INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

ASOS Data Breach Linked to Stolen Employee Credentials Exploited

| 2026-10-08 13:36 CRITICAL HIGH DATA BREACH
Executive Summary
AI-generated
On October 6, a threat actor accessed personal and customer account data at UK fashion retailer ASOS following the breach. The attacker gained access to an employee account by impersonating a trusted contact to obtain log in credentials, which were then used to access information on certain third-party platforms used by ASOS. These platforms enabled the threat actor to send a legitimate-looking push notification to ASOS customers claiming that they had compromised a Snowflake instance and asked the company to engage with them. The attack affected approximately 1 million customer accounts, as revealed in the stolen data shared by the attacker on Telegram, which included names, addresses, phone numbers, emails, customer numbers, search history, and other personal details.
Technical Mitigations AI-generated
• Patch Snowflake Cortex AI to prevent exploitation by ASOS's Simon AI. • Monitor and block Telegram channels with suspicious activity, such as @xuanyegroup. • Implement additional authentication mechanisms for employee accounts to prevent impersonation attacks.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
NORTH_AMERICA NORTH_AMERICA financefinance retailretail
Incident Timeline
‎October 6
Threat actors used stolen employee credentials to access and breach ASOS's personal and customer account data.
target_region United Kingdom
tactic Data Breach
organisation Group-IB
‎October 6, ASOS
ASOS confirmed a data breach linked to stolen employee credentials, which was facilitated by access to third-party platforms used for customer communication.
organisation the London Stock Exchange
‎October 8
Threat actors used a compromised Simon AI instance to gain access to stolen employee credentials, which were then exploited to breach ASOS's systems.
organisation BBC
‎2026/10/08
Threat actors used stolen employee credentials to access ASOS's Snowflake instance and send a legitimate-looking push notification to customers.
organisation ASOS Confirms Data Breach Linked
organisation ASOS
organisation DPO
organisation Monetate
organisation Telegram
organisation Infosecurity
organisation the Xuanye Group
organisation Shutterstock.com
Intelligence Sources
Infosecurity-Magazine 2026-10-08