Science & Tech · Cybersecurity · 2 days ago
ASOS says attackers used stolen employee credentials to access customer data
British fashion retailer ASOS says an attacker accessed customer information after a breach disclosed on October 6.
ASOS said the attacker impersonated a trusted contact to obtain an employee’s login credentials.
The stolen credentials were used to reach information on some third-party platforms that ASOS uses, including platforms for communicating with customers.
The attacker also sent a push notification to customers through one of those systems.
ASOS said payment information was not compromised and its operations were unaffected.
The data may include names, contact details and account information; the BBC also reported that a sample contained customer searches and other details.
The attacker claimed to have accessed a Snowflake instance, but ASOS and independent researchers had not confirmed the exact route into customer data.
ASOS is investigating the incident and the third-party platforms involved.
ASOS said an attacker used stolen credentials from an employee account to access information on certain third-party platforms.
The UK fashion retailer said customer names, contact details and some account-related information were accessed.
ASOS said payment information was not compromised and the incident did not affect its operations.
The attacker used a third-party platform to send a push notification to customers, and claimed to have compromised a Snowflake instance.
The attacker’s claim about Snowflake and the reported role of marketing platform Simon AI have not been confirmed by ASOS or independent researchers.
- Who
- ASOS, a UK fashion retailer, and an attacker identified as Xuanye Group.
- What
- The attacker used stolen employee login credentials to access information on certain third-party platforms and customer data.
- When
- The breach was reported on October 6, 2026; ASOS notified customers on October 8.
- Where
- The accessed platforms were used by ASOS to communicate with customers. The sources do not state where the attacker operated from.
- Why
- Not stated.
This story does not have two clearly opposing sides.
by impersonating a trusted contact to obtain log in credentials
We can confirm this issue did not in any way result from a vuln, weakness, flaw or misconfiguration with the Snowflake service, platform or internal environments, and was not caused by Snowflake. No remediation is required for Snowflake customers.
is safe on our server and will not be touched for a designated period
Xuanye Group announced that it had breached ASOS, and the retailer said it was investigating third-party platforms used to communicate with customers.
ASOS notified customers that an attacker had accessed personal and account information and that payment information was not compromised.
The BBC reported that the threat actor said it had compromised a Simon AI instance to access data.
- Employee account
- Credentials obtained by impersonating a trusted contact
- Data accessed
- Names, contact details and some account-related information, according to ASOS
- Payment information
- Not compromised, according to ASOS
- Third-party platform
- Platforms used by ASOS to communicate with customers
- Threat actor
- Xuanye Group











