Threat reportData BreachTL-2026-3130

ASOS Data Breach: Credential Phishing of Employee Leads to Third-Party Platform (Simon AI / Snowflake) Access and Customer Data Theft

highACTIVE

ASOS Data Breach (TL-2026-3130), also tracked as ASOS breach, is a high-severity data breach, first published 2026-10-09. It is attributed to Xuanye Group with low confidence, affects ASOS ASOS customer data (app and website customer records), maps to 8 MITRE ATT&CK techniques (T1078, T1078.004, T1199), and is covered by 9 detection rules and 7 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
8MITRE ATT&CK
Actors
1Xuanye Group
Detection rules
9SPL · KQL · Sigma
IOCs
7Indicators of compromise

Key facts for TL-2026-3130

Threat ID
TL-2026-3130
Also known as
ASOS breach, ASOS Snowflake incident, Advanced Persistent Teenagers
Severity
HIGH
Status
ACTIVE
Category
DATA_BREACH
First published
Last reviewed
Attribution
Xuanye Group
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
retail, ecommerce, fashion
Target regions
united kingdom, Europe
Detection rules
9
Indicators of compromise
7

Malware and tooling in ASOS Data Breach

Malware and tooling: telegram

How ASOS Data Breach works

Attackers who call themselves the Xuanye Group tricked an ASOS employee into surrendering login credentials and used them to access third-party platforms, including Simon AI (a personalization platform built on Snowflake). Stolen customer data (names, addresses, phone numbers, emails, customer numbers, dates of birth, on-site searches) was used to extort ASOS, with a two-week ransom deadline and samples sent to the BBC.

On 6 October 2026 (around 10 AM, per Malwarebytes) ASOS customers received an in-app push notification headed 'ASOS HACKED' that read: 'Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.' The message was signed 'xuanyewengateway' and linked to a Telegram channel run by a previously unknown group calling itself the Xuanye Group. The channel claimed payment information was not affected and the app was safe to use. Public reporting says ASOS uses Simon AI, a personalization/marketing platform that runs on Snowflake, alongside Braze to personalize and trigger customer communications such as push notifications; the attackers' ability to push messages through the ASOS app channel is consistent with access to this marketing/communications stack, though the exact mechanism has not been published.

According to the Malwarebytes follow-up of 9 October 2026, the attackers tricked an ASOS employee into handing over login credentials and used them to access third-party platforms, including Simon AI. Stolen data includes names, home addresses, phone numbers, email addresses, customer numbers, dates of birth, website search queries (e.g. 'reclaimed vintage', 'glamorous wide fit', 'Asos petite') and account-creation tenure. ASOS states payment card data and customer passwords were not compromised. Snowflake investigated and reported it found no compromise of its own platform, which points to compromised customer-side credentials/third-party tenant access rather than a Snowflake platform vulnerability.

The attackers demanded contact from ASOS within two weeks, threatened to release the data, and contacted the BBC with data samples. Security researcher Kevin Beaumont criticised ASOS's response (roughly five hours elapsed between the attackers' notification and ASOS's official statement) and described the actor as 'Advanced Persistent Teenagers'. ASOS shares reportedly fell about 14%. The number of affected customers has not been disclosed, no CVE is involved, and no network IOCs have been published. Payment of the ransom has not been disclosed.

MITRE ATT&CK techniques used in TL-2026-3130

Initial Access

T1078 Valid Accounts; T1199 Trusted Relationship; T1566 Phishing

Defense Evasion

T1078.004 Valid Accounts: Cloud Accounts

Collection

T1213 Data from Information Repositories; T1530 Data from Cloud Storage

Reconnaissance

T1598 Phishing for Information

Impact

T1657 Financial Theft

Affected products and versions in ASOS Data Breach

  • ASOS — ASOS customer data (app and website customer records)
    Vulnerable versions: Customer records held in Simon AI / Snowflake
  • Simon Data (Simon AI) — Simon AI customer personalization platform (ASOS tenant)
    Vulnerable versions: ASOS tenant accessed with stolen employee credentials
  • Snowflake — Snowflake data platform (ASOS-related instance)
    Fixed in: Snowflake reports no compromise of its platform

Remediation for ASOS Data Breach

Patches

  • No software vulnerability or CVE is involved; no patch applies

Immediate actions

  • Reset credentials and revoke active sessions/API tokens for Simon AI, Snowflake, Braze and other marketing/data platforms accessed by affected staff
  • Audit Simon AI, Snowflake and Braze access logs for unusual logins, bulk queries/exports and push-notification sends
  • Enforce phishing-resistant MFA on all third-party SaaS and data-platform accounts
  • Customers: treat unexpected emails, calls and texts referencing ASOS as potential phishing and do not click links in them

Workarounds

  • Rotate third-party platform credentials and enable conditional access until investigation concludes

Longer-term hardening

  • Apply network-policy / IP allow-listing and SSO on Snowflake and connected SaaS tenants
  • Restrict who can send customer-facing push notifications and require approval workflows for sends
  • Run help-desk and employee social-engineering awareness training with verification procedures for credential requests
  • Apply least privilege and data minimisation to customer profile and search-history data held in marketing platforms
  • Maintain a rehearsed incident-communications plan so customers hear of a breach from the company promptly

Timeline of ASOS Data Breach

  • ASOS shares reportedly fall about 14% following the incident.
  • About five hours after the attackers' notification, ASOS confirms unauthorized activity and says basic personal information such as names and contact details may have been accessed, with no payment-card data or passwords affected.
  • Snowflake investigates and reports it found no compromise of its platform.
  • Around 10 AM, ASOS customers receive an app push notification: 'ASOS HACKED... we have fully compromised the Snowflake instance. Engage with us, or we will leak it', signed xuanyewengateway with a link to a Telegram channel of the Xuanye Group.
  • An ASOS employee is tricked into providing login credentials, which the attackers use to access third-party platforms including Simon AI (exact access date not disclosed; occurred on or before 2026-10-06).
  • Malwarebytes reports the employee credential social-engineering vector, the full set of stolen fields (including customer numbers, dates of birth and on-site searches) and that the attackers gave ASOS two weeks to make contact and sent data samples to the BBC.
  • Approximate expiry of the attackers' two-week window for ASOS to make contact (derived from the 'two weeks' deadline reported by 2026-10-09; exact start date not published).

Sources cited for ASOS Data Breach

Detection coverage for TL-2026-3130

As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3130 across Splunk SPL, Microsoft KQL and Sigma, covering 7 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
7 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats