What happened on the app
Shoppers reported seeing a push notification that read, "Dear Asos DPO and IT, we have fully compromised the Snowflake instance," followed by "Engage with us, or we will leak it," with a link pointing to a Telegram chat. Bloomberg viewed the message, which circulated heavily on social media. The notification seemed to point to the British online apparel seller's data protection officer and to Snowflake Inc.'s platform.
Market moves
In London, Asos fell by as much as 14.5% - its sharpest intraday swing since May 2023 - before recovering some ground. Snowflake fell up to 3.2% in New York premarket trading.
A breach claim can move a share price before anyone confirms what happened. Market Briefs covers corporate security free every weekday.
Who said what
An Asos spokesperson declined to provide an immediate comment, while Snowflake did not return a request for comment right away. "This is an unusually brazen and threatening message," said Marijus Briedis, the chief technology officer at NordVPN. "A message apparently written for ASOS's data protection and IT teams has instead been pushed directly to customers through the company's own app notification system. That suggests someone has gained unauthorised access to at least part of Asos's systems, although we don't yet know how extensive that access is."
Why it matters and context
By the close of its 2026 fiscal year, Asos reported 16.4 million active customers across more than 100 markets, making any security scare quick to reverberate. Snowflake sells cloud software that lets companies organize and analyze data, run cross-business analytics and produce rapid reports. Its website lists big-name clients including OpenAI, the Walt Disney Co. and Novo Nordisk.
Cyberattacks are multiplying, helped by AI tools and organized groups such as ShinyHunters that go after major organizations to steal data. In the UK, a number of companies have faced attacks in the recent past. An attack last year led to months of disruption at Marks & Spencer Group Plc and forced a halt to online clothing and home orders.
Around the same period, other victims included rival Co-op as well as the luxury department store Harrods. A major cyberattack last year struck Jaguar Land Rover as well, leading the automaker to shut factories across the globe.
What this means for your money: big retailers run on sprawling tech stacks, and any hint of a breach can sway sentiment fast. Watch for clarity on the scope of access, whether customer data was touched, and how quickly systems are secured.
Third-party platform risk is now a direct equity risk. Join Market Briefs free and follow the fallout.
