Threat reportData BreachTL-2026-3130
ASOS Data Breach: Credential Phishing of Employee Leads to Third-Party Platform (Simon AI / Snowflake) Access and Customer Data Theft
ASOS Data Breach (TL-2026-3130), also tracked as ASOS breach, is a high-severity data breach, first published 2026-10-09. It is attributed to Xuanye Group with low confidence, affects ASOS ASOS customer data (app and website customer records), maps to 8 MITRE ATT&CK techniques (T1078, T1078.004, T1199), and is covered by 9 detection rules and 7 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 8MITRE ATT&CK
- Actors
- 1Xuanye Group
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 7Indicators of compromise
Key facts for TL-2026-3130
- Threat ID
- TL-2026-3130
- Also known as
- ASOS breach, ASOS Snowflake incident, Advanced Persistent Teenagers
- Severity
- HIGH
- Status
- ACTIVE
- Category
- DATA_BREACH
- First published
- Last reviewed
- Attribution
- Xuanye Group
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- retail, ecommerce, fashion
- Target regions
- united kingdom, Europe
- Detection rules
- 9
- Indicators of compromise
- 7
Malware and tooling in ASOS Data Breach
Malware and tooling: telegram
How ASOS Data Breach works
Attackers who call themselves the Xuanye Group tricked an ASOS employee into surrendering login credentials and used them to access third-party platforms, including Simon AI (a personalization platform built on Snowflake). Stolen customer data (names, addresses, phone numbers, emails, customer numbers, dates of birth, on-site searches) was used to extort ASOS, with a two-week ransom deadline and samples sent to the BBC.
On 6 October 2026 (around 10 AM, per Malwarebytes) ASOS customers received an in-app push notification headed 'ASOS HACKED' that read: 'Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.' The message was signed 'xuanyewengateway' and linked to a Telegram channel run by a previously unknown group calling itself the Xuanye Group. The channel claimed payment information was not affected and the app was safe to use. Public reporting says ASOS uses Simon AI, a personalization/marketing platform that runs on Snowflake, alongside Braze to personalize and trigger customer communications such as push notifications; the attackers' ability to push messages through the ASOS app channel is consistent with access to this marketing/communications stack, though the exact mechanism has not been published.
According to the Malwarebytes follow-up of 9 October 2026, the attackers tricked an ASOS employee into handing over login credentials and used them to access third-party platforms, including Simon AI. Stolen data includes names, home addresses, phone numbers, email addresses, customer numbers, dates of birth, website search queries (e.g. 'reclaimed vintage', 'glamorous wide fit', 'Asos petite') and account-creation tenure. ASOS states payment card data and customer passwords were not compromised. Snowflake investigated and reported it found no compromise of its own platform, which points to compromised customer-side credentials/third-party tenant access rather than a Snowflake platform vulnerability.
The attackers demanded contact from ASOS within two weeks, threatened to release the data, and contacted the BBC with data samples. Security researcher Kevin Beaumont criticised ASOS's response (roughly five hours elapsed between the attackers' notification and ASOS's official statement) and described the actor as 'Advanced Persistent Teenagers'. ASOS shares reportedly fell about 14%. The number of affected customers has not been disclosed, no CVE is involved, and no network IOCs have been published. Payment of the ransom has not been disclosed.
MITRE ATT&CK techniques used in TL-2026-3130
Initial Access
T1078 Valid Accounts; T1199 Trusted Relationship; T1566 Phishing
Defense Evasion
T1078.004 Valid Accounts: Cloud Accounts
Collection
T1213 Data from Information Repositories; T1530 Data from Cloud Storage
Reconnaissance
T1598 Phishing for Information
Impact
Affected products and versions in ASOS Data Breach
- ASOS — ASOS customer data (app and website customer records)
Vulnerable versions: Customer records held in Simon AI / Snowflake - Simon Data (Simon AI) — Simon AI customer personalization platform (ASOS tenant)
Vulnerable versions: ASOS tenant accessed with stolen employee credentials - Snowflake — Snowflake data platform (ASOS-related instance)
Fixed in: Snowflake reports no compromise of its platform
Remediation for ASOS Data Breach
Patches
- No software vulnerability or CVE is involved; no patch applies
Immediate actions
- Reset credentials and revoke active sessions/API tokens for Simon AI, Snowflake, Braze and other marketing/data platforms accessed by affected staff
- Audit Simon AI, Snowflake and Braze access logs for unusual logins, bulk queries/exports and push-notification sends
- Enforce phishing-resistant MFA on all third-party SaaS and data-platform accounts
- Customers: treat unexpected emails, calls and texts referencing ASOS as potential phishing and do not click links in them
Workarounds
- Rotate third-party platform credentials and enable conditional access until investigation concludes
Longer-term hardening
- Apply network-policy / IP allow-listing and SSO on Snowflake and connected SaaS tenants
- Restrict who can send customer-facing push notifications and require approval workflows for sends
- Run help-desk and employee social-engineering awareness training with verification procedures for credential requests
- Apply least privilege and data minimisation to customer profile and search-history data held in marketing platforms
- Maintain a rehearsed incident-communications plan so customers hear of a breach from the company promptly
Timeline of ASOS Data Breach
- ASOS shares reportedly fall about 14% following the incident.
- About five hours after the attackers' notification, ASOS confirms unauthorized activity and says basic personal information such as names and contact details may have been accessed, with no payment-card data or passwords affected.
- Snowflake investigates and reports it found no compromise of its platform.
- Around 10 AM, ASOS customers receive an app push notification: 'ASOS HACKED... we have fully compromised the Snowflake instance. Engage with us, or we will leak it', signed xuanyewengateway with a link to a Telegram channel of the Xuanye Group.
- An ASOS employee is tricked into providing login credentials, which the attackers use to access third-party platforms including Simon AI (exact access date not disclosed; occurred on or before 2026-10-06).
- Malwarebytes reports the employee credential social-engineering vector, the full set of stolen fields (including customer numbers, dates of birth and on-site searches) and that the attackers gave ASOS two weeks to make contact and sent data samples to the BBC.
- Approximate expiry of the attackers' two-week window for ASOS to make contact (derived from the 'two weeks' deadline reported by 2026-10-09; exact start date not published).
Sources cited for ASOS Data Breach
- ASOS breach update: Hackers stole customer details and shopping searches (Malwarebytes)
- ASOS hackers send push notifications to customers (Malwarebytes)
- ASOS Customers Receive Bizarre 'Hacked' Message Amid Suspected Snowflake Compromise (Infosecurity Magazine)
- ASOS hacked? Customers receive threatening notification from hackers (TechRadar)
- When ASOS Hackers Turned the Customer App Into a Ransom Note (Cyber Magazine)
- ASOS push notification apparently sent by hackers (The Record)
- ASOS Hackers Hijack App Notifications, Claim Snowflake Data Breach (Hackread)
Detection coverage for TL-2026-3130
As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3130 across Splunk SPL, Microsoft KQL and Sigma, covering 7 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.