Asos data breach: Hackers sent users a threatening message
A major British online retailer appears to have suffered a data breach.

Hacker sent numerous Asos customers a threatening message. Image by Cybernews.
- Asos app users received a notification claiming the retailer had been hacked.
- The message alleged hackers compromised Asos’s Snowflake instance and threatened to leak data.
- The notification included a link that appeared to lead to the attackers’ Telegram channel.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Numerous Asos clients just received an ominous message, likely attempting to scare the company’s management.
Asos app users received an unusual message via the British fashion retailer's app, on Tuesday.
The notification, titled “ASOS HACKED,” informs customers of an alleged data breach.
“Dear Asos DPO and IT, we have fully compromised the Snowflake instance,” the message reads. “Engage with us, or we will leak it.”
The message is followed by a link to, likely, the attackers’ Telegram channel.
We have reached out to Asos and will update the article once we receive a reply.
As of writing the company's website appears not to be affected by the alleged data breach. The app, which was used to distribute the threatening message, also appears to be working normally. However, since the alleged attackers were able to push the message, they likely had access to systems beyond the app itself.
Hackers want Asos heads panicking
Openly threatening victims is a fairly common tactic, Aras Nazarovas, Senior Information Security Researcher at Cybernews explained. Publicly announcing a hack puts psychological pressure on the decision makers with attackers expecting decision-makers to panic and succumb to their demands.
"Publishing the message via notifications to users is a double edged sword here, as that might have the similar affect as an internal message, but now everyone knows about the breach, which greatly reduces the likelyhood of the ransomware payment actually being made," Nazarovas said.
Typically, ransom payment are negotiated in secret, which allows impacted organizations to avoid public scrutiny over data leaks. Now, for instance, Asos will be forced by UK law to report the data breach to officials within three days.
"DPO" alleged attackers appear to reference in the app notification refers to Data Protection Officer, the person that would typically have to deal with protecting customers' data.
Meanwhile, the reference to the cloud data platform Snowflake may raise some concerns. In mid-2024 attacker managed to break in to hundreds of Snowflake accounts, exposing hundreds of million of customer records.
At the time, attackers used stolen login credentials to access corporate Snowflake accounts, later using information stored there to blackmail businesses for ransom. The exposed companies included a broad list of well known brands such as Ticketmaster, AT&T, and hundreds of other companies.
Asos is major online British fashion and cosmetics retailer with last years' revenue exceeding $3 billion. The company works with hundreds of brans and ships to majority countries around the world. The company employs nearly 3,000 people.
Following the alleged hacker message, the company's shared dipped by over 10% as of 9:50 AM GMT.
This is a developing story.