Skip to main content
Emerging ThreatsData Breaches

ASOS Faces Suspected Snowflake Compromise, Urges Customer Caution

Smartphone with notification on screen beside a laptop in a neutral room.

"Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it." — a push notification sent to ASOS app users on October 6, signed 'xuanyewengateway'.

The push notification and the 'xuanyewengateway' claim

On October 6, some customers of online fashion retailer ASOS received a push notification that appeared to originate from the ASOS mobile app. The message addressed the company's "DPO and IT," said the sender had "fully compromised the Snowflake instance," and urged ASOS to "engage with us, or we will leak it." It was signed "xuanyewengateway" and included a link to a Telegram channel.

The notice used the term DPO, which the reporting explains stands for data protection officer, the role required under the General Data Protection Regulation (GDPR) for organizations operating in the UK or EU to oversee personal-data handling. As of the time of publication, ASOS has not confirmed any compromise.

Snowflake named as the alleged vector and relevant historical context

The message specifically referenced Snowflake, a cloud-based data platform used to store, manage and analyze large data sets. The reporting notes that threat actors have previously targeted Snowflake instances to gain unauthorized access.

Two incidents in the public record are cited: in May 2024, attackers used stolen credentials harvested by infostealer malware to log directly into customer Snowflake tenants that did not have multifactor authentication (MFA) enforced; and in August 2026, security researchers at Wiz, part of Google Cloud, discovered a critical script injection vulnerability in one of Snowflake’s public repositories on GitHub through the cloud service provider’s HackerOne vulnerability disclosure program.

Expert warnings and interpretations of the claim

Security researchers and industry advisers cautioned that the notification should be treated seriously while emphasising uncertainty about the breadth of any actual access.

  • Jake Moore, global cybersecurity advisor at ESET, warned that if the claim is confirmed it "could be one of the most visible hacks in history" and "put a lot of customer data at risk." He noted that the ability to send a push notification "suggests they have gained access to at least some of ASOS’s connected systems, but it doesn’t prove their full claims about the extent of the data breach." Moore added that broadcasting the breach to app users is likely an attempt to apply pressure for ransom.
  • Pieter Arntz, senior malware intelligence researcher at Malwarebytes, pointed out that ASOS uses Simon AI for marketing, and that Simon AI "runs on Snowflake," making any connection "indirect." He said "it’s too early to say how much ASOS customer data attackers could get their hands on," while warning that potential exposure could include "browsing and buying habits to location and loyalty status."
  • Michele Campobasso, senior security researcher at Forescout, observed that the terse message and "the lack of any additional information and the (short) presentation of a group" suggests the threat actor may be planning to claim further attacks. He advised that ASOS app users "ought not to click on the link in the notification and avoid the engaging in the Telegram account" and recommended that customers change their passwords for an extra layer of protection.
  • Kamran Bahdur, CIO at cybersecurity resilience firm FLR Spectron, characterised the notification as something that "should be taken seriously and treated as a potential extortion attempt." He listed immediate priorities for ASOS as establishing whether there has been unauthorised access, reviewing Snowflake audit and authentication logs, assessing any data exposure and following the incident response process. Bahdur also said "Any decision on engaging with the threat actor should be made with input from legal, regulatory and law enforcement partners" and warned ASOS personnel to avoid direct engagement outside a vetted response strategy.

Immediate steps reported or advised for ASOS customers and personnel

Public guidance cited in reporting is limited to expert comments. Customers who received the notification were advised by Michele Campobasso not to click the link in the message or engage with the linked Telegram account, and to consider changing passwords as an extra precaution.

For ASOS personnel, Kamran Bahdur recommended reviewing Snowflake audit and authentication logs and following incident response procedures, with engagement decisions coordinated with legal, regulatory and law enforcement partners. Infosecurity said it has contacted both ASOS and Snowflake for comment.

How this lands for ASOS customers, ASOS IT teams, and regulatory partners

  • ASOS customers: The immediate consumer action recommended in reporting is to avoid interacting with the Telegram link and to change passwords as an added precaution. Experts framed the notification itself as a pressure tactic that could precede extortion.
  • ASOS IT and security teams: Reported expert guidance focuses on log review (Snowflake audit and authentication logs), assessment of potential data exposure, and adherence to incident response playbooks with legal and law enforcement involvement before engaging with the actor.
  • Legal, regulatory and law enforcement partners: Experts advised that any decision to engage with the threat actor should include input from legal counsel, regulators and law enforcement — reflecting the potential GDPR implications of an incident involving customer personal data and the criminal law elements of extortion claims.

The episode is unresolved: ASOS has not confirmed a breach and the notification remains an unverified claim signed "xuanyewengateway." The balance between a visible, user-targeted proclamation of access and the absence of independent confirmation leaves investigators with immediate technical tasks — log review, authentication audits and containment decisions — and ASOS customers with a simple, precautionary step: do not click the link and consider changing passwords. Infosecurity has reached out to ASOS and Snowflake for comment.

Original story