Blog
Events

ASOS Cyber Incident: CYJAX on the Third-Party Risk Facing UK Retailers.

On 6 October 2026, ASOS customers received an extortion message through the retailer's own app claiming its Snowflake instance had been compromised. CYJAX looks at what happened, why third-party and cloud platform risk sits at the centre of the incident, and how organisations can monitor their extended supply chain before attackers do.

October 8, 2026
17
min read
Shail Yadav
Marketing Executive
Table of contents
Share

By now, most people in the UK will have heard about the cyber incident that hit ASOS on 6 October 2026. What made it stand out was not a ransomware lock screen or a quiet data leak, but an extortion demand delivered straight to customers' phones through the retailer's own app.

At CYJAX, we track how threat actors pressure their victims, and this incident shows a clear shift in tactics. It also raises a familiar question for every security and risk team: how much of your exposure sits outside your own perimeter, in the platforms and suppliers your business depends on?

The Extortion Message ASOS Customers Received

On the morning of Tuesday 6 October, ASOS app users received a push notification headlined "ASOS HACKED". It was addressed to the company's data protection officer and IT teams rather than to customers, which suggests the attackers used the app's notification platform as a megaphone to reach the business publicly.

The message claimed: "We have fully compromised the Snowflake instance." It went on to say "Engage with us, or we will leak it," before linking to a Telegram channel. Reports of the notification came from users in the UK, US, Germany and Australia, so its reach was international from the outset.

ASOS said in its statement that it took "immediate action to restrict access to the notification platforms" on Tuesday, and that it was working with specialists inside and outside the company, as well as relevant authorities. The retailer also published an update to the London Stock Exchange's Regulatory News Service to keep investors informed.

It is important to separate the claim from what has been confirmed. Snowflake stated later the same day that it had found no compromise of the Snowflake platform itself, and the full scope of any data access at ASOS had not been confirmed at the time of writing. What is confirmed is that a third party was able to push messages to customers through a trusted channel, and that alone carried real consequences.

The Market Impact

The financial effect was immediate. According to The Guardian, the value of ASOS shares on the London Stock Exchange fell by more than 14% after thousands of customers received the notification.

Shares recovered some ground and closed 9.56% after ASOS announced that it held cybersecurity insurance with a large global provider, including business continuity cover. The company added, however, that it was "too early to quantify any potential impact on trading."

This is a useful reminder that the cost of an incident is not limited to the data involved. A single unauthorised message, sent through a channel customers trust, was enough to move the share price of a listed retailer before the facts were established.

What Should ASOS Customers Do Now?

Incidents like this are quickly followed by opportunistic scams, as criminals know customers are worried and looking for answers. If you use ASOS, the following steps will help reduce your risk:

  • Do not click on links in the notification.
  • Visit the official ASOS website directly for updates.
  • Watch out for emails, texts or calls offering refunds, compensation or help with your account, as scammers will exploit this type of incident.
  • Use different passwords for each of your online services.
  • Enable two-step verification on your email and banking accounts.
  • Keep an eye on your online transactions for anything unusual.

What Does the ASOS Cyber Attack Tell Us About Third-Party Security Risk?

The ASOS incident involved two pieces of technology that sit outside the retailer's core estate: a cloud data platform and a customer notification platform. Neither is unusual. Modern retailers rely on dozens of software-as-a-service providers to store data, run marketing and reach customers, and every one of those connections extends the attack surface.

As we explored in our guide to cyber supply chain risk management, perimeter security alone is no longer adequate when so many digital systems are interconnected. Several of the challenges outlined there map directly onto this case.

Lack of visibility. Organisations often have limited insight into how third-party platforms are configured, who holds access to them and whether credentials tied to them are circulating among threat actors. An account with permission to send push notifications is rarely treated as a critical asset, yet here it became the attacker's loudest weapon.

Limited control. Even when a provider's own infrastructure is secure, as Snowflake has stated in this case, the customer's instance is only as strong as the identities and access controls around it. Snowflake has previously been linked to breaches affecting a number of major companies, which in earlier cases centred on compromised customer accounts rather than a flaw in the platform. Shared responsibility means the gap usually sits on the customer side.

Emerging technologies. Cloud adoption brings new vulnerabilities that require specialist expertise and proactive risk management. Data warehouses, marketing automation and messaging tools are often owned by business teams rather than security teams, which makes them easy to overlook during risk assessments.

Evolving extortion tactics. Threat actors continually adapt to put pressure on victims. Rather than contacting the company privately, the attackers in this case broadcast their demand to customers, turning a trusted channel against the brand and forcing a public response before any investigation could conclude. We expect other groups to note how much attention this approach generated for relatively little effort.

How Can Organisations Reduce Third-Party Cyber Risk?

No organisation can eliminate third-party risk, but it can be managed with a structured approach. Drawing on the best practices CYJAX recommends for supply chain risk management, these are the steps we would prioritise considering the ASOS incident.

  1. Identify critical suppliers and platforms. Map every third party with access to your systems or data, including customer-facing tools such as push notification, email and SMS platforms. Knowing what each provider does and what it can reach tells you where the highest risk sits.
  1. Treat customer messaging as a critical asset. Any account that can send messages to your customers can damage your brand without stealing a single record. Restrict access, enforce strong authentication and set alerts for unusual sending activity.
  1. Enforce strong identity controls on cloud platforms. Require multi-factor authentication on all accounts connected to data platforms, rotate credentials regularly and remove dormant users and service accounts.
  1. Perform regular risk assessments. Review how third parties handle data, what security protocols they follow and how mature their incident response capability is.
  1. Set clear contractual requirements. Agree data protection standards and incident reporting timelines with suppliers before something goes wrong.
  1. Monitor continuously. Point-in-time assessments go out of date quickly. Ongoing monitoring of your suppliers' exposure, including leaked credentials and mentions on criminal forums, gives you early warning rather than a post-incident discovery.
  1. Plan your incident response together. Coordinate response plans with key suppliers so roles, communication routes and escalation paths are clear, including how you would speak to customers if a trusted channel were misused.
  1. Stay informed on emerging threats. Threat intelligence on new extortion tactics, active groups and the platforms they are targeting helps you adjust defences before those tactics reach you.

How CYJAX Helps You Monitor Third-Party Risk

The ASOS incident shows that the first sign of a third-party compromise can arrive in the most public way possible. The goal for security teams is to see the warning signs earlier, while there is still time to act quietly.

CYJAX helps organisations monitor third-party risk by watching their extended supply chain for compromise indicators, leaked credentials and dark web mentions. Our analysts track threat actor activity across criminal forums, marketplaces and messaging channels such as Telegram, and our cyber threat intelligence turns that activity into clear, validated insight your team can use without wading through noise.

If you want to understand your exposure across the suppliers and platforms you rely on, book a demo with CYJAX or ask one of our analysts about a threat actor, emerging threat or potential exposure.

FAQs

Frequently asked questions

On 6 October 2026, ASOS app users received a push notification titled "ASOS HACKED". It claimed attackers had compromised the retailer's Snowflake instance and threatened to leak data unless ASOS engaged with them through a Telegram channel.

At the time of writing, ASOS had not confirmed whether any customer data was accessed. The retailer said it restricted access to its notification platforms and is working with specialist advisers and the relevant authorities.

Snowflake said it had found no compromise of its platform. Any unauthorised access would therefore most likely relate to the ASOS account or the credentials connected to it, rather than a flaw in Snowflake's own infrastructure.

ASOS shares fell by more than 14% during trading on 6 October before closing down 9.56%, after the company confirmed it held cybersecurity and business continuity insurance.

Avoid clicking links in unexpected notifications, emails or texts. Go directly to the official ASOS website or app for updates and be wary of anyone offering refunds or compensation linked to the incident.

Third-party cyber risk is the exposure an organisation faces through the suppliers, cloud platforms and service providers it relies on. A weakness in any of those connections can lead to data loss, disruption or reputational damage for the business itself.

Retailers depend on a wide range of cloud services for data storage, marketing, payments and customer messaging. Each provider holds access or data that attackers can target, and many of these tools sit with business teams rather than under direct security oversight.

Threat intelligence gives early warning of supplier compromise by tracking leaked credentials, dark web mentions and threat actor chatter about the platforms you use. That allows security teams to act before an incident becomes public.

Subscribe for weekly updates

Receive our latest cyber intelligence insights delivered directly to your inbox

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Share
Get started

Get Started with CYJAX CTI

Empower Your Team. Strengthen Your Defences.CYJAX gives you the intelligence advantage: clear, validated insights that let your team act fast without being buried in noise.

Link Copied