On Tuesday, October 6, 2026, millions of ASOS customers received an unexpected push notification titled “ASOS HACKED,” publicly revealing a claimed breach of the fashion giant’s Snowflake cloud instance. The stock fell as much as 12% in intraday trading while the company confirmed an investigation into an intrusion affecting its third-party communication platforms.
🔑 Key Takeaways
- Push notification titled “ASOS HACKED” sent to customers on October 6, 2026
- Attackers claim full compromise of the Snowflake instance and threaten to leak data
- ASOS stock dropped as much as 12% in a single session
- ASOS acknowledges basic personal data may have been accessed
- Payment card details and account passwords reportedly unaffected
An Unexpected Notification Sent to Millions of Customers
On the morning of Tuesday, October 6, 2026, numerous ASOS app users noticed an unusual push notification on their phones, titled “ASOS HACKED.” Contrary to appearances, the message was not addressed to customers themselves, but to the company’s Data Protection Officer (DPO) and IT department. Its content was blunt and threatening: “Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.”
The attackers demanded that ASOS contact them or face a public data leak. The message ended with a link that appeared to lead to a Telegram channel operated by the attackers. The fact that this notification was delivered through ASOS’s own push system indicates that the hackers had, at minimum, access to a communication tool linked to the application.

Snowflake and Simon AI: The Scope of the Potential Exposure
Snowflake is the cloud platform ASOS uses to store, process, and analyze its data, as well as to send push notifications to its customers. According to Sky News, it is on this infrastructure that ASOS runs Simon AI, an artificial intelligence tool that aggregates behavioral, transactional, and demographic data of each customer into a single profile.
These profiles can include particularly sensitive information: clothing sizes commonly purchased, browsing history, purchasing preferences, and potentially even body measurements of shoppers. A compromise of Snowflake would thus open the door to potentially massive access to this behavioral data.
| Data Type | Status According to ASOS |
|---|---|
| Names and contact details | Potentially accessed |
| Behavioral data (Simon AI) | Undetermined |
| Payment information (bank cards) | Not affected according to ASOS |
| Account passwords | Not affected according to ASOS |
| Clothing sizes and body measurements | Undetermined |
Stock Drop and Customer Reactions on Social Media
The market impact was immediate. ASOS shares fell as much as 12% when the news broke, according to Numerama, while BFMTV reported an immediate decline of 10%. This slight difference can be explained by the stock’s evolution over time. The shares had previously gained more than 70% since the start of 2026, making the drop all the more striking.
| Indicator | Value |
|---|---|
| Maximum intraday drop | -12% |
| Drop reported by BFMTV | -10% |
| YTD performance | +70% |
| DownDetector reports | Over 500 |
On the customer side, confusion was widespread. On X (formerly Twitter), several users shared their experience:
- “Anyone else get the ASOS hacked notification? Any ideas?”
- “Has ASOS been hacked…this push notification is crazy.”
- “ASOS got hacked? I got a weird notification.”
Some even speculated that it might be a marketing strategy, as one comment showed: “Has asos actually been hacked or is it just an ad for Christmas. Hence snowflake.” Others joked about the situation, such as one user who wrote: “Not ASOS getting hacked on a Tuesday morning. Or is this a marketing strategy.” More than 500 customers also reported the incident on DownDetector, according to BFMTV.
ASOS Responds and the Scope of Compromised Data
As tensions mounted, ASOS eventually responded officially with a statement:
“We are currently investigating an unauthorized activity involving third-party platforms that we use to communicate with our customers. We have immediately taken measures to restrict access to these notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities.”
ASOS, official statement
ASOS also acknowledged that personal information belonging to its customers “may have been accessed” as a result of the attack. However, the company clarified that it did not believe information relating to payment cards or account passwords had been compromised. Numerama reports that customer banking data would likely not be affected.
It is important to note that, at this stage, nothing yet indicates which data may have actually been accessed or exfiltrated, or even whether customer data is genuinely at risk. The fact that the attack allowed notifications to be sent suggests that the hackers had, at minimum, access to a tool linked to the application.
Recommendations for Customers
- Do not click on the link contained in the “ASOS HACKED” notification
- Be wary of messages claiming to be from the brand in the coming days
- Remove your bank card from the ASOS app as a precautionary measure
- Regularly check bank statements for any suspicious activity
This incident comes as ASOS, one of the world’s largest online fashion retailers, counts 17 million active customers. The company uses Azure Sentinel to centralize its security operations and detect threats early, but this did not prevent the attack.
Outlook and Scenarios
The alleged compromise of ASOS highlights the growing vulnerability of cloud infrastructures among major e-commerce companies, even those equipped with advanced security solutions like Azure Sentinel. If attackers confirm access to the Snowflake instance, a leak potentially including Simon AI data could affect a portion of the brand’s 17 million active customers.
Three scenarios are plausible. In the most optimistic case, ASOS would demonstrate that only the notification function was compromised, with no access to customer databases. In a middle-ground scenario, basic personal data (names, contact details) would surface, as the official statement suggests. In the darkest scenario, Simon AI behavioral profiles would be exfiltrated and published. In all cases, this incident is a stark reminder that push notifications, designed as a direct and trusted communication channel with customers, can become a formidable weapon when hijacked by attackers.
Sources
This article is published for informational and educational purposes. It does not constitute financial advice in any way. Always do your own research (DYOR) before making any decision.

