- ASOS customers got a push alert on October 6 claiming a Snowflake compromise. ASOS says unauthorized activity involved third-party platforms it uses to communicate with customers.
- The Snowflake link is the sender's claim and one researcher's indirect connection, not a confirmed cause. ASOS says names and contact details may have been accessed.
- Leaders should ask who can send messages in the company's name, and how customers would tell a real alert from a fake.
The message was the delivery method
A push notification is a message customers trust. It lands on their own phone under the retailer's name. On October 6, ASOS customers received one that carried a very different kind of content.
Infosecurity Magazine reported that the alert looked like a normal ASOS notification. It was addressed to ASOS's data protection officer and IT staff. It claimed the sender had "fully compromised" a Snowflake instance. It asked ASOS to engage with the sender or see the data leaked.
The sender signed it 'xuanyewengateway' and added a link to a Telegram channel.
Note the route. The message came through ASOS's own app, in front of its customers. ESET's Jake Moore said this suggests the sender reached at least some connected systems. He added that it does not prove the full claim about the extent of any breach.
What is confirmed, and what is claimed
Later that day, ASOS said it was investigating unauthorized activity on third-party platforms it uses to talk to customers. It restricted access to its notification platforms. It is working with advisers and the relevant authorities.
On data, ASOS's early position is narrow. The information that may have been reached covers customers' names and ways to contact them. Its investigators do not think card data or passwords were involved. The administrator of the so-called 'Xuanye Group' said the same about payment data in the Telegram channel.
ASOS said its website and app run as normal. It holds cyber insurance, including business continuity cover. It said it is too early to put a figure on any effect on trading.
Snowflake is a cloud platform where companies store and analyze large amounts of data. It appears in the sender's message, not in ASOS's statement. Snowflake has been asked for comment.
How the pieces may connect
Pieter Arntz of Malwarebytes pointed out that ASOS uses Simon AI for marketing, and Simon AI runs on Snowflake. He called the link indirect. He said it does not show what the sender could actually reach.
Here is the general mechanism to understand. A retailer's customer data does not sit in one place. It moves through data platforms, marketing tools and messaging systems run by other firms. Each holds part of the data. Some may also hold credentials that can send messages to customers.
That is a general risk, not a finding about ASOS. The sources do not say how the sender was able to push the alert. ASOS has not disclosed it.
In that May 2024 incident, the report says, attackers used passwords stolen by infostealer malware. They logged in to customer Snowflake accounts that did not require multifactor authentication. The weakness sat in customer logins. The report presents this as background and does not tie it to ASOS.
The report also notes that Wiz found a script injection flaw in a public Snowflake repository on GitHub in August 2026. The report does not tie it to ASOS. It is background only.
Why this matters for leaders
Moore said the broadcast was likely meant to pressure ASOS by showing how far the sender's access reaches, so it could seek a ransom. Michele Campobasso of Forescout read the short, anonymous message as a sign the group may claim more victims.
Customers face a different problem. They cannot easily tell a real alert from a fake one. Forescout advised ASOS app users not to click the link or engage with the Telegram account. It also advised them to change their passwords.
So the doubt lands on people who did nothing wrong. The company owns the channel. The customer carries the uncertainty.
Questions to ask your team
Kamran Bahdur of FLR Spectron said the claims should be treated as a potential extortion attempt. He listed ASOS's first tasks. Confirm whether access occurred. Review Snowflake audit and login logs. Assess data exposure. Follow the incident process.
He added that any talks with the sender should involve legal, regulatory and law enforcement partners.
Leaders can ask similar questions before an incident. Who can send a message to customers in our name? Which outside vendors hold those keys? Is multifactor authentication required on each one? Can we shut off a channel in minutes? If a fake alert went out today, how would customers know?
A company's voice is an asset. It is also a credential. Treat it like one.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Infosecurity Magazine.





