
Incident details and notification breach
The security incident unfolded around 10 am on October 6, 2026, when customers received an unsolicited notification via the official ASOS mobile application. Addressed directly to the data protection officer and IT team, the alert stated that the company’s Snowflake data instance had been fully compromised and included a Telegram contact link.
Snowflake operates as a cloud data platform utilized by enterprises for data storage and analysis, but security experts emphasize that unauthorized access to a notification channel does not inherently grant entry into underlying cloud databases. ASOS confirmed that unauthorized activity had targeted third party platforms used for customer communications. The retailer restricted platform access immediately and engaged cybersecurity specialists alongside relevant authorities.
While basic personal details such as names and contact information may have been exposed, the company’s initial assessment indicates that payment card data and account passwords remain unaffected. Both the main website and mobile application continue to function normally.
Expert analysis and market impact
Industry analysts suggest the public alert was engineered to apply pressure and provoke direct contact. Charlotte Wilson of Check Point told the BBC that attackers may have utilized the notification system primarily to embarrass the retailer, reiterating that claims of Snowflake database access lack independent verification. Investigators are actively working to determine the initial entry vector, affected systems, and whether any customer records were duplicated.
The public nature of the alert triggered an immediate financial reaction, with ASOS shares dropping over 11 percent amid intraday trading declines of up to 13 percent. Security professionals advise customers to ignore the embedded Telegram link, monitor official updates closely, and remain vigilant against secondary phishing attempts that might exploit the news.