Hackers are threatening to leak ASOS’s Snowflake instance if the online fashion retailer does not engage with them. Customers were sent a mobile app notification today that reads: “Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.” The message directed them to a Telegram account.
It’s not yet known how legitimate the hack is, but ASOS has admitted that “basic personal information” like names and contact details “may have been accessed”. The threat actors appear to have gained access to the marketing systems connected to ASOS, but that does not prove access to the wider retail infrastructure or the claimed data theft. Let’s take a look at what happened.
How Legitimate Is It?
ASOS has 17M customers globally and owns brands including Topshop and Miss Selfridge. Its largest market is the United Kingdom, which represents 49% of all revenues in the first half of the latest financial year.
Snowflake has previously been the subject of media attention due to an attack on Ticketmaster, which saw customer details stolen.
The ShinyHunters hacking group – which is believed to be behind the recent spate of Salesforce hacks – took credit for the Ticketmaster incident, according to a 2024 article from WIRED.
Regarding the more recent incident, chief technology officer at NordVPN, Marijus Briedis, told the PA news agency: “This is an unusually brazen and threatening message. The attackers aren’t simply claiming to have breached ASOS – they’re publicly telling the company to engage with them or they will leak what they say they have obtained.
“What customers should be particularly alert to now is what happens next. High-profile cyber incidents create ideal conditions for phishing attacks.”
Chief Executive of e2e-assure, Rob Demain, said that it is unclear if the claimed Snowflake hack was real, “because we only have the attacker’s word for it”, adding: “The architecture of how ASOS connects to customer data illustrates the wider risk – marketing systems connect valuable customer information with the ability to send messages under the retailer’s name.”
A Snowflake spokesperson later told SF Ben: “As soon as we became aware of the notification that is currently being reported, we began an investigation. At this time, we can report that we have found no compromise of the Snowflake platform. We take customer privacy and security very seriously. The investigation is ongoing and we will provide further updates as soon as more information becomes available.”
An ASOS spokesperson confirmed that an unauthorized notification was sent to customers, and they are investigating activity “involving third-party platforms that we use to communicate with customers”.
“We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities,” the statement reads. “Basic personal information including name and contact details may have been accessed. We do not believe that payment-card information or account passwords were impacted.”
Final Thoughts
The news is still young, so a lot of questions still remain unanswered.
In any case, the incident highlights a broader security problem for companies operating increasingly interconnected tech stacks. A compromise of one system does not necessarily mean an attacker has breached the entire organization, but it can still provide a powerful channel through which to reach customers and potentially access sensitive data.







