ASOS customers got a blunt warning Tuesday morning: hand over money, or your data goes public.
The message arrived as a push notification inside the ASOS app, addressed directly to the company's Data Protection Officer and IT team. It claimed the attackers had "fully compromised" ASOS's Snowflake instance - the cloud environment the retailer uses to store and analyze data - and threatened to leak it unless ASOS engaged via a linked Telegram channel. Down Detector logged a spike in ASOS app complaints just before 10am that same morning. ASOS has not issued a breach notification and had not responded to requests for comment as of publication.
ASOS has roughly 17 million customers across 150 countries, with its biggest concentrations in the UK and Europe - exactly the markets with the strictest breach-disclosure clocks. Under UK law, the company has three days to notify the Information Commissioner's Office once a breach is confirmed, and must tell affected customers directly if the exposure is high-risk. Pushing the threat straight to shoppers' phones, rather than just to ASOS executives, suggests the attackers are trying to force a public reckoning before any of that paperwork happens.
Snowflake accounts have been a popular target before - 2024's wave of attacks on customers like Ticketmaster and AT&T came down to stolen credentials, not a flaw in Snowflake itself, and this looks like the same playbook until ASOS says otherwise.