Skip to main content
Emerging ThreatsData Breaches

Asos Snowflake Instance Targeted in Data Leak Threat

ASOS retail area with a device on a counter and a blurred data center in the background.
"Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it," read a rogue notification that multiple Asos customers reported receiving this week.

The Telegram-linked alert and its claims

Asos customers reported receiving a notification delivered through what they described as a rogue app message. The message explicitly named the retailer's Snowflake instance as compromised, threatened to leak data, and included a link to a Telegram channel labelled "Xuanye Wen Gateway." The notification addressed "ASOS DPO and IT" by name and carried the single demand: engage, or the data will be leaked.

What the message does — and does not — establish

The notification's text is explicit, but that text alone does not prove a breach. The Register notes that the message "does not, by itself, establish that the sender accessed Asos's Snowflake instance or sensitive customer data." Equally important: how the message was delivered remains unclear. The chain of access that would allow an attacker to read, copy, or exfiltrate Snowflake data was not demonstrated in the notice, and no technical evidence was included in the customer-facing alert cited by The Register.

Market reaction: a short, sharp hit to Asos shares

The immediate commercial fallout was visible: Asos's share price fell by around 12 percent after reports of the notification surfaced. The share price has since recovered slightly, according to the source. The market movement underscores how claims of a data compromise — even before technical validation — can produce rapid financial effects for a listed company.

Relevant precedent: the 2024 Snowflake-targeted theft campaign

The October notification arrives in a context where Snowflake customers have previously been singled out. Customers of Snowflake, a cloud platform for storing and analyzing data, were targeted in a major data theft campaign in 2024 that affected Ticketmaster, Santander, AT&T, and dozens of others. That campaign culminated in criminal charges: Connor Riley Moucka, 26, of Kitchener, Ontario, later pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and conspiracy charges over a hacking spree that compromised more than 165 organizations, exposed billions of customer records, and generated roughly $2.5 million in ransom payments, according to the source.

Following that campaign, Snowflake introduced controls allowing administrators to require multi-factor authentication — a configuration change the company added in reaction to the earlier incidents, per the reporting.

Technical uncertainty and the demand to "engage"

The notification's core demand — that Asos "engage" with the sender — is consistent with extortion-style messaging, but without corroborating technical details the claim remains an unverified allegation. The report emphasizes two gaps: no proof that Snowflake was accessed and no clear explanation of the notification's delivery mechanism. Both gaps leave open whether the message is an opportunistic hoax, a social-engineering effort intended to elicit payment or information, or evidence of a substantive compromise.

What this means for Asos customers, Snowflake administrators, and investors

  • Asos customers: recipients of the notification are left with an unresolved allegation about potential exposure of personal data; the message itself raises consumer concern even though access has not been demonstrated.
  • Snowflake administrators: the 2024 campaign and the platform's subsequent controls — including the ability for admins to require multi-factor authentication — remain relevant technical mitigations to review in light of fresh extortion claims.
  • Investors and corporate risk officers: the share-price reaction shows how quickly market confidence can respond to unverified breach claims, underlining the financial sensitivity of public notifications and security-related communications.

The Register has asked Asos and Snowflake to comment. For now, the central questions remain factual and narrow: did anyone gain access to Asos's Snowflake instance, and by what channel was a mass notification sent to customers? The notification's blunt language produced an immediate market wobble and a renewed focus on an earlier Snowflake-targeted criminal campaign that ended in guilty pleas and platform configuration changes — but it did not, on its face, provide the evidence needed to move the story from allegation to confirmed data breach.

Source: https://www.theregister.com/security/2026/10/06/asos_app_delivers_a_data_leak_threat_instead_of_fast_fashion/5301332