ASOS Hacked as Attackers Abuse Customer Notification Platform to Threaten Data Leak
ASOS probes unauthorized customer alerts that threatened a data leak; the Snowflake claim is unverified.
On October 6, 2026, some ASOS shoppers received an app notification headed “ASOS HACKED,” claiming the sender had fully compromised the retailer’s Snowflake instance and threatening to leak data via Telegram. ASOS is investigating unauthorized activity on third-party customer communication platforms, has restricted access, and said names and contact details may have been accessed, but not payment cards or passwords. The company said its checks found no Snowflake platform breach, so the leak claim remains unverified. A separate late-July 2026 incident used externally obtained credentials, consistent with credential stuffing, and is not linked to this alert.
- Extortion alert sent via ASOS customer notifications on October 6
- Snowflake compromise claim is unverified; ASOS found no platform breach
- Names and contacts may be exposed; cards and passwords not believed taken
- Separate August credential-stuffing incident is not linked
Full article517 words · extracted from gbhackers.com · click to collapse
ASOS is investigating unauthorized activity involving third-party customer communication platforms after some shoppers received an alarming app notification suggesting a potential data leak.
The attackers claimed to have accessed the retailer’s Snowflake environment, but this allegation remains unverified. Accessing notifications alone does not confirm a database breach.
ASOS Hacked
The alert reportedly appeared around 10 AM on October 6, 2026, with the heading “ASOS HACKED.” The message addressed the company’s Data Protection Officer (DPO) and IT team, stating: “Dear ASOS DPO and IT, we have fully compromised the Snowflake instance.
Engage with us, or we will leak it.” The message included a Telegram link, turning a customer-facing communication channel into a public extortion mechanism. While the notification indicates unauthorized messaging, it does not independently verify the attackers’ claim that they extracted customer records.
ASOS has responded by restricting access to the affected notification platforms. The company stated, “We are investigating unauthorized activity involving third-party platforms that we use to communicate with customers.”

They confirmed the unauthorized customer notification and immediately took action to limit further access.
ASOS is collaborating with specialists and relevant authorities to conduct a thorough investigation. Their initial assessment suggests that basic personal information, including names and contact details, may have been accessed. However, ASOS does not believe that payment card information or account passwords were compromised.
According to CSN, the ASOS website and app continued to operate normally during this incident. Investigators still need to determine how the breach occurred, identify affected systems, and ascertain whether any unauthorized access resulted in data copying or exfiltration.
Regarding the Snowflake claim, the company stated that its inquiries revealed no breach of its platform. However, this should not be misconstrued as a definitive finding about every customer environment, as the attackers’ specific allegations regarding ASOS remain unverified.
It’s crucial to highlight that access to a messaging service does not automatically prove access to a separate cloud data environment. Public pressure exerted on the retailer via customer notifications might amplify reputational damage without establishing the alleged compromise.
Additionally, ASOS experienced a separate incident on August 25, 2026, when some customer accounts were accessed using credentials obtained from outside the company.
ASOS detected unusual activity on July 28, confirmed the incident the following day, and promptly blocked the affected accounts while enforcing password resets on July 29.
This incident potentially exposed names, addresses, telephone numbers, dates of birth, and redacted payment card details. The circumstances suggested credential stuffing or account takeover, rather than a confirmed compromise of ASOS’s authentication infrastructure. No established link exists between this previous incident and the current notification issue.
Customers are advised not on click the Telegram link and to rely on official ASOS communications. They should also monitor account activity and replace reused passwords with unique credentials. Receiving the notification does not necessarily indicate that a customer’s phone has been compromised.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.