On the morning of October 6, 2026, ASOS app users in the UK and several other countries got a push notification. Around 10:00 BST it read: "Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it." It was signed "xuanyewengateway" and linked to a Telegram channel.
The message was addressed to ASOS's data protection officer and IT team. It was delivered to customers, through ASOS's own app.

By mid-afternoon ASOS had confirmed an attack. In the statement as reported, it did not mention Snowflake.
What ASOS has confirmed
In a statement given to the media, ASOS said: "We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers. We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities". The wording is the same in reports from AFP and the Press Association (via Radio NewsHub).
ASOS also said basic personal information, such as names and contact details, may have been accessed. As reported by FashionNetwork and The Register, the company does not believe payment-card information or account passwords were affected, and says its website and app are running normally. That evening it emailed customers to apologize for the unauthorized notification and to ask them to disregard it and not click the link inside. The UK's National Cyber Security Centre said it has offered ASOS support.
According to AFP, ASOS shares fell by almost 15 percent early in the day and were down about 10 percent by mid-afternoon.
What nobody has confirmed
The Snowflake claim is the attacker's, and it is unverified. The notification shows the sender could reach ASOS's customer-messaging system. It does not show the sender reached ASOS's Snowflake data. Snowflake told AFP it began investigating as soon as it learned of the notification and has "found no compromise of the Snowflake platform", adding that the investigation is ongoing. That statement is about Snowflake's platform. It does not say whether any one customer's account or credentials were involved, and in the 2024 Snowflake campaigns the platform itself was not breached either. ASOS has not said how the attackers got in, which third-party platforms were involved, or whether any data was taken beyond what the statement describes.
The group is also unknown. Forescout researcher Daniel dos Santos said, in comments published by IT Security Guru, that the Telegram channel was created the same day and already had more than 150 subscribers, and that the name "Xuanye" is of Chinese origin, which could point to a Chinese-speaking actor or be a false flag. I have not seen a link to ShinyHunters, Scattered Spider, or any earlier campaign, and I would not draw one today.
What the group says in its own channel
The group has since posted in its Telegram channel. These are the attacker's own words and I could not verify any of them.
One post reads: "Regarding ASOS, payment information is not affected". The next: "That is all for now." A later post, headed "FINAL STATEMENT", says: "The incident involves customer information, it is safe on our server, and it will not be touched for a designated period". The same post tells readers "you can thank us for our generous clarity regarding this incident".

Three things stand out. The group's description of the data, customer information and no payment details, is consistent with what ASOS says. The posts I have seen still do not mention Snowflake. And "final statement" and "for now" read like a group that has the attention it wanted and is pausing, which could mean private negotiation, though nothing in the channel says so. When I checked, the channel had 1,361 subscribers, up from the 150 or so reported on the day it was created.
The extortion note went out before the incident statement
Most extortion starts in private. The attacker contacts the company, names a price, sets a deadline. Here the attacker used the company's own voice to tell customers before ASOS said anything, and the share price fell before ASOS had a statement out. As Check Point's Charlotte Wilson said in comments published by IT Security Guru, customers appear to have heard from the alleged attackers before they heard from the company itself.
Push notifications work because people trust them. A message from the app on your phone is, by design, a message from the company. Once an attacker can send one, every later genuine message from the brand is harder to believe.
Why a third-party platform is the first place I would look
ASOS's own wording points to services it uses to talk to customers, run by other companies. Services like that typically hold a key that proves who they are to the company's systems, and sometimes a key into the data behind them. I do not know how ASOS's are set up. But if an attacker gets one of those keys, the attacker does not need to break anything. The service signs in as itself.
We have seen this shape before, with different details each time:
- In April 2026, stolen tokens from an analytics vendor called Anodot were used to reach customer data in Snowflake. I wrote that up in Supply chain-driven data theft in SaaS.
- In June 2026, a service-account credential at Klue that had never been rotated let attackers push a malicious code update that harvested OAuth tokens (keys that let one cloud service act inside another). The tokens were then used for bulk theft from customer Salesforce accounts. That case is in ShinyHunters isn't a group. It's a pattern.
I am not saying ASOS is the same story. ASOS has not said whether tokens, credentials, or something else were involved. What the earlier cases share is the part defenders can plan for: the attacker holds something real, and the record of who did what shows a normal sign-in. If the route turns out to be a stolen key or token, this is Gap 2 in the Mind Your Attack Gaps ebook: authentication succeeds. The 2024 hardening playbook is still correct, and it does not cover that access path.
What defenders can check this week
You do not need to know how ASOS was reached to ask these questions about your own business:
- Which outside services can speak to your customers or staff for you? Email, SMS, push, and marketing platforms are the obvious ones. Who can create a send, and which keys let them?
- Which keys and tokens do those services hold, and when were they last rotated? The Klue case turned on a credential nobody had rotated. Revoke, not just reset: a token that is never revoked keeps working.
- What does normal look like for each of those integrations? A bulk send, a large query, or a new API key created outside the usual hours is only visible against a baseline.
- Who tells customers first when something goes wrong? ASOS's customers appear to have heard from the attacker first. A holding statement, a verified channel, and a plan for the first hour are cheap to prepare.
For customers, the immediate risk is follow-on scams. Expect fake "ASOS account compromised" emails and texts. Avoid the link in the original notification and go to the app or website directly.
Where Vectra AI fits
Vectra AI detects attacker behavior after authentication succeeds, across identity, SaaS, cloud, and network. The question it asks is whether an identity's actions fit its own history, whatever the entry point was: a stolen password, a phone call to the help desk, or a vendor's token. That includes the identities that belong to integrations as well as the ones that belong to people.
I will update this post when ASOS or the platforms involved say more. For the full walk through Gap 2, see the Mind Your Attack Gaps ebook.

