Asos hacked notification: What a snowflake instance is
The messages ASOS app users received mention a "Snowflake instance." Here's what that means.

ASOS app users in the UK woke up Tuesday to an unsettling pop-up. As Mashable reported, messages that appear to come from hackers have been showing up inside the official ASOS app. One of them, addressed to the retailer's data protection officer and IT team, claims the senders "have fully compromised the Snowflake instance" and threatens to leak it.
For most people, any app you use that stores your personal information is a bit scary. Beyond that, though, most shoppers probably have no idea what a Snowflake instance even is. So, why should ASOS customers be worried?
What is Snowflake?
Snowflake is a company that sells a cloud-based data platform. Businesses use it to store large amounts of information and run analyses on it. According to Snowflake's documentation, the platform combines data storage, processing, and analytics into a single service, and it handles the hardware, software, and maintenance itself. Customers don't install it on their own servers; instead, it runs on major public clouds such as Amazon Web Services, Microsoft Azure, and Google Cloud.
SEE ALSO: The 6 biggest cybersecurity breaches of 2026 so farThe data can take many forms. Snowflake's documentation says the platform can hold neatly organized tables with rows and columns, looser formats like JSON files, and unstructured material such as documents, images, and audio. Companies also use it to build data pipelines, train machine learning models, and share data with partners.
So, think of Snowflake as a highly organized warehouse that a company rents. The company decides what goes inside and who gets a key, while Snowflake runs the building.
What's an 'instance'?
In cloud hosting, an instance generally means one running copy of something. Most often, that's a virtual server. On Amazon Web Services, for example, a virtual machine you rent is called an "EC2 instance." You pick its size, meaning how much processing power, memory, and storage it gets, start it up, and it runs until you shut it down.
Keeping up with the analogy, an "instance" is one company's own private section of Snowflake's warehouse, according to Snowflake's documentation. Snowflake has many corporate customers, and each one gets a separate environment with its own data, users, and access controls. Snowflake's documentation describes security, authentication, and access control as built-in parts of the platform.
When attackers claim to have compromised "the Snowflake instance," they're saying they gained access to the environment where ASOS stores its data. In this case, it appears that only ASOS has been affected and not the entirety of Snowflake's customer base. As of this writing, Snowflake has not publicly commented on the ASOS breach. Mashable reached out to Snowflake for comment and will update this story if they respond.
Several key details remain unconfirmed. As noted in our previous report, it isn't publicly established that ASOS uses Snowflake, and ASOS isn't on Snowflake's published list of partners. ASOS addressed the incident in a statement posted to its Instagram Story on Tuesday.
The company apologized to customers who received what it called an "unauthorized push notification" and asked them to ignore the message and not click its link. ASOS said it is investigating, has restricted access, and is working with internal and external specialists and the relevant authorities.
Based on what it knows so far, the company said, basic personal information, including names and contact details, may have been accessed. ASOS said it doesn't believe payment card information or account passwords were affected.
The statement doesn't mention Snowflake, so it's still unconfirmed whether the data the hackers claim to have taken was stored there. ASOS also didn't say how the hackers were able to send messages through its app, or how many customers may be affected.
What ASOS is saying
ASOS says its website and app are working as usual. Users shouldn't click the link in the pop-up message, which leads to a Telegram channel run by a group calling itself the "Xuanye Group."
The bigger risk may come later. If names and contact details were taken, scammers could use them to send convincing phishing emails or texts that appear to come from ASOS. Be wary of unexpected messages that mention your ASOS account, an order, or a refund, especially ones asking you to click a link or enter personal details.
ASOS doesn't believe passwords were affected, ASOS said on Instagram Tuesday. However, changing yours is a simple precaution. That's especially true if you use the same password on other sites.
Want more tech and digital culture news delivered to your inbox daily or sent straight to your device? Sign up for Mashable's Top Stories newsletter or get Mashable push alerts today.