DKDKCISSPSearch
Data BreachesDEVELOPING

ASOS Confirms Data Breach Linked to Stolen Employee Credentials

In the email to customers on October 8, shared with Infosecurity, ASOS also confirmed that payment information was not compromised and that the incident has not affected operations.

DKCISSP News DeskInfosecurity Magazine8 Oct 2026, 7:06 pm
ASOS Confirms Data Breach Linked to Stolen Employee Credentials
Image courtesy of Infosecurity Magazine. Original report
DKCISSP REPORT

Upon investigating the breach, ASOS discovered that the attacker had gained access to an employee account “by impersonating a trusted contact to obtain log in credentials.” These credentials were then used to “access information on certain third-party platforms used by ASOS.” In a statement sent to the London Stock Exchange , published on October 6, ASOS said they are investigating third-party platforms which were used to communicate with customers.

The notification, seemingly addressed to ASOS’s own data protection officer (DPO) and IT team, claimed that the attacker had compromised a Snowflake instance and asked the company to engage with them.

This comes after Infosecurity reported that the Telegram account behind the rogue message may be linked to gaming trading activity.

Anastasia Tikhonova, global head of threat research at Group-IB, found that the Telegram channel included in the bizarre push notification sent to ASOS customers was brand new – created on October 6 – and that the Telegram account behind it previously carried other names, largely in gaming-item trading.

In the Telegram channel which was linked to in the push notification claiming the hack, the attacker, using the name ‘Xuanyewen’ and ‘Xuanye group,’ said the incident only involves “customer information.” They claimed it “is safe on our server and will not be touched for a designated period.” According to the BBC, a sample of the stolen data it was sent by the threat actor contained more information than the "basic contact details" ASOS had previously said may have been compromised.

However, Pieter Arntz, senior malware intelligence researcher at Malwarebytes, suggested that an agentic marketing platform used by ASOS, known as Simon AI, may be indirectly linked to the incident because it is built on Snowflake Cortex AI .

She also told Infosecurity she has not yet found any evidence to verify the claims that the group has access to ASOS customer data.

ASOS’ first communication regarding the hacker claims confirmed the firm was investigating unauthorized activity "involving third-party platforms that we use to communicate with customers." The company said it took "immediate action to restrict access to the notification platforms" and is "working with our internal and external specialist advisers, as well as all relevant authorities." The company also acknowledged that basic personal information including names and contact details may have been accessed by the threat actor, but the investigators do not believe payment-card information or account passwords were impacted.

However, the fashion retailer did not mention Snowflake in any of its statements and the cloud service firm told Infosecurity it has found “no compromise of the Snowflake platform.” Group-IB’s Tikhonova noted that “being able to send a notification shows access to a customer-messaging channel, not possession of a customer database.” Will Thomas, senior threat intelligence advisor at Team Cymru, assessed that this incident likely points in the direction of some form of a software-as-a-service (SaaS) platform compromise, an approach that has been used in high-profile attacks on UK retailers over recent years.

Opening it would lead to credential theft or malware delivery.

What happened

Upon investigating the breach, ASOS discovered that the attacker had gained access to an employee account “by impersonating a trusted contact to obtain log in credentials.” These credentials were then used to “access information on certain third-party platforms used by ASOS.” In a statement sent to the London Stock Exchange , published on October 6, ASOS said they are investigating third-party platforms which were used to communicate with customers.

The notification, seemingly addressed to ASOS’s own data protection officer (DPO) and IT team, claimed that the attacker had compromised a Snowflake instance and asked the company to engage with them.

What changed

This comes after Infosecurity reported that the Telegram account behind the rogue message may be linked to gaming trading activity.

Anastasia Tikhonova, global head of threat research at Group-IB, found that the Telegram channel included in the bizarre push notification sent to ASOS customers was brand new – created on October 6 – and that the Telegram account behind it previously carried other names, largely in gaming-item trading.

Who is affected

In the Telegram channel which was linked to in the push notification claiming the hack, the attacker, using the name ‘Xuanyewen’ and ‘Xuanye group,’ said the incident only involves “customer information.” They claimed it “is safe on our server and will not be touched for a designated period.” According to the BBC, a sample of the stolen data it was sent by the threat actor contained more information than the "basic contact details" ASOS had previously said may have been compromised.

However, Pieter Arntz, senior malware intelligence researcher at Malwarebytes, suggested that an agentic marketing platform used by ASOS, known as Simon AI, may be indirectly linked to the incident because it is built on Snowflake Cortex AI .

Why it matters

She also told Infosecurity she has not yet found any evidence to verify the claims that the group has access to ASOS customer data.

ASOS’ first communication regarding the hacker claims confirmed the firm was investigating unauthorized activity "involving third-party platforms that we use to communicate with customers." The company said it took "immediate action to restrict access to the notification platforms" and is "working with our internal and external specialist advisers, as well as all relevant authorities." The company also acknowledged that basic personal information including names and contact details may have been accessed by the threat actor, but the investigators do not believe payment-card information or account passwords were impacted.

Technical details

However, the fashion retailer did not mention Snowflake in any of its statements and the cloud service firm told Infosecurity it has found “no compromise of the Snowflake platform.” Group-IB’s Tikhonova noted that “being able to send a notification shows access to a customer-messaging channel, not possession of a customer database.” Will Thomas, senior threat intelligence advisor at Team Cymru, assessed that this incident likely points in the direction of some form of a software-as-a-service (SaaS) platform compromise, an approach that has been used in high-profile attacks on UK retailers over recent years.

Opening it would lead to credential theft or malware delivery.

Response

A Snowflake spokesperson told Infosecurity that the company began an investigation as soon as it became aware of the attacker’s push notification.

Anastasia Tikhonova, global head of threat research at Group-IB, investigated the Telegram channel t.me/xuanyewengateway, included in the bizarre push notification sent to ASOS customers on October 6 where a threat actor claimed to have hacked the company via a Snowflake instance.

What security teams should do

It said external content should always be treated as data, kept separate from instructions.

This article was updated on October 9 to add the latest Snowflake update.

Attribution

Infosecurity Magazine: In the email to customers on October 8, shared with Infosecurity, ASOS also confirmed that payment information was not compromised and that the incident has not affected operations.

Infosecurity Magazine: In research published on October 7, Barracuda said it analyzed a campaign that combined traditional social engineering, such as password-protected attachments, with prompt injection concealed in the same message.

Infosecurity Magazine: Anastasia Tikhonova, global head of threat research at Group-IB, investigated the Telegram channel t.me/xuanyewengateway, included in the bizarre push notification sent to ASOS customers on October 6 where a threat actor claimed to have hacked the company via a Snowflake instance.

MORE IN DATA BREACHES

More cybersecurity reporting

ASOS Customers Sent “Hacked” Message Amid Suspected Snowflake BreachInfosecurity Magazine · 6 Oct 2026, 5:11 pmDanish university DTU breach exposes data of up to 200,000 peopleBleepingComputer · 3 Oct 2026, 8:05 pmAI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit - Help Net SecurityHelp Net Security · 1 Oct 2026, 6:43 pm