P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

ASOS confirms the 10am notification was unauthorised, cites third-party platforms and does not name Snowflake

ASOS's RNS at 15:15 BST, about 5 hours 15 minutes after the notification it dates at around 10am, confirms it was unauthorised and says third-party platforms were involved and names and contact details may have been accessed. It does not mention the Snowflake claim the message made.

By Parminder Kumar Sharma · · 21 min read

A smartphone lying on a dark desk showing a shopping app of blank product tiles, with one wide notification banner of empty rounded shapes dropped across the top, outlined in thin amber. Nothing carries any lettering.

An RNS at 15:15, about five hours after the notification, and no mention of Snowflake

ASOS's own announcement puts the unauthorised notification "at around 10am today". The announcement, RNS number 8604X, headed "Update regarding cyber incident", reached the market at 15:15:21 BST, by the London Stock Exchange's list of ASOS announcements and the timestamp on a news-wire copy. That is about 5 hours 15 minutes after 10am (derived; "around 10am" is ASOS's rounding) and about 5 hours 20 minutes after TechRadar's first-sightings time of "around 9.55am". Until 15:15 the company's only words, as reported, were two holding lines to journalists.

The RNS is short. It says that ASOS "can confirm that, at around 10am today, an unauthorised customer notification was sent to ASOS customers". It says ASOS is "investigating unauthorised activity involving third-party platforms that we use to communicate with customers", that it "took immediate action to restrict access to the notification platforms", and that it is working with advisers and "all relevant authorities". It says "basic personal information including name and contact details may have been accessed" and that ASOS does not believe payment-card information or account passwords were impacted. It adds that the website and app are operating as normal and that "it is too early to quantify any potential impact on trading". The message the customers saw, as the BBC, The Register and Infosecurity Magazine all quote it, read: "Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it." The RNS does not mention Snowflake.

Here is what the announcement does not establish.

  • When ASOS became aware. The notification time is not the awareness time, and the RNS says nothing about when ASOS knew or what it did in the five hours.
  • That the Snowflake claim is true or false. The message names Snowflake. The RNS is silent on it, no Snowflake statement was found, and the BBC says it is not known whether ASOS is a Snowflake customer.
  • How it happened. Which third-party platforms, which access, and what the sender could reach are not stated. The Register said so before the RNS and the RNS does not change it.
  • How many people or what data. "May have been accessed" is ASOS's wording. Whose data, how much and by whom are not stated, and nor is how many customers received the notification. The RNS's own boilerplate gives 16.5m active customers, which is the size of the base, not a count of recipients.
  • Who is behind it. The BBC says the group that signed the message is new and had posted three times. Infosecurity reports that the channel's administrator also said payment information was not affected. That is the sender's word, and it matches ASOS's belief without showing what the sender holds.

The market had moved well before the RNS, and it did not move back after it. On Monday 5 October ASOS closed at 502.00p. At 14:37:35 BST the London Stock Exchange's own page showed 449.50p, down 10.46%. After the announcement the figures were no better: 448.98p, down 10.56%, at 15:51 on ASOS plc's own site, and 445.00p, down 11.36%, at 15:58:07 on the exchange page (delayed by at least 15 minutes, trading status "Normal - Regular Trading"). The day's range so far is 429.00p to 503.00p, and the opening price, 485.00p, was already 3.39% under Monday's close, before any outlet's earliest sighting time. The exchange page lists a market capitalisation of £601.50m, which is 502.00p times about 119.8 million shares, a count that also falls out of ASOS's 5 October holdings notice. At 445.00p that is about £533m, roughly £68m less than on Monday's close (derived, approximate).

The reported size of the fall, by source and time. It is a snapshot, and no two sources give the same one

  1. Source
    Reuters, as syndicated by KSL
    Time (BST)
    About 10:51
    Figure
    Shares down "more than 11%"
  2. Source
    Investing.com, via Yahoo Finance UK
    Time (BST)
    11:54
    Figure
    Down 13.2% at worst, about 9% lower at the time of writing
  3. Source
    The Register
    Time (BST)
    6 October, not timed here
    Figure
    "Around 12 percent", recovered slightly since
  4. Source
    ASOS plc's own investor site
    Time (BST)
    14:20
    Figure
    451.00p, down 10.16%
  5. Source
    London Stock Exchange page, delayed
    Time (BST)
    14:37:35
    Figure
    449.50p, down 10.46%. Open 485.00p, high 503.00p, low 429.00p
  6. Source
    ASOS plc's own investor site
    Time (BST)
    15:51
    Figure
    448.98p, down 10.56%
  7. Source
    London Stock Exchange page, delayed
    Time (BST)
    15:58:07
    Figure
    445.00p, down 11.36%. Day's low 429.00p

"From the ASOS app" was true of the channel and not of the author

A push notification from the ASOS app carries the app's name and appears on the lock screen among everything else the app sends. ASOS's help page tells customers they can opt in to "stock notifications, delivery and returns updates, and discounts and new drops", and the App Store entry lists "sale alerts and promotional nudges". Delivery updates are the kind of message customers expect and read. The label on a notification says which app delivered the words. It does not say who wrote them or whose platform they passed through.

The RNS now says the second half aloud. The unauthorised activity involved "third-party platforms that we use to communicate with customers", and ASOS restricted access to "the notification platforms". So the label read ASOS app, and behind it stood at least one platform run by another company, with credentials the customer has never seen and a security posture the customer never chose. A Check Point executive told the BBC that millions of people trust notifications from apps "because they are supposed to come directly from the company". That borrowed authority is what the message relied on, and the RNS says whose controls it was borrowed through, in the plural.

ASOS's own cyber security page shows how customer cues are usually built. For email it says its logo, shown through BIMI, "means the email is legit and came straight from us". For social media it says to look for "the blue tick". The page, read at 14:48 BST, does not mention notifications at all. It gives customers a check for an email and one for a social account, and none for the app.

One fact follows from the RNS itself, as distinct from what the message claimed: someone was able to drive a channel the app trusts, and ASOS says third-party platforms were involved. How is not stated. It could be a stolen credential, a key, a supplier account, a flaw or a person; no source says which. That fact is more immediate than the Snowflake claim, and a different one. A Horizon3 researcher told the BBC that sending a push to ASOS's app users "would require access to the company's notification system, which is separate from the Snowflake data platform". An ESET adviser, quoted by Infosecurity, said it suggests access to at least some connected systems but "doesn't prove their full claims". The RNS describes the platforms as third-party and does not say whether, or how, they relate to any Snowflake instance. The vendor quotes are expert readings made without sight of ASOS's logs. They are inference, and so is this paragraph.

Four stacked cards joined by arrows. One, confirmed by ASOS: an unauthorised customer notification was sent at around 10am. Two, partly stated: third-party platforms used to message customers were involved, but which and how is not stated. Three, may: name and contact details may have been accessed. Four, unconfirmed: the claim that the Snowflake instance was fully compromised, which the RNS does not mention.
Drawn from ASOS plc's RNS 8604X of 6 October 2026 (15:15:21 BST) and the BBC, The Register, Infosecurity Magazine and Reuters reports, read to 16:14 BST. Statuses are the author's reading of what those sources state.

One more route is worth naming as a question, not a finding. A researcher quoted by Infosecurity and TechRadar said ASOS uses a marketing platform that runs on Snowflake, "making the connection indirect". If a warehouse feeds the system that decides who gets a message, the two claims in the notification could share a route. If it does not, they could not. No source read says which is true here, and no source links any named supplier to this message. The RNS does not name its third-party platforms.

What ASOS has said, and when

ASOS has spoken three times, as reported. Reuters, in an article stamped about 10:51 BST (the time on the syndicated copy, which I read as Utah time), says an ASOS spokesperson "was aware of the reports but did not confirm or comment further". LADbible, published at 13:00 BST, says it approached the company, used the customer-service chat, where it met an AI chatbot and then a human agent, and that the line repeated in a statement was: "We're aware of the notification and are currently investigating. We don't have any further information to share at this stage, but we'll provide an update as soon as we know more." The article did not make clear whether that was a press statement or a chat script, and LADbible updated it at about 15:42 BST to carry the RNS. The third is the RNS at 15:15:21. The BBC page, last modified at 11:37 BST, still says ASOS "did not immediately respond" to its requests. That was true when written and is out of date.

Reading the dated points together gives two rough intervals. If the first sightings were about 09:55 (TechRadar's "around 9.55am BST") and the Reuters line about 10:51, the first on-the-record acknowledgement came about 56 minutes after the first reports. The RNS came about 5 hours 20 minutes after them. All of those times are approximate, and the sightings and Reuters times are secondary, so treat the intervals as derived and indicative. The one time ASOS itself gives is "around 10am".

A vertical time axis from 09:30 to about 16:30 BST on 6 October 2026, drawn to scale. Outlet-reported points: 09:41 site normal, about 09:55 first sightings, 10:49 BBC publishes, about 10:51 Reuters line, 11:54 shares down 13.2% at worst, 13:00 LADbible carries ASOS's chat line. Read on ASOS's or the exchange's pages: about 10:00 ASOS's own time, prices at 14:20, 14:37, 15:43 and 15:51, no RNS at 14:41, and the RNS at 15:15.
Times are as each outlet gave them; the 10:51 Reuters time is read from KSL's stamp as Utah time. ASOS plc's site, its RNS and the London Stock Exchange page were read directly. Ticks are to scale at 1.75 pixels a minute.

Stated and not stated about the ASOS notification, as at 16:14 BST on 6 October 2026

  1. Question
    Was a message sent that ASOS did not authorise?
    Stated
    ASOS RNS: "an unauthorised customer notification was sent to ASOS customers" at "around 10am"
    Not stated
    How many received it, on which devices, or the exact time
  2. Question
    How did it happen?
    Stated
    "Unauthorised activity involving third-party platforms that we use to communicate with customers". Access to the notification platforms restricted
    Not stated
    Which platforms. Which credential, key, account, flaw or person. How the sender got in
  3. Question
    Was personal data reached?
    Stated
    "Basic personal information including name and contact details may have been accessed". Payment cards and account passwords not believed affected
    Not stated
    Whose data, how many people, whether it was taken, by whom. Whether any leak has happened
  4. Question
    Is Snowflake involved?
    Stated
    The message says the instance is fully compromised. The BBC: not known if ASOS is a Snowflake customer
    Not stated
    Anything in the RNS. Any Snowflake statement. Any confirmation or denial
  5. Question
    Who is behind it?
    Stated
    A new group's name signs it; its Telegram channel was created the same day and had three posts (BBC)
    Not stated
    Who the people are. Whether the claim is genuine
  6. Question
    Has anyone else spoken?
    Stated
    ASOS: working with "all relevant authorities". Nothing found from the ICO (news page) or on the NCSC site (search for ASOS: no results). One search summary says the NCSC offered help; its source was not readable and the claim is unverified
    Not stated
    Which authorities. Whether the Commission was notified. A notification need not be public
  7. Question
    Business impact?
    Stated
    Website and app operating as normal. "Too early to quantify any potential impact on trading". Cyber insurance held
    Not stated
    Any figure for cost or customers lost

On the company's own channels, ASOS plc's news page had its newest item dated 24 September 2026, so the RNS is the only place the incident is addressed. At 14:41 BST the RNS feed and the exchange's list of ASOS announcements had a holdings notice of 5 October as the newest entry; the list now shows the RNS at 15:15:21 with the feed total up from 1,165 to 1,166 releases. The notifications help page and the cyber security page on asos.com, read in a browser at 14:47 and 14:48 BST, do not mention the incident. All of that is a statement about those pages at those minutes, and any of it can change.

Snowflake in 2024: context, not evidence about ASOS

The message names Snowflake, and Snowflake has a history that makes the name land. This section is context from Snowflake's own statements and its documentation, and none of it is evidence about ASOS. In its 2024 post, dated 31 May 2024 on its Community site and updated through 10 June 2024, Snowflake said it had "not identified evidence suggesting this activity was caused by a vulnerability, misconfiguration, or breach of Snowflake's platform", that it "appears to be a targeted campaign directed at users with single-factor authentication", and that threat actors "have leveraged credentials previously purchased or obtained through infostealing malware". It told customers to enforce multi-factor authentication on all accounts, set up network policy rules to allow only authorised users or trusted locations, and reset and rotate credentials. The Register adds that a hacking spree later taken to court compromised more than 165 organisations; that figure is not in Snowflake's post.

Two things in Snowflake's current documentation matter now. The documentation on network policies says: "By default, Snowflake allows users to connect to the service and internal stage from any computer or device." Its plan for ending single-factor passwords says Snowflake is requiring MFA for all human password users and disallowing passwords for service users, and its table of estimated dates lists "Aug. 2026 - Oct. 2026" for strong authentication for all users. That window is running today. Whether any ASOS account was covered, or was ever single-factor, is not stated anywhere.

The 2024 pattern is worth holding in mind and worth not over-applying. In 2024 the route was stolen credentials used against accounts without MFA, and Snowflake said its platform was not the point of failure. ASOS's RNS names third-party communication platforms and not a data warehouse, and says nothing of how access was gained. If a Snowflake account at ASOS was reached at all, nothing yet says it was reached the same way. A rogue push message is not something a warehouse login alone would explain, which is why the claim and the channel have to be kept apart.

What UK law and the listing rules say, quoted and not applied

The controller named in ASOS's privacy policy is ASOS.com Limited, "the data controller" for "all ASOS services". The RNS was issued by the listed company, ASOS plc, and speaks as "we". They are different legal entities with different duties, and the sources do not say which has done what. Below are the words of the provisions, read on legislation.gov.uk (Article 4, Article 33, Article 34 of UK GDPR; Article 7 and Article 17 of UK MAR) and on the ICO's pages, with no conclusion about ASOS.

UK GDPR and UK MAR wording as read on 6 October 2026, and what the sources do not establish

  1. Provision
    UK GDPR Article 4(12)
    What it says
    A personal data breach is "a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data"
    What is not established
    ASOS says personal information "may have been accessed". Whether it has concluded that a personal data breach occurred is for the controller to assess, and the RNS does not say
  2. Provision
    UK GDPR Article 33(1)
    What it says
    The controller must notify "without undue delay and, where feasible, not later than 72 hours after having become aware of it", unless the breach "is unlikely to result in a risk"
    What is not established
    When ASOS became aware. Whether it has notified the Commission. "All relevant authorities" does not name it. Since 30 September 2026 the text says "the Commission", defined as the Information Commission
  3. Provision
    UK GDPR Article 34(1)
    What it says
    Where the breach "is likely to result in a high risk", the controller "shall communicate the personal data breach to the data subject without undue delay"
    What is not established
    Whether ASOS has assessed the risk as high, or will write to customers. The RNS says only that an update will be provided as appropriate
  4. Provision
    UK MAR Article 17(1)
    What it says
    "An issuer shall inform the public as soon as possible of inside information which directly concerns that issuer."
    What is not established
    Whether the matter is inside information (Article 7(1)(a): information "of a precise nature, which has not been made public" that "would be likely to have a significant effect on the prices"). The RNS text read carries no statement on it. No conclusion is drawn
  5. Provision
    UK MAR Article 17(4)
    What it says
    Disclosure may be delayed on the issuer's own responsibility if immediate disclosure is likely to prejudice its legitimate interests, delay is not likely to mislead the public and confidentiality can be ensured
    What is not established
    Whether any delay was used, or why. The RNS came about 5 hours 15 minutes after the time ASOS gives for the notification, and customers were reporting the notification from about 09:55

Four cautions on that table. First, the ICO's reporting page says that if a risk is likely, "you must notify us, as soon as possible, and where feasible within 72 hours", and that if the risk is high you "must also notify those people without undue delay". The page also carries a note that the guidance is under review since the Data (Use and Access) Act. Second, the ICO transitioned to the Information Commission on 30 September 2026, which is why Article 33 now reads "the Commission" while the guidance still says ICO. Third, the 72 hours run from the controller's awareness, not from the notification and not to the public; an earlier briefing on a police force that identified an incident on the 14th and disclosed it on the 25th covers how the regulator's clock and the public one differ. As arithmetic only: if "around 10am", the time ASOS gives for the notification, were taken as a start, 72 hours would run to about 10:00 on Friday 9 October 2026 (derived). ASOS has not said when it became aware. Fourth, the ICO's news page, read at 16:08 BST, had nothing on ASOS, and its newest item was dated 1 October.

UK MAR Article 17 is in force on the legislation.gov.uk page, which says it is up to date with changes in force on or before 5 October 2026 and records a revocation by the Financial Services and Markets Act 2023 as a change yet to be applied. For the share price itself, the exchange page showed regular trading and no suspension. That is all the sources establish on the listing side, and ASOS may have good reasons for its timing that its announcement does not give.

The same channel exists wherever there is an app with push permission: retailers, banks, councils and NHS trusts and their apps among them. The NCSC has no guidance specific to push notifications; its search for the term, read at 14:45 BST, returns 17 items and none is about app push messaging. The nearest are its guidance on protecting what an organisation publishes on social media and on protecting SMS messages used in business processes. The social media guidance asks for a "content workflow to manage and enforce the creation, approval, and publication of content", switched-on access logging as "an audit trail for unauthorised posts", and, if a channel is hijacked, says the priority is "regaining control of the account to contain any damage". Applying that to a push console is this briefing's inference, not NCSC advice. A similar case this week was Microsoft's X account, where two posts were not its own and the cause was not said.

What to do, in the order worth doing it

Take this with you

For any organisation with an app and a way to message customers

  • Inventory every system that can send a customer a message: push, email, SMS and in-app, including the third-party platforms that deliver them. For each, record who holds its credentials, keys and tokens.
  • For each third-party messaging or marketing platform, record what personal data it holds, who at the supplier can reach it, how you would hear of an incident there, and how fast you can cut its access. ASOS says it restricted access to its notification platforms; know in advance where your switch is.
  • Require strong authentication and IP allow-lists on every console and programme interface that can broadcast, and keep the right to send separate from the right to administer.
  • Give each push-provider key one purpose and one environment, rotate it on a schedule and on every staff or supplier change, and keep it out of code and shared documents.
  • Put rate limits and a second-person approval on any broadcast to a large audience, so that one credential cannot reach every customer alone.
  • Alert on sends outside change windows, on new audiences and on newly created keys, and route the alert to the security on-call, not only to the marketing team.
  • Write a holding statement now, and build an in-app banner or inbox route that does not depend on push, because push may be the channel you need to switch off.
  • Tell customers in advance what you will never ask for by notification, and give them a place inside the app to check that a message is genuine. Email and social media usually have such a cue and push usually has none.
  • Where you hold data in Snowflake or another cloud data platform: enforce MFA for every human user, restrict sign-in with network policies, move service accounts off passwords and rotate credentials, as Snowflake's own guidance has said since 2024.
  • Rehearse the clocks. Decide who determines that the organisation has become aware, who assesses whether a rogue message is a personal data breach, who notifies the Commission within 72 hours, and who decides whether listed-company disclosure applies and when. Record each decision and its time.
  • Label judgement: this order is the author's, drawn from Snowflake's guidance, NCSC guidance on adjacent channels and the gap this incident shows. It is not a standard.

Method, interest and limits

Read directly between 14:37 and 16:14 BST on 6 October 2026: ASOS plc's RNS 8604X (on ASOS's RNS provider's page, the exchange's list, and a news-wire copy), ASOS plc's investor and news pages, the London Stock Exchange's ASOS pages, ASOS's help, privacy, cyber security and App Store pages, Snowflake's 2024 post (on its Community site, because Medium answered with a block and no block was bypassed) and documentation, the legislation.gov.uk text of UK GDPR Articles 4, 33 and 34 and UK MAR Articles 7 and 17, the ICO's pages and the NCSC's pages. The BBC, The Register, Infosecurity Magazine, Reuters (through KSL), Investing.com (through Yahoo), LADbible and TechRadar are secondary and are used as pointers; each number from them is attributed. Three outlets, Quartz, Cybernews and IT Security Guru, answered with a block and were not used. The Telegram channel was not visited and X was not read.

Interest. The security vendors quoted, Check Point, Horizon3, ESET, Huntress, Malwarebytes and others, sell security products and spoke about an unconfirmed claim, mostly before the RNS. Snowflake sells the platform named, and its 2024 statements are its own account of a campaign against its customers. ASOS has an interest in limiting what it says while it investigates, and in how an RNS reads to the market; a holding line or a short announcement is not evidence of more or less than it states. Share-price figures are a market's reaction and say nothing about whether the message is true.

Limits. The press-time of each outlet is as the page showed it, and the 10:51 Reuters time depends on reading KSL's stamp as Utah time. The 119.8 million share count and the £68m are derived, and the share count agrees across two routes: the exchange's market capitalisation divided by Monday's close, and a holdings notice. The 72-hour date is arithmetic from ASOS's own "around 10am", not a deadline anyone has stated. Work files and every page text are kept beside this briefing's source files.

The question that exposes the gap

When a message reaches your customers under your name, which of the platforms behind it could a stranger use, and who has checked?

Key facts

Sources

  1. PrimaryRNS 8604X, Update regarding cyber incident, 6 October 2026, read in full: the unauthorised customer notification at around 10am, third-party platforms, name and contact details may have been accessed, no mention of SnowflakeASOS plc (RNS, on its RNS provider's page)accessed 2026-10-06
  2. PrimaryInvestor site regulatory news page: the site's own share price ticker (451.00p, down 10.16%, at 14:20 BST; 444.84p, down 11.39%, at 15:43 BST)ASOS plcaccessed 2026-10-06
  3. PrimaryThe RNS feed behind ASOS plc's regulatory news page: at 14:41 BST the newest was a 5 October holdings notice and the total 1,165; at 16:07 BST it listed the 6 October RNS and the total was 1,166ASOS plc (RNS feed supplied by Euroland)accessed 2026-10-06
  4. PrimaryLatest news page, read at 14:38 BST: newest item dated 24 September 2026, nothing on the notificationASOS plcaccessed 2026-10-06
  5. PrimaryASOS PLC company page, read at 14:37:35 and 15:51:53 BST (delayed at least 15 minutes): price, change, open, high, low, previous close of 502.00p, market capitalisation of 601.50m and trading statusLondon Stock Exchangeaccessed 2026-10-06
  6. PrimaryASOS PLC news list: read at 14:40 BST (newest was a 5 October holdings notice) and again at 16:06 BST (Update regarding cyber incident, RNS, 06.10.26 15:15:21)London Stock Exchangeaccessed 2026-10-06
  7. PrimaryASOS holdings notice of 5 October 2026 used only for a share count: 6,270,537 voting rights stated as 5.233234%, implying about 119.8 millionInvestegate (RNS republisher)accessed 2026-10-06
  8. PrimaryHelp page on subscriptions and notifications, read in a browser at 14:47 BST: how customers opt in to push, and the categories (stock, delivery and returns, discounts and new drops)ASOSaccessed 2026-10-06
  9. PrimaryCyber security page for customers, read in a browser at 14:48 BST: its BIMI and blue-tick cues for email and social media, and no mention of notificationsASOSaccessed 2026-10-06
  10. PrimaryPrivacy and cookies page, read in a browser at 14:47 BST: names ASOS.com Limited as the data controller for all ASOS servicesASOSaccessed 2026-10-06
  11. PrimaryThe app's store entry, read at 14:47 BST: lists "sale alerts and promotional nudges" and the developer's declared privacy labels; it does not name a push providerApple App Store (ASOS listing)accessed 2026-10-06
  12. PrimarySnowflake's 2024 statement on the targeted campaign against customer accounts, on its Community site: findings, MFA and network policy recommendations; used as labelled context onlySnowflakeaccessed 2026-10-06
  13. PrimaryDocumentation on planning for the deprecation of single-factor password sign-ins: the enforcement timeline, including Aug. 2026 to Oct. 2026 for all usersSnowflakeaccessed 2026-10-06
  14. PrimaryDocumentation on network policies: by default users can connect from any computer or deviceSnowflakeaccessed 2026-10-06
  15. PrimarySnowflake newsroom, read at 14:43 BST for any statement on the ASOS claim: none foundSnowflakeaccessed 2026-10-06
  16. PrimaryUK GDPR Article 33 as revised: 72 hours, 'the Commission' since 30 September 2026legislation.gov.ukaccessed 2026-10-06
  17. PrimaryUK GDPR Article 34: communication of a personal data breach to the data subjectlegislation.gov.ukaccessed 2026-10-06
  18. PrimaryUK GDPR Article 4: the definition of a personal data breach at point (12) and of the Commissionlegislation.gov.ukaccessed 2026-10-06
  19. PrimaryUK MAR Article 17 as revised: public disclosure of inside information as soon as possible, and delay conditions; page notes a revocation by 2023 c. 29 yet to be appliedlegislation.gov.ukaccessed 2026-10-06
  20. PrimaryUK MAR Article 7: the definition of inside informationlegislation.gov.ukaccessed 2026-10-06
  21. PrimaryBreach reporting page: notify as soon as possible and where feasible within 72 hours; high-risk breaches to individualsInformation Commissioner's Officeaccessed 2026-10-06
  22. PrimaryPersonal data breaches: a guide: what a breach is and when a controller is 'aware'Information Commissioner's Officeaccessed 2026-10-06
  23. PrimaryNews page, read at 14:45 BST: no item on ASOS; transition to the Information Commission on 30 September 2026Information Commissioner's Officeaccessed 2026-10-06
  24. PrimaryGuidance on stopping unauthorised content in organisational social media channels: workflow, 2-step verification, access logging, regaining controlNational Cyber Security Centreaccessed 2026-10-06
  25. PrimaryGuidance on SMS used to message end users; the nearest NCSC guidance to a customer messaging channel. NCSC site search for push notification returned nothing specific to app pushNational Cyber Security Centreaccessed 2026-10-06
  26. Reported byReport of 6 October 2026 (published 10:49 BST, last modified 11:37 BST): the message text, ASOS had not responded, group and channel facts, expert commentBBC Newsaccessed 2026-10-06
  27. Reported byReport of 6 October 2026: the notification does not by itself establish access to Snowflake or customer data; how it was sent is unclear; share fall of around 12 percentThe Registeraccessed 2026-10-06
  28. Reported byInfosecurity Magazine report of 6 October 2026, updated with ASOS's RNS: appeared as a legitimate ASOS push notification; expert comment; the channel administrator's claim on payment data (reported, channel not visited)Infosecurity Magazineaccessed 2026-10-06
  29. Reported byReuters report: shares down more than 11 percent; an ASOS spokesperson was aware of the reports and did not confirmReuters (syndicated by KSL)accessed 2026-10-06
  30. Reported byReport timed 11:54 BST: shares down as much as 13.2 percent then about 9 percent; Downdetector figures; site normal until 9:41Investing.com (via Yahoo Finance UK)accessed 2026-10-06
  31. Reported byLADbible: first published about 13:00 BST with ASOS's chat line, updated at about 15:42 BST to carry the RNS textLADbibleaccessed 2026-10-06
  32. Reported byLive blog: first reports at around 9.55am BST; an expert's comment on a marketing platform running on SnowflakeTechRadaraccessed 2026-10-06
  33. Reported byA second copy of RNS 8604X, listed at 3:15 PM on 6 October 2026, to confirm the textInvestegate (RNS republisher)accessed 2026-10-06
  34. Reported byNews-wire copy of RNS 8604X whose publication timestamp converts to 15:15:21 BSTTradingView (news-wire copy of the RNS)accessed 2026-10-06

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

How often

Every new briefing in one email, at 7am, or at 7am, 12:30pm and 6pm. Nothing is sent when nothing is new. Unsubscribe any time.