Published: October 6, 2026 · Last updated: October 6, 2026
TL;DR: ASOS customers got a push notification today that wasn’t meant for them. It was addressed to the company’s own data protection officer and IT team, warning that hackers had “fully compromised” ASOS’s Snowflake cloud instance and threatening to leak data unless ASOS engaged with them. ASOS says names and contact details may have been exposed, but not payment information or passwords, and its stock dropped as much as 13% once the notification went public.

Around 10am UK time today, thousands of ASOS customers opened their phones to a push notification that read like it was never supposed to leave the building. “Dear ASOS DPO and IT,” it began, “we have fully compromised the Snowflake instance. Engage with us, or we will leak it.” A link pointed to a Telegram channel run by a group calling itself Xuanye Group, a name that, according to cybersecurity reporting, nobody in the industry seems to recognize. Whoever wrote the message was clearly talking to ASOS’s internal staff. They just didn’t bother making sure only internal staff would read it.
ASOS took about six hours to say anything official. When it did, the statement landed on the company’s Instagram Story rather than a press release: “We’re sorry that you may have received an unauthorised push notification from ASOS earlier today. Please disregard the notification and do not click or engage with the link it contained.” The company said it had restricted access to the systems involved and was working with internal and external specialists “as well as all relevant authorities.” Its bottom line for customers: basic personal information, meaning names and contact details, may have been accessed, but there’s no indication payment-card numbers or account passwords were touched.
Whether the hackers actually got into Snowflake itself is the part nobody outside the investigation can confirm yet. Charlotte Wilson of Check Point told the BBC the attackers may simply be trying to embarrass ASOS into responding, and stressed that the claimed Snowflake access hasn’t been verified. That distinction matters a lot here. Getting into the platform that pushes out customer notifications is a real security failure on its own, but it’s a different animal from getting into the database that holds transaction and demographic records. Snowflake has a track record that makes the name alone scary, including its role in the 2024 breach that hit Ticketmaster and dozens of other companies, so attaching it to any new incident does a lot of the fear-mongering work for free.
The market didn’t wait for clarity. ASOS shares fell more than 11%, with some reporting an intraday drop closer to 13%, before the company’s statement slowed the bleeding. That’s a steep reaction for an incident where the confirmed damage, so far, is limited to contact information. ASOS has about 17 million customers globally, and this is also a separate, unrelated matter from the credential-stuffing attack the company disclosed back in August, which exposed partial payment details for a smaller group of accounts. Investors and reporters conflating the two isn’t helping anyone get a clear picture of what actually happened today.
What makes this incident worth watching isn’t the scale of the data, which still looks relatively contained. It’s the delivery method. Hacking a company’s own trusted notification system and using it to broadcast your ransom demand to millions of customers is a cheap, effective way to force a public response regardless of how deep you actually got. Companies spend enormous effort locking down databases and payment systems while treating the pipes that send a “your order shipped” text as an afterthought. ASOS just found out the hard way that those pipes are part of the attack surface too, and the fix for distrust doesn’t come from a statement on an Instagram Story. It comes from proving, with specifics ASOS hasn’t given yet, exactly what the attacker could and couldn’t see.
Related: Denmark just suffered the biggest data breach in its history and a Pentagon records agency confirmed a breach affecting 3 million people.
Bottom Line: ASOS may have dodged a worst-case breach this time, but the attackers didn’t need to actually drain a database to hurt the company. They just needed access to the one system everyone already trusts to tell the truth. That’s a cheaper bar to clear than a full compromise, and more companies are going to find out the hard way that it’s the bar that matters.
Follow Teck Hustlers: Facebook · X · Instagram · LinkedIn · TikTok · Pinterest



