On October 6, customers of the popular online fashion retailer ASOS were surprised to receive a peculiar mobile notification claiming that the company had been hacked through a Snowflake compromise. This alarming message, which appeared to be a legitimate push notification from ASOS, read: “Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.” The message concluded with the signature ‘xuanyewengateway’ and included a link directing recipients to a Telegram channel.
The term “DPO” stands for Data Protection Officer, an essential role within organizations that ensures compliance with regulations regarding personal data collection, storage, and protection. According to the General Data Protection Regulation (GDPR), any organization operating within the United Kingdom or the European Union is mandated to have a DPO on staff.
Snowflake is a widely-used cloud-based data platform that allows businesses to store, manage, analyze, and share vast quantities of data efficiently. Unlike traditional data storage solutions that rely on physical servers, Snowflake enables organizations to centralize their data, granting accessibility from multiple systems and geographic locations. Unfortunately, the platform has been a target for cybercriminals seeking unauthorized access through various means, including compromises.
A notable incident involving Snowflake occurred in May 2024, when hackers employed stolen credentials—obtained via infostealer malware—to gain direct access to customer Snowflake tenants lacking multifactor authentication (MFA). More recently, in August 2026, security researchers at Wiz, a company under Google Cloud, uncovered a critical script injection vulnerability in one of Snowflake’s public repositories on GitHub. This discovery was made possible through the company’s HackerOne vulnerability disclosure program.
As of the latest updates, ASOS has not confirmed any compromise related to the notification that has been circulating among its customers.
### Experts Advocate for Vigilance Amid Potential ASOS Data Breach
In the wake of these troubling developments, cybersecurity experts are voicing their concerns regarding the implications of the alleged breach. Jake Moore, global cybersecurity advisor at ESET, emphasized that if the claims turn out to be true, it could represent “one of the most visible hacks in history” and could endanger a significant amount of customer data. He articulated that the act of sending a push notification to ASOS customers indicates that the hackers may have gained access to certain connected systems within ASOS but cautioned that this does not necessarily validate the full extent of their claims about data exposure.
By alerting ASOS app users directly, the threat actors seem to be applying pressure on the company, demonstrating the extent of their access, presumably to elicit some form of ransom. Pieter Arntz, a senior malware intelligence researcher at Malwarebytes, pointed out that ASOS employs Simon AI for its marketing operations, which relies on the Snowflake platform, although this connection remains indirect. He remarked, “It’s too early to ascertain how much ASOS customer data attackers could potentially access, but the implications are significant.”
Arntz further noted that any unauthorized access could yield a comprehensive profile of ASOS customers, including details on browsing behaviors, purchasing habits, locations, and loyalty status—information that could be exploited for various malicious purposes. Michele Campobasso, a senior security researcher at Forescout, added that the brevity of the hacker’s message and lack of substantial information suggest an intent to execute further attacks.
In light of these circumstances, experts advise ASOS app users to refrain from clicking on the link provided in the suspicious notification and to avoid engaging with the associated Telegram account. Additionally, to bolster their security, customers are encouraged to change their passwords as a precautionary measure.
### Urgency for Investigation and Customer Safeguards
While numerous facts surrounding the incident still need to be confirmed, Kamran Bahdur, Chief Information Officer at cybersecurity resilience firm FLR Spectron, urged that the messages from the threat actors “should be taken seriously and treated as a potential extortion attempt.” He further highlighted the urgent need for ASOS to verify whether there has been unauthorized access, scrutinize Snowflake audit logs, evaluate any data exposure, and adhere to established incident response protocols.
Bahdur stressed that any decision regarding engagement with the hackers should occur only after consultation with legal, regulatory, and law enforcement partners. He also advised ASOS personnel to avoid direct communication with the threat actors unless it is part of an agreed-upon strategy finalized with legal representatives.
At this stage, the broader implications of the alleged hack on customer privacy and data security remain a pressing concern, prompting further calls for vigilance among ASOS customers and a thorough investigation by company officials. Infosecurity has reached out to both ASOS and Snowflake for their official comments on the unfolding situation.
