Asos is investigating unauthorized activity involving third-party platforms after some users of its app received a notification on October 6 claiming that attackers had compromised a Snowflake instance. The message, addressed to the company’s data protection team and technology department, threatened to leak information unless Asos contacted its authors.
The company took steps to restrict access to the notification platforms and said its website and app continued to operate normally. According to information Asos submitted to the London Stock Exchange, basic personal data, such as names and contact details, may have been accessed. The company said it does not believe payment card details or passwords were affected.
The claim about Snowflake remains unverified
The notification attributed the alleged intrusion to a Snowflake instance, a cloud platform for storing and managing data. However, the attackers’ claim does not in itself prove that the platform was breached. Snowflake said it had found no evidence that its platform had been breached.
The scope and method of the incident therefore remain unclear. Josep Albors, ESET’s head of research and awareness, noted that access to customer information would depend on how Asos had configured and used Snowflake. He also considered it unusual that the attackers contacted customers through notifications instead of publishing a sample of the data they claim to have.
What is known about the possible impact on customers and operations
Asos has not specified how many people received the notification, nor has it confirmed that personal data was extracted. The company said it is continuing to investigate with internal and external specialists and will cooperate with the relevant authorities. In the meantime, the threat to leak data should be distinguished from a confirmed leak: the former was circulated by the attackers; the latter has not been substantiated by the information available.
The company said there had been no disruption to its operations and that it was still too early to estimate any business impact. It also said it has cybersecurity insurance, but did not specify which costs or losses the policy would cover.
Stock market reaction and obligations in the United Kingdom
Asos shares fell sharply during the day, with intraday declines that various reports put at approximately 10% to 13%. This movement reflects the market’s reaction to the news available at the time; it does not by itself establish the incident’s final financial impact. Some reports also recorded a fall in Snowflake shares, despite the company saying it had found no breach of its platform.
In the United Kingdom, data protection rules provide for notifying the Information Commissioner’s Office (ICO) within 72 hours of an organization becoming aware of a personal data breach that may pose a risk to people’s rights and freedoms. If the breach may pose a high risk, the affected people must be informed without undue delay. The obligation to notify depends on the risk assessment, not on formal confirmation of the breach; the published information does not make it possible to conclude whether Asos has already made a regulatory notification.
Sources and methodology
This report summarizes information published by EFE, City A.M., Quartz, ABC, and FashionUnited about the incident of October 6, 2026. It distinguishes the attackers’ claims from statements attributed to Asos and Snowflake, and presents share price movements as intraday figures reported by various media outlets.