 138,828 customers were affected and that the company blocked affected accounts and imposed password resets.

That event, while confirmed, is materially different from the new Snowflake claim, and there’s no reliable evidence linking the two, so they should be treated as separate unless ASOS or investigators say otherwise.

What UK businesses should take from this

The most useful lesson is to notice how many parts of a modern business can carry trust: a cloud database, an identity provider, a service account, a customer app and the platform that sends notifications. An attacker only needs one successful route that reaches something valuable or visible.

01

Know what sits outside the traditional network

List cloud platforms, customer communications tools and integrations alongside servers and laptops. Record who owns them, what data they can reach and how access is granted.

02

Treat identity as the control plane

Require phishing-resistant MFA where available, remove dormant accounts and review service accounts, API keys and integration secrets.

03

Monitor actions that matter

Unexpected notifications, bulk exports, new administrators, unusual logins and changed integrations should create useful alerts with named owners.

04

Make the first hour repeatable

Revoke active sessions, rotate affected credentials and preserve relevant logs before normal retention windows remove them.

05

Start the data protection assessment promptly

Start an incident log immediately and assess whether personal information is involved while the investigation develops.

06

Communicate with precision

Say what is confirmed, what is still being investigated and when the next update will come. Don’t repeat attacker claims as established fact.

Know what sits outside the traditional network

List cloud platforms, customer communications tools and integrations alongside servers and laptops. Record who owns them, which data they can reach, and how access is granted.

Treat identity as the control plane

Require phishing-resistant MFA where available, remove dormant accounts, restrict privileged access and review service accounts, API keys and integration secrets. Human users are only part of the identity estate.

Monitor actions that matter

An unexpected notification, bulk export, new administrator, unusual login or changed integration should create a useful alert with a named owner. Logging that nobody reviews is an archive, not a defence.

Make the first hour repeatable

Revoke active sessions, rotate affected credentials and preserve relevant logs before normal retention windows remove them. Record decisions and timestamps as the facts develop.

Bring technical, legal, data protection, insurance, leadership and communications contacts into the response early. The NCSC recommends that incident plans include key contacts, escalation criteria, regulatory guidance and links to business continuity and communications plans.

Start the data protection assessment promptly

The UK GDPR does not require every incident to be reported, but a notifiable personal data breach should be reported to the ICO without undue delay and, where feasible, within 72 hours of becoming aware. Start the incident log immediately, even while the scope is unclear. ICO guidance explains the reporting threshold and timetable.

Communicate with precision

Say what is confirmed, what is being investigated and when the next update will come. Avoid repeating attacker claims as fact. A rushed statement can create a second problem that lasts longer than the technical incident.

What to do if you received the notification

For ASOS customers

Receiving the notification does not, by itself, mean your individual account or phone has been compromised. Don’t open the Telegram link or contact the sender, and use established ASOS channels for any updates.

Don't follow the attacker link

Check ASOS updates through its official website, app store listing or established customer-support routes.

Check password reuse

Make sure your ASOS password is unique. If you use it elsewhere, change those accounts too.

Watch for follow-on phishing

Be cautious about unexpected messages involving refunds, orders, password resets or supposed breach protection.

Review account activity

Check account and payment activity and report anything you do not recognise through official channels.

In short, nothing. Receiving the alert doesn’t mean your individual ASOS account or phone has been compromised, but don’t open the Telegram link or contact the sender.

Check for updates through ASOS's official website, app store listing, or established customer support routes rather than links sent in messages.

Make sure your ASOS password is unique. Change it on the official site if you reuse it elsewhere, and change every other account that uses the same password.

Be alert to convincing follow-on phishing attempts that appear genuine, which could be about refunds, order issues, password resets, or "breach protection". Go directly to the service involved on their site, rather than opening links sent to you.

Review account and payment activity and report anything you do not recognise through official channels.

The next update matters

ASOS now has the difficult job every organisation faces in a developing incident: establish the facts, contain access, understand what data may be involved and communicate before speculation fills the gap.

For everyone else, this is a useful time to check whether the same steps would be clear inside your own business. Who can send messages to every customer? Which cloud accounts hold sensitive data? Can you revoke access quickly? Who decides when the DPO, the insurer, or the board needs to be involved?

We will update this article as ASOS ,or other authoritative sources provide more information. Until then, caution is more useful than certainty.

ASOS cyber incident FAQs

Has ASOS been hacked?

An unauthorised push notification appears to have been distributed through the ASOS app, so there is evidence of a cyber incident involving a customer communications channel. At the time of writing, ASOS has not publicly confirmed the wider attacker claim about its Snowflake environment.

Has ASOS suffered a Snowflake data breach?

The notification claims an ASOS Snowflake instance was compromised, but that claim remains unverified at the time of writing. There is not yet authoritative evidence showing what data, if any, was accessed or copied.

What is Snowflake?

Snowflake is a cloud data platform used by organisations to store, analyse and share large volumes of business information. Access to a customer Snowflake environment can therefore be valuable to an attacker even if public websites remain online.

Is the ASOS incident ransomware?

There is not enough verified information to describe it as ransomware. The notification contains an apparent data-theft and extortion claim, but there is currently no public evidence of encryption, operational lockout or a specified ransom amount.

Does receiving the ASOS notification mean my account was hacked?

No. Receiving the push notification does not itself show that an individual ASOS account or phone was compromised. Customers should avoid the Telegram destination in the message and follow updates through established ASOS channels.

Should ASOS customers change their password?

Customers should make sure their ASOS password is unique. If the same password is used on other accounts, those reused passwords should be changed regardless of whether the current Snowflake claim is eventually confirmed.

Was ASOS breached earlier in 2026?

ASOS US Sales LLC disclosed a separate credential-stuffing incident affecting customer accounts in July 2026. There is currently no reliable evidence connecting that confirmed event with the developing October incident, so they should be treated separately.

Jordan Stewart
Jordan Stewart Fifosys insights, news and practical technology guidance for UK business leaders.
Next
Next

One phishing email and almost ten years of fallout: What the Manchester City story teaches every business about cyber risk