"That suggests an identity set up or reorganized around this incident," said Anastasia Tikhonova, summarizing Group-IB's early findings on the Telegram account tied to a disturbing October 6 push notification sent to ASOS customers.
Group-IB's Telegram findings: a new channel, an old trading profile
Group-IB's investigation, shared with Infosecurity, traced the Telegram channel referenced in the October 6 notification to t.me/xuanyewengateway. The channel itself was created on October 6, the firm found, but the Telegram account that administered it has an online history predating the incident. That account, now labelled ‘Xuanyewen’ (@@xuanyegroup), previously used names associated with gaming-item trading, including JohnCZ (@JohnCzwartacki) and Moon Transfers (@NFTmoonstock).
Tikhonova cautioned that this history "does not tell us who controls it, how experienced they are or how access was gained, and we have no evidence on the entry route." She added that Group-IB has "seen no sample, dump or other evidence" to verify claims that the group possesses ASOS customer data.
The October 6 notification and ASOS' confirmed response
The message that triggered widespread concern was a push notification claiming a Snowflake-instance compromise. ASOS' initial communication confirmed the company was investigating unauthorized activity "involving third-party platforms that we use to communicate with customers." The retailer said it had taken "immediate action to restrict access to the notification platforms" and was "working with our internal and external specialist advisers, as well as all relevant authorities."
ASOS acknowledged that basic personal information, including names and contact details, may have been accessed, while investigators do not believe payment-card information or account passwords were affected. The administrator of the Telegram channel linked in the notification also stated that payment information is not affected. Separately, Snowflake told Infosecurity it has found "no compromise of the Snowflake platform."

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadSaaS and messaging channels as an attack surface: Team Cymru and Group-IB analysis
Will Thomas, senior threat intelligence advisor at Team Cymru, assessed the incident as most consistent with a software-as-a-service (SaaS) platform compromise — a route that can allow attackers to trigger notifications or other communications without direct access to a customer database. Thomas outlined several possible techniques that could produce this result: social engineering of helpdesk staff to trigger password resets, discovery of an API key exposed in website JavaScript, reuse of credentials found in infostealer logs, or another vulnerability introduced by a developer. "Whether the helpdesk was socially engineered to trigger a password reset, an API key was found in some exposed JavaScript on the website, a credentials were reused from infostealer logs or another vulnerability was introduced by a vibe-coding developer, it’s unclear right now," he said.
Tikhonova echoed the broader pattern: "attackers target the platforms and integrations companies depend on, because one point of access reaches a long way." She stressed that being able to send a notification demonstrates access to a customer-messaging channel, "not possession of a customer database," a technical distinction with practical consequences for what data may — or may not — actually be exposed.
Thomas also referenced groups that have used similar techniques in recent UK retail incidents, naming FulcrumeSec, ExfilSquad, Scattered Spider, and Lapsus$ as examples of data extortion actors who have leveraged platform and integration weaknesses.
Guidance for ASOS customers from Arctic Wolf and the NCSC
Arctic Wolf's Nick Dyer warned that compromised datasets could include customer, sales, order, marketing or operational records and might expose users to fraud, phishing or identity theft. He noted ASOS has "around 17 million customers globally," underlining the potential scale of any exposure.
Dyer advised customers to:
- avoid clicking or interacting with unexpected notifications, emails or messages claiming to be from ASOS, especially if asked to click a link or provide personal information;
- be wary of phone calls or texts from unknown numbers that try to create urgency and instead go directly to the ASOS website; and
- change your password, given that ASOS and many retailers may not have rolled out multifactor authentication across all accounts.
The UK's National Cyber Security Centre (NCSC) has issued similar advice and pointed customers to its Stop! Think Fraud guidance for how to report fraud in the UK and top tips for staying secure online.
What this means for retailers, security teams, and customers
Retailers: The incident underlines the risk posed by third-party communication platforms and integrations. Companies that delegate customer messaging to SaaS providers need to treat those channels as critical components of their security posture and monitor them accordingly.
Security teams and technologists: Analysts on the case emphasize investigating not only direct data stores but any API keys, exposed JavaScript, helpdesk workflows and credential hygiene that could permit messaging abuse. Confirming whether an attacker has a data set requires proof — a sample, a dump, or forensic traces — that Group-IB says it has not yet observed.
Customers: Practicing basic scepticism toward unsolicited communications and following the practical steps recommended by Arctic Wolf and the NCSC remain the immediate defensive actions available to individuals.
As investigators continue their work, the record so far contains a mix of confirmed actions — ASOS' platform restrictions and Snowflake's denial of compromise — and unverified claims tied to a newly created Telegram channel administered by an account with a prior gaming-trading profile. Whether the notification represents a messaging-channel abuse, a larger data breach, or an attempt at extortion remains to be proven; for now, authorities, ASOS and external specialists are the named parties conducting that probe, and outside analysts caution against equating messaging access with possession of a customer database.
https://www.infosecurity-magazine.com/news/telegram-accoun-asos-tied-gaming/




