ASOS Hacked: App Push Notification Claims Snowflake Breach
ASOS customers found an unwelcome alert on their phones on Tuesday, October 6, 2026. A push notification titled "ASOS HACKED," sent through the official app, claimed attackers had "fully compromised" the retailer's Snowflake instance and threatened a leak unless ASOS made contact via Telegram. ASOS hasn't confirmed the incident, and the claims remain unverified.
Benediktas Kazlauskas
Last updated: Oct 06, 2026
4 min read

TL;DR
- ASOS app users received a push notification on October 6, 2026, claiming a full compromise of the retailer's Snowflake environment.
- The message was an extortion demand aimed at ASOS staff, but it was delivered to customers through the app's own notification channel.
- No public statement from ASOS and no independent confirmation of data theft were available at the time of publishing.
- The incident follows a separate ASOS account takeover disclosed in August 2026 that affected approx. 138,828 people in the US.
- Customers should avoid the Telegram link, change reused passwords, and treat any ASOS-branded messages with extra caution for now.
What happened
The notification arrived as a standard push alert from the ASOS app, with the ASOS logo and the app listed as the sender. Here's what it said, word for word:
“ASOS HACKED. Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.”
The message ended with a link to a Telegram account. We're not reproducing the handle here, and we'd strongly advise against opening it.
Two things stand out. First, the text isn't written for shoppers at all. It speaks directly to ASOS's data protection officer and IT department, which reads like a ransom note sent through the loudest channel the attackers could find. Second, the alert was pushed through ASOS's own app infrastructure. That part is confirmed by the notification itself: it arrived as an ASOS app alert, not as an SMS or email that could have been spoofed.
What we know and what we don't
It's worth separating the facts from the claims, because breach news tends to blur them within hours.
What's confirmed:
- A push notification with the content above was delivered through the ASOS app on October 6, 2026.
- It references a Snowflake instance and includes an extortion threat and a Telegram contact link.
What's unconfirmed:
- That attackers accessed ASOS's Snowflake environment, or what data it holds.
- How many customers, if any, are affected.
- Who is behind the message.
- How the attackers gained the ability to send push notifications.
Sending a push notification to an app's user base usually requires access to a push provider account, a customer engagement or marketing automation platform, or the credentials and API keys behind them. Those keys often live alongside other secrets in the same cloud tooling. If the attackers had that level of access, it would at least make broader access more plausible. It doesn't prove the Snowflake claim, though. Attackers regularly exaggerate what they've taken to increase pressure.
We found no public statement from ASOS and no independent reporting on the incident when this article went live. We'll update the post when that changes.
The Snowflake connection
Snowflake is a cloud data platform that many large companies use as a central warehouse for customer, order, and analytics data. The name carries weight in security circles because of the 2024 campaign that hit its customers.
In that campaign, Snowflake said it became aware of potentially unauthorized access to certain customer accounts on May 23, 2024. Mandiant tracked the attackers as UNC5537 and, together with Snowflake, notified 165 potentially exposed organizations. Victims included AT&T and Ticketmaster, Advance Auto Parts, and Neiman Marcus.
The key detail: according to Mandiant's investigation, the attackers didn't breach Snowflake's own systems. They logged into customer accounts with stolen usernames and passwords, some taken from contractors' computers, and those accounts had no multi-factor authentication turned on. Snowflake has since given administrators the option to enforce MFA.
There's currently no evidence connecting the ASOS claim to UNC5537 or to the 2024 campaign. We're including that history as context only. It shows that a "Snowflake compromise" usually means a compromised customer account on Snowflake, not a flaw in Snowflake itself, and that stolen credentials are the most common way in.
Not ASOS's first security headline this year
This is the second security incident tied to ASOS in 2026. In a breach notification dated August 21, 2026, ASOS US Sales LLC said it detected unusual activity on customer accounts on July 28. By the next day, the company determined that an unauthorized party had likely signed in using login credentials obtained outside ASOS, a classic credential stuffing pattern.
That incident affected 138,828 people, according to filings reported by state attorneys general. The exposed account details may have included names, email addresses, delivery and billing addresses, phone numbers, dates of birth, and linked social media account details. Limited card data was also listed: cardholder name, last four digits, and expiry date. ASOS blocked the affected accounts and forced password resets on July 29, then emailed customers on July 30.
Nothing published so far links the July account takeovers to today's notification. Still, two incidents in roughly ten weeks will put ASOS's credential and access controls under a brighter spotlight.
Why the push notification matters
Extortion groups have long pressured victims by contacting customers, journalists, or partners directly. Using the victim's own app to do it is a sharper move. It removes any doubt that the attackers have some foothold, and it makes the incident public before the company can shape the story.
It also damages a trusted channel. Customers are used to tapping ASOS notifications for sales and order updates. For a while, any message from the app, or anything claiming to be from ASOS, will deserve a second look. That's prime territory for follow-up phishing, both from the original attackers and from opportunists riding the headlines.
What should ASOS customers do now?
- Don't open the Telegram link. It's the attackers' contact channel, and there's nothing in it for customers.
- Change your ASOS password if you reused it anywhere, then update every account that shares it, starting with your email.
- Turn on MFA for your email, banking, and payment apps, since those protect everything else.
- Ignore unexpected messages asking you to "verify" your account, confirm payment details, or claim compensation.
- Check ASOS's real emails for the brand logo. ASOS uses BIMI, which shows its logo next to authenticated emails in supported inboxes.
- Watch your bank and card statements for unfamiliar charges.
- Wait for an official statement on asos.com or ASOS's verified channels before acting on any breach-related instructions.
If you keep a card saved in your ASOS account, consider removing it for now and entering payment details only at checkout, or paying through a digital wallet where available, since wallets typically don't pass your full card number to the retailer. Turn on instant transaction alerts in your banking app so unfamiliar charges stand out right away, and remember that most banks let you freeze a card in a few taps if something looks off. Spot a payment you don't recognize? Contact your bank immediately to block the card and order a replacement. While you're at it, check your ASOS account for changed delivery addresses or orders you didn't place.
These steps are suggestions based on standard breach hygiene, not instructions from ASOS.
What businesses can take away
Even before the facts settle, the pattern is familiar enough to act on:
- Enforce MFA on every data warehouse, cloud console, and SaaS admin account, with no exceptions for service or contractor logins.
- Treat push and messaging API keys as high-value secrets. Scope them tightly, rotate them, and alert on unusual send volumes.
- Monitor for your staff's and customers' credentials in infostealer logs and breach dumps.
- Give contractors managed devices or strict access policies. The 2024 Snowflake victims show how a single infected laptop can open the door.
- Rehearse incident communications, including what you'll say if attackers reach your customers first.
Bottom line
Right now, the only confirmed fact is that someone used ASOS's app to broadcast an extortion message. The Snowflake claim, the scope of any data theft, and the people behind it are all unverified. Expect more details once ASOS responds, and treat anything branded ASOS with healthy suspicion until then.
About the author

Benediktas Kazlauskas
Content & PR Team Lead
Benediktas is a content professional with over 8 years of experience in B2C, B2B, and SaaS industries. He has worked with startups, marketing agencies, and fast-growing companies, helping brands turn complex topics into clear, useful content.
Connect with Benediktas via LinkedIn.
All information on Decodo Blog is provided on an as is basis and for informational purposes only. We make no representation and disclaim all liability with respect to your use of any information contained on Decodo Blog or any third-party websites that may belinked therein.


