Skip to content
Bramble

Business

ASOS app users receive push notification claiming Snowflake data was 'fully compromised'

ASOS customers received a push notification on 6 October claiming hackers had compromised the retailer's Snowflake instance and threatening a leak. ASOS had not commented in the early reports, and the claim is unverified.

8 outlets · 2L · 3C · 3R First reported Account updated
Image: Daily Express
Image: Evening Standard
Image: Daily Mirror
Image: BBC News
Image: Metro
Image: Irish Independent
Image: CNA
Image: City A.M.

1 / 8

The story, neutrally told

Mixed · 2Shortly before 10am on Tuesday 6 October 2026, ASOS app users received a push notification reading: "Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it." Left · 2The Mirror said the notification was titled 'ASOS HACKED' and, like the other outlets, reported that it linked to a Telegram chat; Metro said the Telegram channel asked users to join a second broadcast channel it described as 'legitimate'. Mixed · 2Reports differ on how many people received it: the Express said thousands, Metro's headline said thousands but its text said hundreds, and the Mirror and Standard did not give a figure for recipients.

Left · 3The Mirror reported almost 500 customers had flagged problems with the ASOS site on Downdetector just before 10am, Metro said hundreds were reporting trouble accessing the app, and the Standard said more than 400 had reported the issue by 10.30am. Mixed · 2The outlets explained that DPO means data protection officer and that Snowflake is a cloud data platform used by many companies to store and share data. Left · 3The Mirror, Metro and Standard said they had approached ASOS for comment; none of the four reports said whether a breach had occurred or whether the message came from a genuine attacker.

Centre · 1The Standard added that ASOS has around 17 million customers in more than 150 countries and reported revenues of £2.5 billion in 2025, and that UK law requires companies to report data breaches to officials within three days and to notify those affected in high-risk cases. It quoted social media users, one of whom wrote "Never deleted my payment methods so quick".

Every sentence links to the reporting it rests on. The pill in front of each says where its sources sit: Left, Centre or Right when one side supplies at least half of them, Mixed when they are evenly split. The number is how many outlets it cites.

Left2 outlets

Framing
Breaking-news reports that lead on the 'bizarre' or 'sinister' message and treat the hack as reported but unconfirmed.
Emphasis
The wording of the message, the Telegram link and Downdetector outage reports.
Leaves out or plays down
No ASOS response yet and no detail on what data might be at risk.
Charged language
“bizarre”“sinister”
For example
“ASOS customers sent bizarre ‘hacked’ notification threatening information leak” — Daily Mirror
“Asos hack fears after thousands of shoppers sent sinister phone message” — Metro

Centre3 outlets

Framing
Question-led explainer ('Has ASOS been hacked?') that attributes the claim to the notification.
Emphasis
Customer reactions, company scale and UK breach-reporting obligations.
Leaves out or plays down
No ASOS response yet.
Charged language
“worrying”
For example
“Has ASOS been hacked? Customers concerned after receiving alert” — Evening Standard
“UK law requires British companies to report any data breaches to officials within three days.” — Evening Standard

Right3 outlets

Framing
Short alarm-led piece stressing customer fear and the message wording.
Emphasis
The scale ('Thousands') and the push-notification delivery.
Leaves out or plays down
Does not mention ASOS being approached for comment, Downdetector reports or the Telegram detail.
Charged language
“alarming”“chilling”“bizarre”
For example
“The chilling message was sent via a push notification” — Daily Express
“ASOS 'hacking' fears as customers sent alarming message - 'fully compromised'” — Daily Express