Tendvane

← All articles

AccountsOctober 7, 2026

ASOS shoppers got a push notification saying the shop had been hacked. It was genuine.

Around ten in the morning on Tuesday, ASOS customers in the UK felt their phones buzz. The notification came from the ASOS app itself, and it was not about a sale. It was addressed to the company's own data protection officer.

"Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it." Signed with a handle, and carrying a link to a Telegram channel. ASOS has since confirmed that third-party platforms it uses to communicate with customers were accessed without authorisation, says it restricted access immediately, and is working with specialists and the authorities. Basic personal information, names and contact details, may have been exposed. Payment card details and account passwords were not, according to the retailer. Snowflake, the data warehousing company named in the message, says its own investigation has so far found no compromise of its platform.

What makes this one worth paying attention to is the delivery route. A push notification from an app you installed yourself is about the most trusted channel there is, and someone else got to use it. Even if nothing more than names and email addresses moved, that is exactly the raw material for the next few weeks of convincing "ASOS security update" emails. Assume they are coming. If a message about this lands, do not follow the link in it; open the app or type the address yourself and look for the notice there.

ASOS also has not said how many customers were affected, so keep half an eye on your order emails. And if one of those follow-up messages has already been clicked on, Tendvane's safety check is a quick way to see what turned up on the PC afterwards.

Sources

Download Tendvane