ASOS push notification hack: What the “Snowflake” message means for your card and password

October 7, 2026
3 mins read
Close-up photograph of a consumer holding a smartphone while checking an e-commerce order beside retail shopping parcels on a wooden table.
Millions of consumers rely on mobile shopping applications for seamless checkout, yet an unexpected broadcast alert can instantly raise questions about third-party system vulnerabilities and personal data vigilance. When communication relays fail to authenticate origin tokens, routine push channels transform into direct extortion vectors. [Photo: Unsplash / License: Unsplash Commercial Free-Use]

If you received an “Asos hacked” push notification on your phone today, your immediate question is whether your payment card or password was stolen. ASOS confirmed it is investigating unauthorised activity involving third-party platforms after thousands of app users received a rogue message this morning demanding the company contact attackers via Telegram or face a data leak. Here is what the company has confirmed and what you should do right now.

Early on October 6, 2026, some ASOS app users received a push notification titled “Asos hacked.” The message read: “Dear Asos DPO and IT, we have fully compromised your Snowflake instance. Engage with us, or we will leak it.” ASOS confirmed it had taken immediate action to restrict access to the notification platforms and was working with internal and external specialists as well as relevant authorities. The company said basic personal information — including names and contact details — may have been accessed. Payment card information and account passwords are not believed to have been affected.

ASOS said it does not believe payment-card information or account passwords were impacted by the incident. However, your name and contact details may have been exposed through third-party communication tools. ASOS is not currently asking customers to change their passwords or take any other specific action. You should ignore the Telegram link in the notification, use only the official ASOS website or app, and stay alert to phishing emails that may follow.

What the Snowflake claim actually means

The push notification framed the attack as a compromise of ASOS’s Snowflake instance. Snowflake is a cloud data platform companies use to store and analyse large volumes of customer data. Claiming that Snowflake was breached was a deliberate choice — it signals the most alarming possible outcome to anyone who knows what it is, and generates public pressure on the company.

Snowflake issued a direct statement: “At this time, we can report that we have found no compromise of the Snowflake platform. We take customer privacy and security very seriously. The investigation is ongoing.”

ASOS confirmed unauthorised activity involving third-party platforms used to communicate with customers. The exact access method and full scope of the incident remain under investigation. What the evidence points to is that at minimum, the communications channel used to send push notifications to ASOS app users was compromised, allowing the attacker to broadcast a message to customers. It does not, based on what has been confirmed, establish that the data systems holding payment tokens, order histories, or account passwords were reached — but ASOS and its investigators have not yet publicly closed off those possibilities.

Change your ASOS password if you wish as a personal precaution by going directly to the ASOS website or app — not through any link in the push notification, in follow-up emails, or in text messages. Do not click the Telegram link in the notification under any circumstances. Watch for follow-up phishing attempts. If your name and email address were accessed through the compromised messaging platform, you may receive targeted emails designed to look like official ASOS communications. Check the sender address carefully and report anything suspicious. For guidance on locking down your online accounts after incidents like this, see our guide on protecting your shopping accounts and our overview of how data breach notifications work.

Did the ASOS hack expose customer credit card numbers or passwords?

No. ASOS confirmed in an official statement that payment card information and account passwords are not believed to have been affected by the incident. While basic contact details such as customer names and email addresses may have been accessed through a compromised third-party messaging platform, ASOS’s statement is that payment data was not impacted.

ASOS said its website and app remain fully operational. The formal investigation is ongoing. If ASOS determines that a notifiable personal-data breach occurred, UK GDPR rules require notification to the Information Commissioner’s Office within 72 hours of becoming aware of it. Check back for updates when the company confirms the scope of what was accessed.

Leave a Reply

Your email address will not be published.

High-magnification microscope view of stained colorectal cancer tissue cells under laboratory evaluation.
Previous Story

Early-onset cancer rose 79% since 1990—what younger adults should know

Latest from News

Don't Miss

Exterior facade of the J Edgar Hoover FBI Building in Washington DC

ShinyHunters Suspect Detained in Jordan as FBI Probes Job Portal Claims

ShinyHunters Hacker Detained in Jordan: What We Know