Skip to main content
Emerging ThreatsData Breaches

ASOS Breach Exposes Customer Data After Stolen Credentials Used

Blurred computer screen and employees in background of ASOS office login area.
"At this time, we can report that we have found no compromise of the Snowflake platform," a Snowflake spokesperson told Infosecurity.

How ASOS says the attacker gained entry: impersonation and stolen employee credentials

UK fashion retailer ASOS told customers in an October 8 email — shared with Infosecurity — that investigators traced the breach to an attacker who "impersonat[ed] a trusted contact to obtain log in credentials" for an employee account. Those credentials, ASOS said, were then used to "access information on certain third-party platforms used by ASOS."

ASOS first disclosed the incident to the London Stock Exchange on October 6, saying it was investigating third-party platforms used to communicate with customers. The company has said payment information was not compromised and that the incident has not affected operations.

Third‑party platforms, a push notification, and the Snowflake claim

ASOS said access to the third‑party platforms enabled the threat actor to send a legitimate‑looking push notification to ASOS customers. The message appeared to be addressed to ASOS’s own data protection officer (DPO) and IT team, and claimed the attacker had compromised a Snowflake instance, asking the company to engage with them.

Snowflake, a cloud‑based data platform used to store and manage large volumes of data, told Infosecurity it began an investigation after becoming aware of the push notification. The Snowflake spokesperson stated they have found no compromise of the Snowflake platform.

Simon AI, Monetate, and the contested chain of compromise

Security researchers and reporters have pointed to an agentic marketing platform called Simon AI as potentially linked to the incident. Pieter Arntz, senior malware intelligence researcher at Malwarebytes, suggested Simon AI may be indirectly linked because it is built on Snowflake Cortex AI. Simon AI’s website lists ASOS among its partners, alongside Bombas and Equinox.

Simon AI was acquired by American software firm Monetate in July; Monetate has been contacted by Infosecurity for comment. Separately, the BBC reported that the threat actor told its cybersecurity reporter Joe Tidy a Simon AI instance had been compromised to gain access to the data.

What appears to have been taken: customer records and search history

In the Telegram channel linked in the push notification, the attacker — using the names "Xuanyewen" and "Xuanye group" — stated the incident "only involves 'customer information' " and claimed the data "is safe on our server and will not be touched for a designated period."

The BBC said a sample of the stolen data it received contained more than the "basic contact details" ASOS had initially described. The BBC's sample allegedly included names, addresses, phone numbers, emails, customer numbers, and website search terms such as "reclaimed vintage," "glamorous wide fit" and "ASOS petite." The BBC did not report whether the sample had been independently analyzed by cybersecurity experts to verify its legitimacy.

The Telegram presence: new channel, old usernames

Infosecurity reported the Telegram account behind the rogue message may be linked to gaming‑item trading activity. Anastasia Tikhonova, global head of threat research at Group‑IB, found the Telegram channel included in the push notification was brand new — created on October 6 — and that the account previously used other names largely associated with gaming trading.

As Tikhonova explained, "Our instant messaging monitoring system retained historical changes to Telegram account display names and usernames. Those records show JohnCZ and Moon Transfers as earlier display names of the same account currently using @xuanyegroup, which is associated with the Xuanye Group Telegram presence."

What this means for technologists, customers, and third‑party vendors

  • Technologists and security teams: Incident details center on stolen employee credentials and the use of third‑party platforms to reach customers. Teams will be focused on credential misuse, access logs for external integrations, and communications channels that can be impersonated to deliver legitimate‑looking messages.
  • Customers and the public: ASOS has notified customers and stated payment information was not compromised; nevertheless, the BBC's reported sample suggests names, contact details, customer numbers and search activity may be exposed — information customers should monitor and treat cautiously.
  • Third‑party vendors and platform providers: The disclosure highlights the role of third‑party platforms in the chain of access. Monetate (which acquired Simon AI in July) has been contacted for comment, and Snowflake has publicly stated its platform shows no signs of compromise while investigations continue.

The record published so far lays out a clear attack vector — social engineering to obtain employee credentials, followed by exploitation of third‑party platforms to send targeted, believable messages — but leaves key verifications pending: whether Simon AI or another intermediary was actually compromised, and independent confirmation of the provenance and scope of the data samples circulating online. ASOS’s ongoing investigation, responses from Monetate and Snowflake, and any forensic analysis of the purported data will determine how far the breach reached and which controls failed.

https://www.infosecurity-magazine.com/news/asos-data-breach-stolen-employee/