On Tuesday morning, ASOS customers using the retailer’s app received alarming notifications from hackers claiming to have compromised the company’s Snowflake data environment and threatening to leak information unless contacted.
- Hackers claim access to ASOS's Snowflake cloud data platform
- Threatening notification sent to thousands via app
- ASOS has yet to issue an official data breach statement
What happened
On the morning of October 6, 2026, many ASOS app users received an unsolicited notification from a hacker group claiming to have fully compromised ASOS’s Snowflake cloud instance. The message directly addressed ASOS’s Data Protection Officer and threatened to leak data if the company did not make contact through a Telegram link.
Users began reporting problems with the ASOS app shortly before 10AM according to monitoring services like Down Detector. Snowflake is a popular software-as-a-service platform used by many businesses to securely store and analyze their data in the cloud. The message suggests hackers accessed sensitive information through this platform, but ASOS has yet to issue any official confirmation or breach disclosure.
Why it matters
ASOS handles data for approximately 17 million customers across 150 countries, with a significant portion of its customer base in the UK and Europe. A breach of its data systems could expose sensitive personal and payment information, leading to financial fraud, identity theft, and reputational damage for the retailer.
Under UK data protection law, ASOS is obligated to report any data breaches to the Information Commissioner’s Office (ICO) within three days and notify affected customers if the breach poses a high risk. The absence of a formal response combined with public notifications of the compromise heightens concern about the scale and severity of the incident.
What to watch next
Stakeholders should monitor ASOS’s official communications closely for any confirmation of a breach, detailed incident reports, and remediation steps. The company’s timely transparency and compliance with regulatory requirements will be critical in managing fallout and restoring customer trust.
Additionally, cybersecurity observers will be watching for any public release of stolen data or follow-up attacks stemming from this incident. It underscores the ongoing risk challenges retailers face from cloud service vulnerabilities and the growing importance of robust data protection strategies.