INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ASOS Data Breach Linked to Stolen Employee Credentials Exploited
| 2026-10-08 13:36 CRITICAL HIGH DATA BREACH
Executive Summary
AI-generated
On October 6, a threat actor accessed personal and customer account data at UK fashion retailer ASOS following the breach. The attacker gained access to an employee account by impersonating a trusted contact to obtain log in credentials, which were then used to access information on certain third-party platforms used by ASOS. These platforms enabled the threat actor to send a legitimate-looking push notification to ASOS customers claiming that they had compromised a Snowflake instance and asked the company to engage with them. The attack affected approximately 1 million customer accounts, as revealed in the stolen data shared by the attacker on Telegram, which included names, addresses, phone numbers, emails, customer numbers, search history, and other personal details.
Technical Mitigations AI-generated
• Patch Snowflake Cortex AI to prevent exploitation by ASOS's Simon AI.
• Monitor and block Telegram channels with suspicious activity, such as @xuanyegroup.
• Implement additional authentication mechanisms for employee accounts to prevent impersonation attacks.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
financefinance
retailretail
Incident Timeline
October 6
Threat actors used stolen employee credentials to access and breach ASOS's personal and customer account data.
Click on any entity below to view its context and source!
target_region
United Kingdom
UK fashion retailer ASOS has notified customers the threat actor had accessed personal and customer account data following the October 6 data breach.
tactic
Data Breach
UK fashion retailer ASOS has notified customers the threat actor had accessed personal and customer account data following the October 6 data breach.
organisation
Group-IB
Anastasia Tikhonova, global head of threat research at Group-IB, found that the Telegram channel included in the bizarre
push notification sent to ASOS customers
was brand new – created on October 6 – and that the Telegram account behind it previously carried other names, largely in gaming-item trading.
October 6, ASOS
ASOS confirmed a data breach linked to stolen employee credentials, which was facilitated by access to third-party platforms used for customer communication.
Click on any entity below to view its context and source!
organisation
the London Stock Exchange
Access to Third-Party Platforms Enabled ASOS Attack
In
a statement sent to the London Stock Exchange
, published on October 6, ASOS said they are investigating third-party platforms which were used to communicate with customers.
October 8
Threat actors used a compromised Simon AI instance to gain access to stolen employee credentials, which were then exploited to breach ASOS's systems.
Click on any entity below to view its context and source!
organisation
BBC
On October 8, the BBC
reported
a conversation cybersecurity reporter Joe Tidy had with the threat actor in which they said a Simon AI instance was compromised to gain access to the data.
2026/10/08
Threat actors used stolen employee credentials to access ASOS's Snowflake instance and send a legitimate-looking push notification to customers.
Click on any entity below to view its context and source!
organisation
ASOS Confirms Data Breach Linked
ASOS Confirms Data Breach Linked to Stolen Employee Credentials.
organisation
ASOS
Access to these platforms enabled the threat actor to send a legitimate-looking push notification to ASOS customers.
organisation
DPO
The notification, seemingly addressed to ASOS’s own data protection officer (DPO) and IT team, claimed that the attacker had compromised a Snowflake instance and asked the company to engage with them.
organisation
Monetate
American software firm Monetate, which acquired Simon AI in July, has been contacted by
Infosecurity
for comment.
organisation
Telegram
More Than Basic Contact Details Could Be Exposed
In the Telegram channel which was linked to in the push notification claiming the hack, the attacker, using the name ‘Xuanyewen’ and ‘Xuanye group,’ said the incident only involves “customer information.”
organisation
Infosecurity
This comes after
Infosecurity
reported
that the Telegram account behind the rogue message may be linked to gaming trading activity.
organisation
the Xuanye Group
Those records show JohnCZ and Moon Transfers as earlier display names of the same account currently using @xuanyegroup, which is associated with the Xuanye Group Telegram presence," she further explained.
organisation
Shutterstock.com
Image credits: Mamun_Sheikh / Burdun Iliya / Shutterstock.com
Intelligence Sources
Infosecurity-Magazine
2026-10-08
ASOS Confirms Data Breach Linked to Stolen Employee Credentials
Infosecurity-Magazine
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-09T06:15
Comprehensive Tactical Telemetry
Highly Correlated Entities
11x
organisation
Identified Entity
ASOS Confirms Data Breach Linked
entity
3x
timeline
Temporal Reference
October 6
date
2x
target region
Target Country
United Kingdom
country
2x
industry
Targeted Sector
Finance
sector
Contextual Telemetry
Context Block
2 METRICS
tactic
Cyber Operation Type
Data Breach
tactic
tactic
MITRE ATT&CK Technique
T1589.001 - Credentials
technique
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.