Xuanye Group is a previously unknown threat actor that claimed responsibility for an October 2026 data breach affecting ASOS, a UK-based online fashion retailer. The group used unauthorized push notifications delivered through ASOS’s own mobile application to demand contact from the company and threaten publication of customer data. It maintained a Telegram channel to publicize its claims and communicate its threats. The ASOS intrusion involved impersonating a trusted contact to obtain an employee’s login credentials. Credentials obtained through the compromised account were subsequently used to access third-party platforms containing customer information. ASOS confirmed exposure of customer names, contact details, and certain non-personal account-related information, while stating that payment-card information and customer account passwords were not accessed. The attackers abused customer-facing messaging infrastructure to publicize the incident directly to customers and pressure the retailer. Xuanye Group’s observed activity centers on credential-based intrusion and threatened data disclosure rather than confirmed ransomware deployment. Its geographic origin, organizational structure, and relationship to other threat actors are not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claims responsibility for compromising British fashion retailer ASOS and obtaining customer data, including through an alleged attack on Simon AI integrated with Snowflake. ASOS confirmed employee-account compromise, unauthorized customer push notifications, and access to some personal and account information, but did not confirm data exfiltration or attribute the incident to Xuanye Group. Snowflake denied being breached. The group had published no customer-data samples to substantiate its claims.
Linked to the breach of UK fashion retailer Asos’ customer data in a third-party platform. The attackers allegedly compromised Asos’ Snowflake instance, stole customer personal information, and abused in-app notifications to pressure Asos into engaging under threat of publishing the data. The volume stolen and the method of accessing the notification system remain unknown.
Claimed responsibility for stealing customer data from UK fashion retailer ASOS and sent malicious in-app notifications urging staff to contact them on Telegram. ASOS confirmed that an attacker impersonated a trusted contact to steal an employee’s login credentials, then accessed information on third-party platforms. Exposed information included full names, contact details, and certain non-personal account-related information; payment card information and account passwords were not accessed. The article does not report independent confirmation of the attacker’s identity.
Claimed responsibility for the ASOS breach involving a compromised third-party customer communication platform and unauthorized app notifications. The notifications threatened to leak data and alleged compromise of ASOS's Snowflake instance. ASOS confirmed the communication-platform compromise and possible exposure of names and contact details, but did not confirm the group's attribution or a Snowflake compromise. A researcher suggested the name could indicate a Chinese-speaking actor or a false flag; geographic origin and state sponsorship remain unknown.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.