ASOS customers get "hacked" message via Snowflake breach
ASOS customers received a startling push notification on October 6 claiming the online fashion retailer had been “hacked” through a Snowflake compromise. The alert looked like a legitimate ASOS message, but it carried a threat: engage with the attackers or see the data leaked.

A Threat Signed ‘xuanyewengateway’

The notification read: “Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.” It also included a link to a Telegram channel. DPO refers to a data protection officer, a role mandated by GDPR for UK and EU organizations.

ASOS quickly confirmed unauthorized activity. The company said its investigation was “involving third-party platforms that we use to communicate with customers” and that it moved immediately to restrict access to those notification platforms.

Investigators currently believe basic personal information, such as names and contact details, may have been accessed. ASOS says payment-card information and account passwords were not affected, and the ‘Xuanye Group’ administrator in the linked Telegram channel also claimed payment data was untouched. The website and app remain operational, overall business operations are unaffected, and ASOS says it holds cybersecurity insurance with a major global provider.

Snowflake Says Its Platform Wasn’t Breached

Snowflake, the cloud data platform ASOS uses to store and manage large datasets, opened its own investigation. A spokesperson said: “At this time, we can report that we have found no compromise of the Snowflake platform.”

Cloud platforms are frequent targets. In May 2024, stolen credentials were used against Snowflake tenants that lacked multifactor authentication. In August 2026, security researchers also found a critical script injection vulnerability in a Snowflake GitHub repository.

Security researchers are split on how serious this is. Jake Moore, a global cybersecurity advisor at ESET, warned that a confirmed breach could be “one of the most visible hacks in history,” noting that sending push notifications suggests significant access to ASOS’s connected systems. Pieter Arntz, a senior malware intelligence researcher at Malwarebytes, pointed to ASOS’s use of Simon AI for marketing, which runs on Snowflake, as a possible indirect route to the data. Michele Campobasso, a senior security researcher at Forescout, believes the message signals the threat actor is planning more attacks.

What ASOS Customers Should Do

Experts advise ASOS app users to take a few simple precautions:

  • Do not click the link in the notification
  • Do not engage with the Telegram account
  • Change your ASOS password as an extra layer of protection

On the company side, Kamran Bahdur, CIO at FLR Spectron, said ASOS must prioritize reviewing Snowflake audit and authentication logs, and that any engagement with the threat actor should involve legal, regulatory, and law enforcement partners. The incident underlines how hard it is for companies to secure an extensive third-party vendor ecosystem.

Hashlytics Take

ASOS’s own wording deserves a closer read. It points to the tools used to message customers, not to a breach of its core retail systems, which fits Arntz’s indirect-connection theory and would explain how a Snowflake denial and an ASOS admission can both be true. If that holds, the lesson isn’t another Snowflake headline. It’s that marketing stacks sit on top of customer data with far less scrutiny than core databases. Until ASOS publishes its findings, treat the “fully compromised” claim as unverified, since attackers have every incentive to oversell.

Follow Hashlytics on Bluesky, Facebook, LinkedIn , Telegram and X to Get Instant Updates