Skip to content

Leadership1 publisherNot yet confirmed elsewhere3 min readPublished

Hackers delivered their Asos extortion demand through the retailer's own app

Hackers used the Asos app on Tuesday to send UK users an extortion demand claiming they had compromised the retailer's Snowflake instance. Because the demand went to shoppers, the attackers decided when Asos had to speak to customers, before it could say what data, if any, was taken.

The Board Room · Leadership desk

How we use AISend a correction

Photograph accompanying Hackers delivered their Asos extortion demand through the retailer's own app
Photo: independent.co.uk

What happened

  • Asos emailed customers to apologise for the "unauthorised push notification" and told them to disregard it and not click the external link it carried.
  • Later on Tuesday, Asos said it had acted immediately to restrict the apparent hackers' access and was working with advisers and relevant authorities.
  • Snowflake, the data storage company named in the message, told the BBC its own investigations had found no compromise of its platform.
  • The BBC reported that it is not yet clear who is behind the message, what they want, how many people received it or how many may be affected.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

  • exposure Anyone who can reach a retailer's push tool can put words in front of its whole app audience under the brand's name, so control of that tool belongs in the same incident plan as the customer database.
  • constraint Customers now warned to distrust messages claiming to come from Asos will treat Asos's genuine updates with the same caution, leaving the company fewer trusted ways to explain the scope.
  • precedent A ransom note addressed to the data protection officer arrived as a customer alert. Incident plans that assume the first contact from attackers will be private now have a public counterexample.

"Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it," the message read [3]. It was addressed to Asos's data protection officer and IT staff. It was received by Asos app users across the UK, who got it as a pop-up from the app along with a link to a Telegram account [2][5]. The BBC told readers that receiving it did not mean their phones had been hacked [18]. The words came through the retailer's own channel, and customers saw them before Asos had made any statement [6].

Choosing that audience set the company's timetable. By Tuesday evening Asos was telling customers the data involved may include "basic personal information including name and contact details" [8]. "However, we don't believe that any payment-card information or account passwords have been impacted," it said [9]. At the same point, the BBC reported that it was not clear what information, if any, had been accessed [7].

The note claims a compromise of "the Snowflake instance" [3]. Snowflake's denial, given to the BBC, covers its platform [1]. One statement is about a vendor's platform and the other is about the particular instance the attackers say they hold, so both can be true. A retailer whose data sits with a vendor should expect that vendor to make its own statement, and Snowflake's covers only Snowflake's platform. Neither company has said how the attackers got access to the app's push tool, or whether the same access reached the data store the note names.

Charlotte Wilson, head of enterprise at Check Point, said "the biggest immediate risk may be what happens next" [10]. She expects "attempts to exploit that confusion" [11], and advised customers to be "extremely suspicious" of messages claiming their account has been compromised or asking them to click a link to reset a password [12]. That advice also applies to the channels Asos would use for its own follow-up. The company has promised an update "as soon as we have confirmed more information" [15]. The BBC tells readers to go to Asos's official website directly [16]. Kat Cereda, a spokesperson for Which?, says people should hang up on callers who might be posing as Asos and contact the company by separate means [17].

On Tuesday night Asos said its website and app were operating "as normal, and customers can continue to shop with confidence on ASOS as normal" [14]. That statement concerns whether the shop works. The alert concerned who can send a message to every Asos app user under the company's name [2].

In my view, a push tool belongs in the breach plan for two reasons this case shows. It carried an attacker's demand to Asos customers [2]. It is also one of the most direct routes a retailer has to those same customers once it knows what was taken. If the tool is run as campaign software, the people who can send to the whole base are picked so promotions go out fast. If it is run as production infrastructure, with a short list of senders and a second approver on any message to every user, campaigns slow down. The trade-off is marketing speed against control of a channel that has now carried a ransom note. This quarter's choice is how many people can reach every customer at once. The consequence comes in the next incident, when customers who have been told to distrust brand messages [12] have to decide whether the company's own alert is genuine.

What to watch

  • Asos's promised further update, and whether it widens the data involved beyond names and contact details or changes its view on payment cards and passwords.
  • Any account from Asos or Snowflake of how the attackers reached the app's push tool and the Snowflake instance, and whether one access route covered both.
  • Follow-on phishing emails, texts or calls posing as Asos, which Check Point's Charlotte Wilson expects.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence45
Adoption
Insufficient
Hype gap+5
Incentives65
Confidence40
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Data storage company Snowflake told the BBC its investigations had "found no compromise" of its platform.

    ReportedSupportedSource: Snowflake, to the BBC2 sources— create a free account to open themView cited source
  2. [2]

    On Tuesday morning, Asos users across the UK were sent pop-up messages from its app that appear to have been sent by hackers trying to extort the company.

    ReportedSupportedSource: BBCView cited source
  3. [3]

    "Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it," the message read.

    ReportedSupportedSource: Text of the push notification, as reported by the BBCView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. bbc.co.uk

    1 article · October 6, 2026

    What can I do to protect myself after 'Asos hacked' message?

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories