Updated:
Snowflake shares fell about 2% on Tuesday morning, October 6, after ASOS customers received a push notification claiming attackers had compromised a Snowflake instance used by the British online retailer. The message threatened to leak data and directed recipients to Telegram, but the claim had not been independently verified.
The incident put the cloud-data company in the market spotlight even as the alleged intrusion remained under investigation. Reuters reported that ASOS said it was aware of reports about a hack but did not confirm that customer data or its systems had been compromised. The retailer’s app and website appeared to remain operational, according to The Guardian.
Notification raised an unverified breach claim
The alert was reportedly sent through ASOS’s mobile app and addressed to the company’s data protection officer and IT staff. It claimed that the “Snowflake instance” had been compromised and threatened a data leak unless the company engaged with the sender. The notification included a link to a Telegram channel.
Reuters said it could not immediately verify the reports. The Guardian reported that ASOS was investigating whether a hack had taken place. As of the reporting available on Tuesday, neither the scope of any possible access nor whether customer information had been taken was established.
The use of the retailer’s app to deliver the message added a separate concern: the sender appeared able to reach customers through a channel associated with ASOS. Cybersecurity specialists cited by Reuters said that this could indicate access to systems controlling app notifications, but the notification alone does not establish how it was sent or prove that the claimed Snowflake access occurred.
ASOS shares fell more sharply
Investing.com reported Snowflake’s morning decline at about 2%. ASOS stock came under greater pressure in London trading: Reuters reported a fall of more than 11%, while Investing.com later reported the shares down 10.2% at 450.9 pence, after touching 435.5 pence. Those figures reflect different reported points during the session rather than a confirmed closing price.
The episode linked the two companies in investors’ attention because the notification named Snowflake. That reference is an allegation by the sender, not independent confirmation of a breach of Snowflake’s systems or evidence that the cloud provider itself was compromised. Snowflake sells cloud-based data storage and management services to businesses.
Investigation and scope remained unclear
ASOS had not publicly confirmed the extent of any compromise in the reports available Tuesday. Reuters reported the company’s limited response: it was aware of the reports but offered no further confirmation or comment. No verified customer-data totals, affected records, or details about the method of access were reported.
Reuters also noted that a confirmed personal-data breach could carry regulatory reporting obligations in the UK. However, whether such a breach occurred—and what data, if any, may have been affected—remained unknown. The available reporting did not establish a timetable for ASOS to conclude its investigation or announce further findings.
Market reaction preceded confirmation
The sharp move in ASOS shares and the smaller decline in Snowflake came while key facts were unresolved. That distinction matters: the notification triggered a market response, but the underlying breach claim remained unverified in contemporaneous reporting.
For now, the next material development is whether ASOS can substantiate or rule out unauthorized access and clarify whether customer information was exposed. Until the companies or investigators provide verified findings, the notification’s claims should not be treated as confirmation of a data breach.







