Asos customers who opened the retailer's app on Tuesday found a message the company never wrote. Titled 'Asos hacked' and addressed to the firm's data protection officer and IT teams, the push notification read: 'Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.' The message pointed recipients to a Telegram account.

In a statement the same afternoon, Asos confirmed an 'unauthorised customer notification' and said access to 'basic personal information, including name and contact details' may have occurred, adding: 'We do not believe that payment card information or account passwords were affected.' The company said it saw no disruption to trading and is investigating 'unauthorised activity on platforms from third parties that we use to communicate with customers'.

That wording matters. The intruders appear to have reached Asos's audience through an outside marketing or messaging provider that holds push access to its app, rather than by breaking into Asos's own stack. An unauthenticated push channel carrying a trusted brand is one of the widest blast radii a retailer owns — whoever controls the provider can speak to every customer in the company's name.

Shares fell more than 10% in London. Asos, whose brands include Topshop and Miss Selfridge, has around 17 million customers worldwide and had only recently returned to growth after years of restructuring.

The mention of Snowflake is pointed: the cloud data platform sat at the centre of a 2024 extortion wave in which attackers signed into customer tenants with stolen credentials rather than exploiting the platform itself. There is no public evidence yet that Snowflake is involved this time, and Asos has not named the company.

What to watch: whether a third-party vendor is identified, whether Asos formally notifies the UK's Information Commissioner's Office, and whether the attackers publish data once the 'engage with us' deadline the message implies has passed.