British fashion retailer ASOS has recently confirmed that customers received distressing push notifications linked to a potential data breach involving a third-party service provider, Snowflake. The messages appeared to be threats from hackers, warning ASOS of a full compromise of Snowflake’s data instance, urging the company to engage with them, or face the leak of sensitive information.
:max_bytes(150000):strip_icc():format(jpeg)/ASOS-online-only-fashion-retailer-2968d009d04e43feaff95865cb203dbf.jpg)

On October 6, ASOS took to its Instagram Stories to acknowledge the issue, stating it was investigating the “unauthorised activity” that led to the alarming notifications. The brand expressed its commitment to prioritising consumer protection and ensuring a secure shopping experience.

The troubling alert reportedly contained a message from a group calling itself “Xuanye Group,” with a link to a Telegram channel. Recognising the potential risk to their customers, ASOS advised those who received the notification to disregard it and refrain from clicking on the link provided. The message stated, “Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.”
Although ASOS has not confirmed whether it uses Snowflake’s services, the firm is known to collaborate with various high-profile businesses, including Ticketmaster and AT&T, making the implications of the breach concerning. According to a report by the BBC, the investigation is ongoing, and ASOS has stated it is also cooperating with internal and external specialists, as well as relevant authorities.
In its public statement, ASOS provided some clarity on the nature of the compromised data. The retailer indicated that some basic personal information, such as names and contact details, might have been accessed, but reassured customers that no payment card information or account passwords were believed to have been affected. This revelation is crucial for customers who may be concerned about the security of their financial data.
ASOS, known for its rapid turnaround in the fast fashion industry, sought to reassure its customers that its online platforms are still operating normally during the investigation. “Protecting our customers and maintaining a reliable shopping experience are our priorities. While our investigation continues, please be assured that our website and app are operating as usual,” the company stated. ASOS ended its message by thanking customers for their patience and promising further updates as more information became available.
The announcement of the data breach comes at a challenging time for ASOS, with the company already in the spotlight following the tragic death of its co-founder, Quentin Griffiths. Griffiths passed away earlier this year after a fatal fall from a 17th-floor apartment in Pattaya, Thailand, raising questions surrounding the circumstances of his death. An autopsy at the time revealed no signs of foul play, and he had been alone in the apartment.
Complicating matters further, it has been reported that Griffiths was engaged in two ongoing legal disputes that may have contributed to his stress. These included a case against his estranged Thai wife relating to a business they once shared. Documents associated with these legal matters were discovered in Griffiths’ apartment, hinting at the personal challenges he may have been facing prior to his untimely death.
The UK Foreign Office has confirmed its support for Griffiths’ family and stated that it is in touch with local authorities regarding the situation. As of now, neither ASOS nor the Royal Thai Police has commented on Griffiths’ passing.
As the investigation into the data breach ramps up, the implications for ASOS and its customers remain to be seen. With growing concerns over data security in the digital age, companies like ASOS must navigate these challenges with transparency and efficiency to maintain consumer trust.
