ASOS app users got a threatening push notification on Tuesday morning claiming the company’s systems had been compromised and warning that a Snowflake instance would be leaked unless the sender was engaged. The message, addressed to “Dear Asos DPO and IT,” linked to a Telegram chat and appeared to have reached at least a large number of the retailer’s customers.
The alert is landing now because it points to a possible live intrusion, not just a rumor spreading on social media. ASOS says it has 17 million customers each year in more than 150 countries, so even a notification sent to a fraction of that base could reach a large audience. Within about half an hour of the message going out, ASOS’s share price had fallen around 5 per cent.
Snowflake is a data platform used by many companies, which makes the specific reference in the message more serious than a generic scam note. ASOS reported revenues of £2.5 billion in 2025 and an operating loss of £212 million last year, underscoring how much is riding on trust in its online operation. A company of that size and reach cannot treat a warning like this as background noise.
But the central facts behind the alert are still unverified. ASOS did not immediately respond to a request for comment, had not posted about the notification or any possible cyber attack on its social media accounts, and it remained unclear how many customers received it. That leaves open a hard question: whether the message was a genuine warning from inside a breach, or part of a broader intrusion meant to look that way.
UK law requires companies such as ASOS to notify officials within three days if there has been a data breach, and to quickly warn affected people when a hack poses high risk. If this notification reflects a real compromise, the company is now on a short clock to show that it can contain the damage and explain what, if anything, was taken.

