A threatening push notification sent to ASOS app users has set off an investigation into an ASOS Snowflake data breach claim. The message, which appeared on customers' phones on October 6, reportedly opens with the line "Dear Asos DPO and IT, we have fully compromised the Snowflake instance." Whether that is true remains unverified, but the way the message was delivered has made security experts take notice.
Here is what we know, what we do not, and what shoppers can sensibly do in the meantime.
What ASOS Customers Received and What Is Confirmed
Customers who had the ASOS mobile app installed received a push notification that read like a message to the company rather than to shoppers. According to reporting from several outlets, it claimed the retailer's data had been "fully compromised" and threatened to leak sensitive information. Early coverage also noted that the ASOS website and app stayed online after the message went out.
That is about where the confirmed facts end. Reports describe the claim that customer information was stolen as unverified, and the assertion that attackers accessed ASOS's Snowflake environment has not been independently confirmed in the coverage we reviewed. Some outlets also reported that ASOS shares fell sharply after the message appeared, though the figures differ between reports, so treat any specific percentage with caution.
In short: a message was sent, it reached customers through the official app, and the underlying claims are still being assessed.
Why a Snowflake Claim and a Push Notification Raise Concern
Two details make this story more than an ordinary breach rumor.
The first is Snowflake itself. It is a large cloud data platform used to store and analyse data, and retailers typically keep sensitive customer information in systems like it. If attackers really had reached an organisation's Snowflake instance, that could mean access to a large store of customer records. The word "if" matters here, because the claim has not been verified.
The second is the delivery method. A push notification sent through the ASOS app suggests the attackers may have reached the systems that control the mobile app's messaging, not just a database. Analysts quoted in the coverage describe the message as clear public extortion: instead of quietly demanding payment, the sender used the company's own channel to put pressure on it in front of its customers.
It is worth separating two possibilities that are easy to blur together. A compromised notification system and a compromised customer database are different incidents with different consequences. One does not automatically prove the other. A sender who can push a message to an app may not necessarily hold the data they claim to have. Until ASOS or independent investigators say more, we cannot tell which scenario applies, or whether both do.
This pattern of extortion pressure without a clear technical breach is not new. Our look at the Revolut data extortion breach shows how a company can face a serious crisis even when the story is not a classic hack.
What Data Could Be Exposed and What Is Still Unverified
Because the attackers' claims are unproven, no one outside the investigation can say which data, if any, was taken. The source reporting only says that retailers typically store sensitive customer information in Snowflake. It does not list what ASOS keeps there, and we will not guess.
What we can do is consider the kinds of information online retailers generally hold, so readers know what to watch for:
- Account details such as name, email address and phone number
- Delivery addresses and order history
- Any information tied to saved payment methods or marketing preferences
This is a general list of what shoppers might reasonably worry about, not a confirmed inventory of what was exposed. Until ASOS publishes findings, the honest position is that the scope, and whether there was any theft at all, is unknown.
What This Means For You
If you shop with ASOS, there is no need to panic, but there is good reason to be careful. Extortion cases often produce follow-on scams. Even if the data claim turns out to be exaggerated, criminals know customers are anxious and may send fake emails or texts posing as ASOS, a bank, or a delivery service.
The push notification itself is also a reminder that an alert appearing in a trusted app is not proof that the content is trustworthy. Do not tap links or call numbers contained in unexpected messages about the incident. Go to the retailer's official site or app directly and look for statements there.
Steps ASOS Shoppers Can Take Now
- Change your ASOS password and make it unique. If you reuse it elsewhere, change it on those accounts too.
- Turn on two-factor authentication wherever it is offered, on your ASOS account, your email and your payment apps.
- Watch your bank and card statements for unfamiliar charges, and report anything suspicious to your provider promptly.
- Treat unexpected messages with suspicion. Be wary of emails, texts or calls that mention ASOS, refunds, account problems or the breach claim.
- Check official channels for updates from ASOS rather than relying on screenshots shared on social media.
- Review app notification permissions and remove apps you no longer use.
The Bottom Line
The ASOS Snowflake data breach claim is still a claim. A threatening message did reach app users, and the retailer's reaction and any independent findings will determine how serious this turns out to be. In the meantime, the smart move is to tighten your account security and stay alert for phishing.
For a closer comparison of how extortion-driven incidents can unfold without a traditional break-in, read our report on the Revolut extortion case, then take a few minutes today to review your passwords, enable two-factor authentication and check your recent account activity.




