# ASOS Data Breach: Credential Phishing of Employee Leads to Third-Party Platform (Simon AI / Snowflake) Access and Customer Data Theft

> Attackers who call themselves the Xuanye Group tricked an ASOS employee into surrendering login credentials and used them to access third-party platforms, including Simon AI (a personalization platform built on Snowflake). Stolen customer data (names, addresses, phone numbers, emails, customer numbers, dates of birth, on-site searches) was used to extort ASOS, with a two-week ransom deadline and samples sent to the BBC.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-09T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3130
- **ID:** TL-2026-3130
- **Severity:** HIGH
- **Category:** DATA_BREACH
- **Status:** ACTIVE
- **Actor:** Xuanye Group
- **Detections:** 9 · **IOCs:** 7 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 6 October 2026 (around 10 AM, per Malwarebytes) ASOS customers received an in-app push notification headed 'ASOS HACKED' that read: 'Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.' The message was signed 'xuanyewengateway' and linked to a Telegram channel run by a previously unknown group calling itself the Xuanye Group. The channel claimed payment information was not affected and the app was safe to use. Public reporting says ASOS uses Simon AI, a personalization/marketing platform that runs on Snowflake, alongside Braze to personalize and trigger customer communications such as push notifications; the attackers' ability to push messages through the ASOS app channel is consistent with access to this marketing/communications stack, though the exact mechanism has not been published.

According to the Malwarebytes follow-up of 9 October 2026, the attackers tricked an ASOS employee into handing over login credentials and used them to access third-party platforms, including Simon AI. Stolen data includes names, home addresses, phone numbers, email addresses, customer numbers, dates of birth, website search queries (e.g. 'reclaimed vintage', 'glamorous wide fit', 'Asos petite') and account-creation tenure. ASOS states payment card data and customer passwords were not compromised. Snowflake investigated and reported it found no compromise of its own platform, which points to compromised customer-side credentials/third-party tenant access rather than a Snowflake platform vulnerability.

The attackers demanded contact from ASOS within two weeks, threatened to release the data, and contacted the BBC with data samples. Security researcher Kevin Beaumont criticised ASOS's response (roughly five hours elapsed between the attackers' notification and ASOS's official statement) and described the actor as 'Advanced Persistent Teenagers'. ASOS shares reportedly fell about 14%. The number of affected customers has not been disclosed, no CVE is involved, and no network IOCs have been published. Payment of the ransom has not been disclosed.

## MITRE ATT&CK

- T1598 Phishing for Information
- T1566 Phishing
- T1078 Valid Accounts
- T1199 Trusted Relationship
- T1078.004 Valid Accounts: Cloud Accounts
- T1213 Data from Information Repositories
- T1530 Data from Cloud Storage
- T1657 Financial Theft

## Sources

- [ASOS breach update: Hackers stole customer details and shopping searches (Malwarebytes)](https://www.malwarebytes.com/blog/data-breaches/2026/10/asos-breach-update-hackers-stole-customer-details-and-shopping-searches)
- [ASOS hackers send push notifications to customers (Malwarebytes)](https://www.malwarebytes.com/blog/news/2026/10/asos-hackers-send-push-notifications-to-customers)
- [ASOS Customers Receive Bizarre 'Hacked' Message Amid Suspected Snowflake Compromise (Infosecurity Magazine)](https://www.infosecurity-magazine.com/news/asos-customers-message-suspected/)
- [ASOS hacked? Customers receive threatening notification from hackers (TechRadar)](https://techradar.com/pro/security/asos-hacked-customers-receive-threatening-notification-from-hackers-heres-what-we-know)
- [When ASOS Hackers Turned the Customer App Into a Ransom Note (Cyber Magazine)](https://cybermagazine.com/news/when-asos-hackers-turned-the-customer-app-into-a-ransom-note)
- [ASOS push notification apparently sent by hackers (The Record)](https://therecord.media/asos-push-notification-apparently-sent-by-hackers)
- [ASOS Hackers Hijack App Notifications, Claim Snowflake Data Breach (Hackread)](https://hackread.com/asos-hackers-hijack-app-notifications-snowflake-data-breach/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3130
