Asos is investigating a possible cyberattack after thousands of customers received mobile app push notifications titled “Asos hacked.” The messages claimed attackers had fully compromised the retailer’s Snowflake instance and threatened to leak data unless its data protection officer and IT team engaged with the sender. Customers were directed to a Telegram channel named “Xuanye Wen Gateway,” apparently associated with the Xuanye group, although attribution remains uncertain. Asos’s shares fell roughly 10–12% following the reports before recovering slightly; its website and app appeared to remain operational.
Neither the claimed Snowflake compromise nor theft of sensitive customer data has been verified. The mechanism used to deliver the notifications and the scope of any intrusion remain unknown. Security commentators said the messages could indicate unauthorized access to systems controlling app notifications, but did not establish access to Snowflake. Researchers also warned that publicity could fuel follow-on phishing against customers. A separate data-theft campaign targeted Snowflake customers in 2024, after which Snowflake introduced controls allowing administrators to require multi-factor authentication; no connection to the Asos incident has been established.

TTPs, infrastructure, and targeting history in one profile.
18 events from the most recent confirmed update back to the earliest known activity.
On October 8, the BBC reported that the attacker claimed a compromised Simon AI instance provided access to ASOS data. A purported stolen-data sample supplied to the BBC reportedly included contact details, customer numbers and website searches, but the report did not establish whether experts had authenticated it.
The UK's National Cyber Security Centre published an incident alert advising all ASOS customers to assume they are affected, even if they did not receive the unauthorised notification. It urged customers to watch for suspicious messages, avoid suspicious links, review account activity, and strengthen account security.
On the morning of October 6, thousands of Asos customers received a push notification claiming that attackers had fully compromised the retailer’s Snowflake instance and threatening to leak data unless Asos engaged with them. The message addressed the retailer’s data protection officer and IT team and linked to Telegram; neither the claimed compromise nor data theft was verified.
A Telegram channel linked in the rogue Asos notification was created on the day of the incident. The channel was identified as “Xuanye Wen Gateway” and associated with an apparent group called Xuanye, although attribution remained unconfirmed.
Wiz researchers discovered a critical script injection vulnerability in a public Snowflake GitHub repository through Snowflake's HackerOne vulnerability disclosure program. The report did not establish any connection between this vulnerability and the alleged ASOS incident.
On July 29, 2026, ASOS confirmed unauthorized customer-account access involving credentials obtained outside the company, after detecting the activity the previous day. ASOS blocked affected accounts, required password resets, and reported that associated suspicious transactions were blocked or canceled.
A separate 2024 hacking campaign targeted Snowflake customers including Ticketmaster, Santander, and AT&T. The campaign compromised more than 165 organizations, exposed billions of customer records, and generated approximately $2.5 million in ransom payments.
ASOS confirmed that attackers impersonated a trusted contact to steal an employee’s login credentials and access information on third-party platforms. Exposed information included customers’ full names, contact details, and certain non-personal account-related information; ASOS said payment-card information and customer account passwords were not accessed.
Bloomberg reported that hackers tricked an ASOS employee to steal a work-account login. Only the headline was available, leaving the attack's timing, specific method, scope, and impact unspecified.
Group-IB found that the Telegram account associated with the channel promoted in the rogue ASOS notification previously used the identities JohnCZ (@JohnCzwartacki) and Moon Transfers (@NFTmoonstock) and had participated in gaming-item trading. The account history did not establish who controlled it, and Group-IB found no sample, data dump or other evidence verifying access to ASOS customer data.
Snowflake said it found no compromise of the Snowflake platform following claims that attackers had compromised ASOS’s Snowflake instance. The statement does not establish whether ASOS’s individual tenant or associated integrations were accessed.
The self-described Xuanye group published a Telegram 'FINAL STATEMENT' claiming it had stolen ASOS customer information and would leave it untouched on its server for a designated period. The group did not specify the data or number of customers involved, or provide evidence of its alleged Snowflake compromise.
ASOS confirmed unauthorized activity involving third-party customer-communication platforms, restricted access to its notification platforms, and said it was working with specialists and relevant authorities. Names and contact details may have been accessed, but ASOS said it did not believe payment-card information or account passwords were affected; the claimed Snowflake compromise remained unverified.
Asos shares fell following the notifications, with reports describing declines of almost 10 percent to approximately 12 percent. The Register reported that the share price subsequently recovered slightly.
Asos began investigating after customers received the unauthorized-looking app notification. The report did not establish whether a breach had occurred or whether customer data had been accessed or stolen.
ASOS’s US business notified customers in August that their accounts had been accessed using credentials obtained outside the company, following unusual activity detected in late July. The report established no connection between this incident and the threatening app notification.
Connor Riley Moucka, a resident of Kitchener, Ontario, pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and conspiracy charges relating to the historical hacking spree.
Following the historical data-theft campaign, Snowflake introduced controls allowing administrators to require multi-factor authentication.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
28 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcecysecurity.news
Open sourcetechcrunch.com
Open sourceinfosecurity-magazine.com
Open sourcetheguardian.com
Open sourcebloomberg.com
Open sourcetherecord.media
Open sourcereddit.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.