Skip to content

Security1 publisher3 min readPublished

Extortionists send a Snowflake leak threat through ASOS's own app notifications

Extortionists sent ASOS app users an apparently genuine ASOS push alert on October 6 claiming they had fully compromised the retailer's Snowflake instance. The alert is the only access anyone outside ASOS has seen; the entry route and any data taken are unknown.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Photograph accompanying Extortionists send a Snowflake leak threat through ASOS's own app notifications
Photo: standard.co.uk

What happened

  • The message was signed 'xuanyewengateway' and carried a link to a Telegram channel.
  • ASOS had not confirmed any compromise when Infosecurity Magazine published, and the outlet said it had asked both ASOS and Snowflake for comment.
  • Malwarebytes researcher Pieter Arntz said ASOS's link to Snowflake is indirect, running through the Simon AI marketing platform ASOS uses, which is built on Snowflake.
  • Forescout's Michele Campobasso said the message's thin detail and brief introduction of the group suggest the actor plans to claim more attacks.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Whoever sent the alert could address ASOS app users under the ASOS brand, so any further push from the same sender would look just as legitimate until ASOS shows that channel is shut.
  • decision ASOS has to establish whose Snowflake tenant was reached, its own or its marketing vendor's, before it can size the exposure.
  • constraint Until the entry route is known, nobody can say whether enforced MFA on Snowflake logins would have stopped this intrusion.

Jake Moore, global cybersecurity advisor at ESET, separated what the alert shows from what it claims. "The fact the hackers managed to send a push notification to customers suggests they have gained access to at least some of ASOS's connected systems, but it doesn't prove their full claims about the extent of the data breach," he said [5].

Sending a push and reading a Snowflake tenant are different jobs. Snowflake is a cloud platform for storing, managing, analysing and sharing large amounts of data [9]. A push notification needs a system with permission to message the app's users. Which system sent this one is not public. If the Snowflake tie is indirect, as Arntz describes [7], the instance the note refers to may sit on the vendor's side. Two readings fit, and neither is confirmed: the push came from a second foothold, or one marketing system both holds the data and sends the alerts.

Stolen credentials are the first suspect because of what happened before. In May 2024, attackers used credentials harvested by infostealer malware to log directly into customer Snowflake tenants that did not enforce multifactor authentication [10]. In August 2026, Wiz researchers found a critical script injection flaw in one of Snowflake's public GitHub repositories and reported it through Snowflake's HackerOne program [11]. That flaw was in Snowflake's own repository, a different class of problem from a stolen customer login. Neither event has been tied to ASOS. Until the entry route is known, this case does not show stolen platform credentials still working as a way in.

The note was addressed to "Asos DPO and IT" and told the company to engage or see the data leaked, yet it went to shoppers [2]. "By broadcasting their breach directly to ASOS app users, the threat actors are likely trying to apply pressure to ASOS, showing how extensive their access is so they can leverage some sort of ransom," Moore said [6].

Kamran Bahdur, CIO at FLR Spectron, said ASOS's first job is to establish whether there was any unauthorised access, review Snowflake audit and authentication logs and assess what data was exposed [12]. "Any decision on engaging with the threat actor should be made with input from legal, regulatory and law enforcement partners," he said [13].

For customers, the immediate risk is the link in the alert. Infosecurity Magazine advised app users not to click it or engage with the Telegram account, and to change their passwords [14]. Arntz described what a confirmed exposure would hold. "Any exposure could reveal a detailed customer picture, from browsing and buying habits to location and loyalty status. That's valuable profiling data, though the connection alone doesn't establish what attackers could actually access," he said [8].

What to watch

  • Any statement from ASOS or Snowflake confirming or denying access, and naming whose Snowflake tenant the note refers to.
  • Whether ASOS explains which system sent the October 6 push, and whether another unauthorised alert reaches app users.
  • Whether the xuanyewengateway Telegram channel posts data samples or names other companies, which would test Campobasso's read.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories