← Back to the feed

Unverified Snowflake breach claim sends Asos shares tumbling

The Register ·

Asos customers reported receiving a rogue app notification claiming hackers had compromised the retailer’s Snowflake instance and threatening to leak data. The claim has not been verified, and the notification alone does not show that customer information was accessed; how it was sent is also unclear.

The message linked to a Telegram channel called “Xuanye Wen Gateway” and was addressed to Asos’s data protection officer and IT team. Asos’s share price fell by about 12 per cent after reports of the notification, then recovered slightly. Snowflake customers were targeted in a major data theft campaign in 2024, prompting the platform to introduce administrator controls requiring multi-factor authentication.

  • A rogue alert claimed Asos’s Snowflake data was compromised.
  • No customer data theft has been verified.
  • Asos shares fell around 12 per cent after the reports.

New here? Start with this

Asos is one of the UK's largest online fashion retailers, with millions of customers purchasing clothing and accessories through its platform each year. Snowflake is a cloud database service used by major companies to store vast amounts of customer and business data. If a hacker were to successfully breach such a system, they could potentially access sensitive information including customer addresses, payment details, and shopping histories.

Asos customers received a notification this week claiming that hackers had compromised the company's Snowflake database and threatening to release customer data. However, the claim remains unverified and there is currently no evidence that customer data was actually accessed or that the message came from genuine hackers. The method by which the notification was sent to customers' devices also remains unclear.

A significant data theft campaign targeted Snowflake customers in 2024, successfully breaching multiple companies and accessing their stored data. Snowflake responded by introducing stronger security requirements, including mandatory multi-factor authentication for database administrators. Because Asos holds extensive personal and payment information about millions of customers, a successful breach would potentially affect a large number of people.

Both sides, in good faith

The strongest fair case each way — we don't pick a winner.

The case for

An unverified message triggering a 12 per cent share drop exemplifies how speculation can distort markets and harm businesses unfairly. Without evidence of actual data compromise, the claim's origins remain unclear and it may constitute social engineering or market manipulation. Companies and investors should demand substantiation before treating claims as credible, rather than reward potential hoaxes with outsized market reactions.

The case against

Dismissing security claims as merely unverified is naive when Snowflake has demonstrably been targeted in major campaigns and Asos holds millions of customer records. The company has a fiduciary and ethical duty to investigate thoroughly and inform stakeholders of genuine risks rather than wait for absolute proof before acting. The market's concern reflects real vulnerability in the current threat landscape, and responsible security posture means treating potential incidents with urgency until verified otherwise.

Culture Fashion Software Technology

Read the full article at the source →

Originally published by The Register as “Asos app delivers a data leak threat instead of fast fashion”.