Executive Summary
Publication Date: October 6, 2026
On October 6, 2026, a significant cybersecurity incident was reported by ICE (https://www.ice.co.il/digital-140/news/article/1132515), detailing a breach of the ASOS cloud infrastructure, specifically targeting the Snowflake data platform and the company’s notification system. Attackers exploited these systems to send a direct push notification to thousands of ASOS app users, including Israeli customers. The notification claimed that the attackers had achieved full compromise of the Snowflake environment and threatened to leak sensitive data unless the company’s Data Protection Officer (DPO) and IT team engaged with them via a Telegram channel. This incident underscores the evolving threat landscape facing organizations leveraging cloud-based data platforms and highlights the critical need for robust cloud security and incident response protocols.
Technical Information
The breach of ASOS’s cloud environment represents a sophisticated attack vector, combining elements of credential compromise, cloud infrastructure exploitation, and extortion via direct user notification. The attackers’ ability to commandeer the notification system and reach all app users demonstrates a deep level of access, likely achieved through compromised credentials or abuse of privileged API keys associated with either the notification system or the Snowflake environment.
The Snowflake platform, a widely adopted cloud-based data warehousing solution, is designed to centralize and process vast amounts of sensitive business and customer data. In this incident, the attackers claimed “full compromise” of the Snowflake instance, which, if accurate, could potentially expose a wide array of sensitive information, including customer records, transaction histories, and internal business analytics. The precise scope of data accessed or exfiltrated remains unclear as of the publication date, but the attackers’ public extortion attempt suggests they possess at least some level of privileged access.
The attack unfolded in several distinct phases. Initial access was likely obtained through credential theft, phishing, or exploitation of weak authentication mechanisms. Once inside, the attackers escalated privileges to gain control over the notification system, enabling them to broadcast a push notification to all ASOS app users. The message, written in both English and Hebrew, explicitly referenced the Snowflake compromise and included a Telegram link for further communication, a tactic commonly associated with ransomware and data extortion groups.
The technical sophistication of this attack is evident in the attackers’ ability to pivot from initial access to lateral movement within the cloud environment, ultimately achieving persistence and command over critical business systems. The use of Telegram as a command-and-control (C2) and extortion channel is consistent with recent trends observed in financially motivated cybercrime, where attackers seek to maximize pressure on victims by leveraging public communication channels and threatening large-scale data exposure.
Indicators of compromise (IOCs) associated with this incident include the specific push notification content sent to ASOS app users, any unusual access patterns or credential use within Snowflake logs, and the presence of unauthorized Telegram communication links within internal or customer-facing systems. Organizations utilizing Snowflake or similar cloud data platforms should immediately review access logs for anomalous activity, rotate all credentials and API keys, and implement enhanced monitoring for suspicious authentication attempts.
The attack also highlights the importance of securing notification systems, which are often overlooked in traditional security architectures. These systems, if compromised, can be weaponized to deliver malicious content, sow panic among users, and amplify the impact of a breach. Ensuring that notification systems are protected by strong authentication, least-privilege access controls, and regular security audits is essential to mitigating this risk.
From a threat intelligence perspective, the tactics, techniques, and procedures (TTPs) observed in this incident align with those of financially motivated extortion groups targeting cloud environments. The attackers’ use of direct communication with the victim organization, public threats to leak data, and reliance on third-party messaging platforms for negotiation are hallmarks of modern ransomware and data extortion campaigns. While no direct attribution to a known advanced persistent threat (APT) group has been made as of this report, the incident bears similarities to recent breaches involving Snowflake and other SaaS platforms.
The MITRE ATT&CK framework provides a useful lens for analyzing this incident. Relevant techniques include Valid Accounts (T1078) for initial access, Exploit Public-Facing Application (T1190) for potential exploitation of the notification system, Cloud Service Dashboard (T1098.003) for persistence, Application Layer Protocol: Web Protocols (T1071.001) and Use of Third-party Services (Telegram) for command and control, Exfiltration Over Web Service (T1567) for potential data theft, and Data Manipulation (T1565) for the impact phase.
Mitigation strategies should focus on immediate containment and remediation. This includes a comprehensive review of all Snowflake and notification system access logs, immediate rotation of all credentials and API keys, enhanced monitoring for further attacker communications, and coordination with law enforcement and incident response teams. Affected customers should be notified in accordance with regulatory requirements, and organizations should review their cloud security posture to ensure robust credential management, multi-factor authentication, and least-privilege access controls are in place.
In conclusion, the ASOS breach serves as a stark reminder of the evolving threat landscape facing organizations operating in the cloud. Attackers are increasingly targeting SaaS platforms and leveraging direct communication with victims to maximize the impact of their campaigns. Proactive security measures, continuous monitoring, and rapid incident response are essential to defending against these sophisticated threats.
References
ICE (Hebrew): אתר ההזמנות הגדול בישראל נפרץ: ההודעה החריגה שנשלחה ללקוחות (https://www.ice.co.il/digital-140/news/article/1132515)
CyberNews: Asos data breach: Hackers threaten leak via app message (https://cybernews.com/security/asos-data-breach-notification-message-hacker/)
The Mirror: ASOS hacked live updates: Customers sent bizarre 'snowflake' notification (https://www.mirror.co.uk/news/uk-news/asos-hacked-notification-snowflake-app-37739601)
The Independent: Asos customers receive threatening notification in apparent hack (https://www.independent.co.uk/bulletin/news/asos-hacked-notification-snowflake-message-b3062040.html)
Huffington Post UK: ASOS 'Snowflake Hack': App Users Report 'Scary' Notification (https://www.huffingtonpost.co.uk/entry/asos-snowflake-hack_uk_6ac4b935e4b024c9b491860d)
BBC: ASOS app users receive notifications from hackers in apparent breach (https://www.bbc.com/news/articles/cj62ylzpr6d3o)
Metro: Asos hack fears after thousands of shoppers sent sinister phone message (https://metro.co.uk/2026/10/06/asos-shoppers-sent-sinister-phone-message-threatening-leak-information-29683447/)
The Guardian: Asos customers receive phone alerts saying retailer has been hacked (https://www.theguardian.com/business/live/2026/oct/06/euro-france-central-bank-interest-rates-bonds-latest-live-updates)
Rescana is here for you
At Rescana, we understand the complexities and risks associated with third-party and cloud-based environments. Our advanced TPRM platform empowers organizations to continuously monitor, assess, and mitigate cyber risks across their entire digital supply chain. We are committed to helping you stay ahead of emerging threats and ensuring the resilience of your business operations. For any questions or further information, please contact us at info@rescana.com.



