Thousands of ASOS customers across the UK received pop-up notifications through the retailer's mobile application claiming that hackers had compromised the company's data systems. The messages, which alarmed users and sparked confusion on social media, represent a significant security incident for the fashion and beauty retailer. ASOS shares fell nearly 12% on the London stock exchange following the incident, though the company's website and app continued to operate normally.
Users reported seeing a notification titled "ASOS hacked" that directed them to a message on the Telegram messaging service. The message stated:
Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it
Although the extortion demand was delivered directly to customers' devices, it was specifically addressed to ASOS's data protection officer and IT department, suggesting the attackers intended the message to reach company leadership through the customer base. The notification claims that the perpetrators have obtained complete access to what they describe as a Snowflake instance—a reference to the cloud data platform used by numerous organisations for data collection, analysis and storage. According to security experts, Snowflake is a massive cloud database where retailers typically store sensitive customer information including transaction records and demographic details such as clothing sizes and body measurements.
ASOS confirmed it is investigating whether any breach has taken place but has not yet provided a public statement regarding the incident or confirmed whether the company uses Snowflake's services or what information, if any, may be stored on such a platform.
What is Snowflake and why does it matter?
Snowflake is a widely-adopted cloud data warehouse platform employed by organisations across multiple sectors. The service has become a frequent target for cybercriminals in recent years, with high-profile breaches affecting major companies. The platform has been linked to security incidents involving Ticketmaster, Santander and numerous other organisations, making it a known vulnerability in the digital infrastructure of many businesses.
Dray Agha, senior manager of security operations at Huntress, an online security firm, warned that the push notification itself suggests attackers may have breached the systems controlling the ASOS mobile app. He described the tactic as "clear public extortion," noting that "sending a ransom demand directly to consumer devices is an aggressive extortion tactic designed to force the business into a quick negotiation." He advised shoppers to watch for targeted phishing attempts while awaiting official confirmation of a data breach.
Marijus Briedis, chief technology officer at NordVPN, cautioned that high-profile cyber incidents create ideal conditions for follow-up attacks. "What customers should be particularly alert to now is what happens next," he said. "Criminals may exploit the publicity by sending emails and texts claiming to be from ASOS, perhaps asking customers to reset a password, confirm payment details, check an order or claim a refund."
Is this connected to other ASOS security incidents?
A separate security incident affecting ASOS was disclosed in August 2026, when the company revealed that attackers may have used login credentials obtained from external sources to access customer accounts in the United States. According to official notification documents, the incident potentially affected 138,828 people. The compromised information included names, contact details, dates of birth and limited payment-card details, though social-media login credentials were not involved. It remains unclear whether this account-access incident is connected to the current app notification breach.
The incident comes after a string of British retailers suffered major hacking events in recent years. Marks & Spencer and the Co-op experienced significant disruptions, with M&S forced to close its website for several weeks as it worked to ensure its systems were secure. Other retailers including Harrods have also been targeted, as has carmaker Jaguar Land Rover.
How widespread is the Snowflake extortion campaign?
The apparent extortion attempt against ASOS appears to be part of a broader pattern of attacks targeting organisations that use Snowflake. According to cybersecurity reporting, a 2024 extortion campaign linked to Snowflake compromises targeted at least 165 organisations globally. Former US Army soldier Cameron John Wagenius was sentenced to 70 months in prison for his involvement in a related hacking and extortion operation, demonstrating the serious criminal consequences associated with such campaigns.

What happens next?
Connor Riley Moucka, who pleaded guilty in August 2026 in connection with the Snowflake extortion campaign, is scheduled to be sentenced on 27 October 2026, according to court records and cybersecurity tracking. The outcome of this case may provide further insight into the scope and coordination of attacks targeting Snowflake users. ASOS customers should remain vigilant for any suspicious communications or unauthorised account activity and monitor their financial statements for fraudulent charges.
Key Facts
- ASOS app users received extortion messages claiming hackers had compromised a Snowflake data instance, with shares falling nearly 12% following the incident
- The message was addressed to ASOS leadership but delivered to customer devices via a Telegram link, a tactic designed to pressure the company into negotiation
- A separate ASOS incident in August 2026 affected approximately 138,828 US customers through credential-based account takeovers, with unclear connection to the current breach
- Snowflake has been targeted in multiple high-profile breaches affecting major retailers and financial institutions including Ticketmaster and Santander
- At least 165 organisations were targeted in the 2024 Snowflake extortion campaign, with criminal prosecutions ongoing and sentencing scheduled for 27 October 2026




