The message linked to a Telegram channel calling itself Xuanye Group, a name extortion trackers hadn’t seen before, per The Record. The channel later posted that payment information “is not affected,” that the app is safe to use, and that the customer data it claims to hold won’t be released for a “designated period.” It posted no samples. So right now there are two separate claims, and only one is confirmed. Confirmed: someone could send a push notification to ASOS customers. Unproven: that they got into ASOS’s Snowflake data.
What ASOS actually said. It restricted access to the notification platforms, brought in internal and external specialists and the relevant authorities, and says the website, app and operations are running normally. It carries cyber insurance, including business continuity cover, with a large global provider, and says it’s too early to quantify any trading impact. ASOS reports 16.5M active customers in over 100 markets. How many of them got the alert, or had data exposed: Undisclosed.
Why the Snowflake line matters even if it’s a bluff. In 2024, Mandiant tied a wave of data theft to Snowflake customer accounts, not the platform: stolen credentials from infostealer logs, used on accounts without MFA. Snowflake’s statement today is the same shape. If ASOS’s tenant turns out to be involved, the question is credentials and access policy on the customer side, not a Snowflake bug.
What we’d do this morning. Treat your push, email and SMS engagement platforms as a broadcast channel to every customer you have, because that’s what an attacker gets with one API key or one marketing-console login. Pull the list of who and what can send to your full audience. Put SSO and MFA on those consoles, scope API keys to the campaigns that need them, and require a second approver for sends to all users. Alert on any full-audience send outside a scheduled campaign. Then check the data side: in Snowflake, review LOGIN_HISTORY for password logins from new IPs, confirm network policies are on, and find service users still authenticating by password. If your marketing stack can read customer tables in your warehouse, map that path too. That link is exactly what this attacker is claiming.
The market read. A 10% move came before ASOS had published anything, off a screenshot. Check Point’s Charlotte Wilson put it as investors “already pricing in the potential consequences” before the company had established what happened. For boards, the lesson is that a customer-visible intrusion gets priced in minutes, so the disclosure clock starts when the alert lands on phones, not when forensics finish.
Desk sheet: unauthorised push about 10am UK, Oct 6. ASOS RNS same day: third-party customer-communication platforms, names and contact details may be accessed, no card data or passwords believed hit. Shares down about 10%. Snowflake: no platform compromise found. Claimed by Xuanye Group on Telegram, no evidence posted. Vendor, record count and initial access: Undisclosed.
