ASOS customers across the UK were alarmed on Monday after the retailer’s app sent a push notification claiming its Snowflake database had been “fully compromised,” with the message directing recipients to a Telegram channel and threatening to leak the data unless the company’s security team engaged with the alleged attackers.
ASOS customers were left unsettled on 6 October after receiving an unexpected notification through the retailer’s official app, warning that a database system had been “fully compromised” and threatening to leak the information unless the company responded. The message, which appeared to come directly from ASOS’s own notification infrastructure, directed recipients to a Telegram group named Xuanye Gateway. Because the alert was sent through ASOS’s genuine app rather than via a separate phishing message, it appears likely that whoever sent it had gained access to a system within the company itself, rather than simply impersonating the brand.
What the notification said
The message read in full: “Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.” The reference to “DPO” is understood to relate to ASOS’s Data Protection Officer, while the message also directly addressed the company’s IT department by name. Given this framing, the notification appears to represent an attempt at extortion aimed at ASOS’s internal security team, rather than a message intended for ordinary shoppers, even though it was customers who ultimately received it on their devices.
The notification included a link to a Telegram group, a messaging platform offering end-to-end encryption and self-destructing messages. Unlike many messaging apps, Telegram is not tied to a phone number, a feature that has previously made it attractive to criminals seeking to communicate securely, since built-in timers can automatically delete messages and media from both sender and recipient devices, leaving little trace. The specific Telegram group referenced in the ASOS notification was reportedly created on 6 October, shortly before the alert began appearing on customers’ phones across the country.
Public reaction and market impact
Shoppers took to social media within moments of receiving the notification, with many seeking reassurance that others had received the same message, while others warned fellow users not to click the link. ASOS’s share price reportedly fell by more than 4 per cent as news of the incident spread, suggesting investors were reacting to the possibility of a serious cybersecurity breach at the company.
As of now, ASOS has not publicly confirmed that its Snowflake database environment was actually compromised. The notification should therefore be treated as an allegation of a cyberattack rather than verified confirmation that ASOS’s systems or customer data have been breached.
How the attack may have been carried out
If confirmed, the method used to distribute the message would mark a significant escalation compared with typical phishing attempts. Rather than sending a fraudulent email or text message designed to imitate ASOS, the alleged attackers appear to have used the company’s own push-notification system to deliver their message directly to customers’ devices. Such access, if verified, would indicate a breach extending into part of ASOS’s internal notification infrastructure, rather than simply an external attempt to deceive customers.
A separate confirmed breach earlier this year
This is not the first cybersecurity incident to affect ASOS in 2026. In July, ASOS US Sales reported a separate, confirmed data breach involving unauthorised access to its systems between 28 and 29 July, using credentials that had apparently been obtained from outside the company. That earlier breach is reported to have affected approximately 138,828 individuals, according to filings made across various US states.
Information potentially exposed in the July incident included customers’ names, email addresses, delivery and billing addresses, telephone numbers, dates of birth, and limited payment card details, including the cardholder’s name, the last four digits of the card, and its expiry date. That breach was described at the time as involving credential-based unauthorised access, rather than evidence that attackers had gained broader control over ASOS’s wider systems.
Possible link to a separate Snowflake vulnerability
Separately, the cloud data platform Snowflake disclosed a security vulnerability of its own in September 2026, affecting some of its database drivers. The flaw could potentially cause sensitive authentication information and encryption keys to be exposed within diagnostic logs, and Snowflake subsequently released patched versions of the affected software to address the issue. However, there is currently no evidence linking that particular Snowflake vulnerability to Monday’s incident involving ASOS, and the two events should be treated as separate until any connection is confirmed.
