ASOS has confirmed a data breach affecting customer personal data, disclosed in an email to customers on 8 October 2026. The retailer said the attacker gained access by impersonating a trusted contact to obtain login credentials for an employee account, which were then used to access information on third‑party platforms used by ASOS. The incident did not involve payment information and ASOS noted that its operations were not impacted.
The breach involved access to third‑party platforms used to communicate with customers, enabling the attacker to send a legitimate‑looking push notification to ASOS customers. The message claimed that a Snowflake instance had been compromised and urged engagement. Snowflake stated there was no compromise of its platform, though industry observers have pointed to potential links via a marketing platform used by ASOS built on Snowflake Cortex AI.
Public reporting indicates that the data exposed could extend beyond basic contact details, potentially including names, addresses, phone numbers, emails, customer numbers and recent site searches. The incident follows chatter about the Telegram channel behind the push notification and ongoing scrutiny by researchers and media outlets, with ASOS, Snowflake and related parties continuing investigations.