Skip to content

ASOS app users receive hacker threats over alleged Snowflake breach

ASOS app users in the UK received threatening notifications on Tuesday morning from hackers claiming to have compromised the company’s Snowflake instance. The hackers demanded ASOS engage with them or risk data leakage. ASOS has not confirmed the breach, and it remains unclear whether the company uses Snowflake or what data may be at risk.

Editor, Lazyfounder

Published 5 min read
ASOS app users receive hacker threats over alleged Snowflake breach
Image: (Image credit: Shutterstock) via source

ASOS app users in the UK received threatening notifications on Tuesday morning from hackers claiming to have compromised the company’s Snowflake instance. The hackers demanded ASOS engage with them or risk data leakage. ASOS has not confirmed the breach, and it remains unclear whether the company uses Snowflake or what data may be at risk.

30 SEC SUMMARY

  • ASOS app users received a threatening notification on Tuesday morning from hackers claiming to have compromised the company’s Snowflake instance.
  • The hackers demanded ASOS engage with them or risk data leakage, targeting the company’s data protection officer and IT team.
  • ASOS has not confirmed the breach, and it remains unclear whether the company uses Snowflake or what data may have been exposed.
  • Under UK law, ASOS must report high-risk breaches to the Information Commissioner’s Office within three days.
  • Snowflake has been linked to recent high-profile breaches, including those affecting Ticketmaster and Santander.

TABLE OF CONTENTS

  • Threatening notifications sent to ASOS app users
  • ASOS’s response and legal obligations
  • Snowflake’s role and recent breaches
  • Background
  • What this means
  • Key takeaways
  • FAQ
  • Sources

KEY HIGHLIGHTS

  • ASOS app users received a threatening notification from hackers on Tuesday morning, claiming to have compromised the company’s Snowflake instance.
  • The hackers demanded ASOS engage with them or risk data leakage, targeting the company’s data protection officer and IT team.
  • ASOS has not confirmed the breach, and it remains unclear whether the company uses Snowflake or what data may have been exposed.
  • Under UK law, ASOS must report high-risk breaches to the Information Commissioner’s Office within three days.
  • Snowflake has been linked to recent high-profile breaches, including those affecting Ticketmaster and Santander.

Threatening notifications sent to ASOS app users

On Tuesday morning, users of the ASOS app began reporting unusual notifications claiming to be from hackers. According to TechRadar and BBC News, the messages warned that ASOS’s Snowflake instance had been compromised and demanded the company engage with the hackers or risk data leakage.

The notifications were directed at ASOS’s data protection officer (DPO) and IT team, according to reports. A DPO is responsible for overseeing a company’s data security strategy and ensuring compliance with data protection laws, such as the UK’s GDPR framework.

ASOS’s response and legal obligations

As of the time of publication, ASOS had not confirmed the breach or issued an official statement, according to TechRadar. The company has not responded to requests for comment from media outlets.

Under UK law, companies must report data breaches to the Information Commissioner’s Office (ICO) within three days if they pose a high risk to individuals. ASOS, which has 17 million customers across 150 countries, would be required to notify affected users if the breach is classified as high risk.

Snowflake’s role and recent breaches

Snowflake is a cloud-based data storage and analytics platform used by many companies to manage and process large datasets. An "instance" refers to an organization’s account within Snowflake’s environment, where data is stored and analyzed.

It is unclear whether ASOS is a Snowflake customer or what data, if any, the company stores with the service. BBC News reported that Snowflake has been linked to several high-profile data breaches in recent years, including incidents involving Ticketmaster and Santander.

Cybersecurity experts have noted the unusual nature of this incident. Charlotte Wilson, Head of Enterprise at Check Point, described the attack as "deeply serious" due to its public and brazen approach. Most extortion attempts by cybercriminals are conducted privately, making this a notable departure from typical tactics.

Background

The incident comes amid growing concerns about cloud security and third-party risk. Companies increasingly rely on SaaS platforms like Snowflake to store and analyze data, which can create vulnerabilities if access controls and security measures are not properly configured.

Recent high-profile breaches linked to Snowflake have raised questions about shared responsibility in cloud security. While vendors provide the infrastructure, companies remain responsible for securing their own data and responding to potential threats.

In a separate development, Dutch authorities recently arrested a suspect linked to the ShinyHunters hacking group, which has been responsible for multiple high-profile data breaches. The group’s activities highlight the growing sophistication of cybercriminals and the challenges companies face in protecting sensitive data.

What this means

Lazyfounder analysis — our interpretation, not reported fact.

This incident highlights the growing boldness of cybercriminals, who are increasingly using public-facing channels like app notifications to pressure companies into engaging with their demands. For founders and operators, this serves as a reminder of the importance of not only securing data but also preparing for scenarios where breaches are disclosed in unexpected or highly visible ways.

The fact that ASOS has not confirmed the breach—and that it is unclear whether Snowflake was even involved—underscores the challenges companies face in verifying and responding to such claims quickly. The UK’s three-day reporting window for high-risk breaches adds pressure, as companies must balance transparency with accuracy to avoid misinformation or panic among users.

For startups relying on third-party SaaS platforms like Snowflake, this incident also raises questions about shared responsibility in cloud security. While vendors provide infrastructure, the onus remains on companies to ensure their configurations, access controls, and incident response plans are robust enough to handle potential threats.

Key takeaways

  • ASOS app users received a threatening notification from hackers claiming to have compromised the company’s Snowflake instance.
  • The hackers demanded engagement from ASOS and threatened to leak data if their demands were not met.
  • ASOS has not confirmed the breach, and it is unclear whether the company uses Snowflake or what data may be at risk.
  • UK law requires ASOS to report high-risk breaches to the Information Commissioner’s Office within three days.
  • Snowflake has been linked to recent high-profile data breaches, including those affecting Ticketmaster and Santander.

FAQ

What do the hackers claim to have done?

The hackers claim to have compromised ASOS’s Snowflake instance and sent threatening notifications to ASOS app users, demanding engagement from the company’s data protection officer and IT team.

Has ASOS confirmed the breach?

No, ASOS has not confirmed the breach or issued an official statement as of the time of publication.

What is Snowflake, and how is it involved?

Snowflake is a cloud-based data storage and analytics platform used by companies to manage and process large datasets. It is unclear whether ASOS is a Snowflake customer or what data, if any, the company stores with the service.

What are ASOS’s legal obligations under UK law?

Under UK law, ASOS must report data breaches to the Information Commissioner’s Office within three days if they pose a high risk to individuals. The company would also be required to notify affected users if the breach is classified as high risk.

Related on Lazyfounder

Sources

  1. TechRadar · 2026-10-06
    ASOS hacked? Customers receive threatening notification from hackers, here’s what we know
  2. BBC News (Tech & Business) · 2026-10-06
    ASOS app users receive notifications from hackers in apparent breach

This story is an original summary drafted with AI by Lazyfounder from the reporting listed above and checked by automated validation. Facts are attributed to their original publishers; sections marked as analysis are Lazyfounder's. Where a source is in another language, facts were machine-translated and quotations are reported, not reproduced. Read the original coverage via the links, and see our AI policy and corrections policy.

About the author

Editor, Lazyfounder

Tarun Mottlia edits LazyFounders, covering Indian startups, funding rounds, AI and product launches. Every story on the site is AI-assisted and checked against its cited sources before publication.

More stories by Tarun Mottlia

Get the LazyFounder Brief

Startup, funding and AI news in a five-minute read. Join the early-access list.

Lazy Founder - Powered by Blogy.in

Contact us

Have a story tip, correction or partnership idea?

Write to us at tarun.kumar@blogy.in or talk to the founder directly. We read every message.

Contact us