Features 09.10.2026
ASOS Breach: Retailer in Incident Response Mode After Hackers Notify Customers
The job of the firm’s first responders just got a whole lot harder
Features 09.10.2026
The job of the firm’s first responders just got a whole lot harder
On October 6, ASOS customers received a disconcerting message on their phones. Direct from the ASOS app came a push notification stating: “Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us or we will leak it: t.me/xuanyewengateway.” The high-street retailer later confirmed a customer data breach, which could have significant financial and reputational impacts.
Details are still emerging. But the incident already tells us much about the importance of supply chain risk management, access controls and employee security awareness programmes.
Later the same day, ASOS released a formal statement to the London Stock Exchange (LSE). It confirmed that an “unauthorised customer notification was sent to ASOS customers” and that “basic personal information including name and contact details may have been accessed.”
“An unauthorised party gained access to an ASOS employee account by impersonating a trusted contact.” Asos statement
The threat actors subsequently contacted the BBC to clarify that this initial statement was not 100% accurate. ASOS was forced to send a notice to customers two days later, confirming that not only names, addresses, phone numbers, and emails were compromised, but also customer numbers and searches on the site. This could make follow-on phishing/smishing/vishing attempts more convincing.
“We discovered that an unauthorised party gained access to an ASOS employee account by impersonating a trusted contact to obtain log in credentials,” the statement continued. “Those credentials were then used to access information on certain third-party platforms used by ASOS.”
What is not clear is which services this enabled them to log in to, although the threat actors told the BBC they accessed the data via Simon AI, an agentic marketing platform that runs natively on Snowflake. This would support Snowflake’s claims that its own platform wasn’t breached.
Assured CISO, Nick Harris, has a theory about the credential that was stolen and how the hackers sent out the initial notification.
“The mentioning of ‘platforms’ (plural) from one credential suggests an Entra ID SSO account federated into Simon and [customer engagement platform] Braze, making this more likely than separate local logins,” he says. “Simon can trigger Braze channel actions directly, so Simon access alone may have been enough.”
It remains to be seen how many of ASOS’s 17 million active global customers were affected. Questions also remain about the identity of the hackers, who call themselves “Xuanye Group”. The Telegram channel linked in the push notification was created on October 6 and previously carried names associated with gaming trades, according to Group-IB. The use of spellings and names consistent with Chinese pinyin may be a false flag.
The use of push notifications in data extortion cases like this is rare but not completely unprecedented. In 2023, hackers compromised a US university’s RamAlert emergency alerts system to notify faculty and students that they were ready to leak admissions data from thousands of students. In appealing directly to the victims of a breach, the extortionists hope to force payment.
“Public knowledge provides an attacker with genuine targets and information to concoct realistic phishing emails.” Nick Harris
Such an eventuality should be built into incident response planning. Public notifications like this reduce the window of opportunity investigators have to find out what happened before they need to update customers, shareholders and regulators. This compressed timeline may account for ASOS initially underestimating the scope of the breach.
Other early lessons learnt at this stage include the importance of best practice identity and access management (IAM) and employee security awareness programmes. It appears that a simple phishing attack was enough to gain access to the data trove. Could phishing-resistant MFA and a savvier employee have thwarted the hackers? Outpost24’s Borja Rodriguez claims to have found ASOS work email logins for 118 accounts on the dark web, including some taken by infostealers.
A final word of warning to organisations. Assured’s Harris was able to find out a surprisingly large amount of publicly available information on ASOS’s IT infrastructure and software supply chain. This included its Azure microservices architecture, managed security services provider, and identity solution. “With such public knowledge, it provides an attacker with both genuine targets and enough information to concoct realistic phishing emails,” he argues.
The size of the financial and reputational hit to ASOS is already becoming clear. Reports suggest it lost a tenth of its value on London’s stock market following the news, putting extra pressure on incident responders at the struggling retailer.
In these circumstances, a good cyber insurance policy can be invaluable, shouldering costs associated with incident response and notification, regulatory fines, crisis management, extortion, and more. Perhaps not coincidentally, ASOS added a line in its LSE statement confirming it has insurance “with a large global provider”.