ASOS push alerts claim a Snowflake compromise
Retail app used as the ransom note, claim still unconfirmed

ASOS push alerts claim a Snowflake compromise

On Tuesday 6 October, ASOS app users in the UK received a push notification addressed to the retailer's data protection officer and IT team. It said the Snowflake instance was fully compromised and told the company to engage or face a leak. ASOS had not confirmed the claim when the BBC published.

What happened

The message linked to a Telegram channel opened the same day by a group calling itself Xuanye Group. The channel had only a handful of posts. One of them said payment information was not affected. That line is the group's own claim, not a verified finding.

Sending a push to ASOS customers needs access to the notification system, which is separate from Snowflake. Horizon3's Dan Bird told the BBC that if both claims hold, the attackers had credentials that opened more than one door. A customer-service representative told Sky News the notification was fraudulent and that ASOS was investigating. That is not a company statement.

It is not publicly confirmed that ASOS is a Snowflake customer, or what data, if any, sits there. The site and app stayed up. There is no verified evidence that card data or passwords were stolen.

Who is affected

  • ASOS app users who received the push. Do not tap the Telegram link.
  • Retailers and brands that send customer pushes from a platform a marketing vendor can reach.
  • Any firm that stores customer data in Snowflake and shares admin credentials with an agency.

What to do now

Treat the breach claim as unconfirmed. Review who can send customer push notifications, and rotate credentials shared with marketing and data platforms.

If you run a similar stack, check push-provider audit logs for messages you did not send. Customers should not follow links inside an unexpected push, even when it appears to come from the brand app.

Source: BBC News, 6 October 2026. ASOS app users receive push notifications apparently sent by hackers.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

CVE-2026-86360: Dell System Update path traversal to root
Unauthenticated remote code execution on PowerEdge update hosts