Key Takeaways
- ASOS said names and contact details may have been accessed, but payment-card details and passwords were not believed to be affected.
- An unauthorized app notification claimed a Snowflake instance had been compromised, although Snowflake found no evidence its platform was breached.
- The incident highlights the need to treat customer-notification systems as sensitive security infrastructure.
ASOS is investigating a security incident after customers received an unauthorized notification through its app on 6 October 2026. The message claimed attackers had compromised a "Snowflake instance" and threatened to leak information through Telegram, bringing the incident directly onto customers' phone screens.
The immediate concern is potential exposure of customer data. ASOS said basic personal information, including names and contact details, may have been accessed. However, ASOS did not believe payment-card information or passwords were affected, according to the BBC. The distinction matters, but names and contact details can still support convincing phishing, impersonation and social-engineering attempts.
The unauthorized alert demonstrates that an actor gained the ability to send a message through, or in the name of, ASOS's customer-notification channel. It does not, by itself, prove every claim made in that message. In particular, Snowflake said it had found no evidence that its cloud data platform was compromised. That leaves several possible paths under investigation, including customer credentials, connected applications, administrative accounts or another component in ASOS's technology chain.
That said, the notification is more than an embarrassing communications failure. Mobile alerts benefit from customer trust and immediate visibility. If attackers obtain access to such a channel, they can create confusion, amplify extortion claims or direct recipients toward fraudulent destinations. In this case, Telegram was presented as the alleged attackers' contact channel. Customers should be cautious about unexpected messages, links or requests that refer to the incident, even when those communications appear to know basic personal details.
The episode also arrives against a difficult security backdrop for UK retail. A report covered by Intelligent CISO ranked retail and manufacturing as the UK's most security-exposed industry, with a score of 50.9. It also cited the latest Home Office survey, in which 41% of wholesale and retail premises reported crime. Retailers combine large customer databases, seasonal staffing, extensive supplier networks and digital systems that face the public. That mix can widen the number of routes an attacker may probe.
Process weaknesses deserve attention too. The same research reported that 77% of UK data breaches in 2025 were attributed to human error or process failure rather than hacking, while 19% reportedly took more than a week to reach the Information Commissioner's Office. Under the UK GDPR, controllers generally have 72 hours after becoming aware of a qualifying personal-data breach to notify the ICO. Fast escalation and reliable internal evidence can therefore affect both customer protection and regulatory exposure.
For security leaders, the practical lesson is to include messaging infrastructure in incident-response planning. Push-notification consoles, marketing systems and customer-engagement tools can hold powerful publishing permissions. Access should be tightly limited, protected with phishing-resistant authentication where feasible, logged in detail and monitored for unusual campaigns. Teams can also prepare an emergency method for revoking tokens, stopping queued messages and switching to verified customer communications.
The broader response can draw on NIST SP 800-61 Rev. 3, published in 2025. It places incident response across the six functions of the NIST Cybersecurity Framework 2.0: Govern, Identify, Protect, Detect, Respond and Recover. Applied here, that means examining not only how access occurred, but also who owned the notification channel, which controls failed, how quickly ASOS detected misuse and how confidently ASOS can restore customer trust. The next crucial step will be evidence-based clarification of the access route, the information involved and the number of people affected.
⬇️