ASOS hit by extortion hack: push notifications hijacked and Snowflake instance allegedly compromised

The CyberSec Guru

ASOS Data Breach

If you like this post, then please share it:

Buy me A Coffee!

Support The CyberSec Guru’s Mission

🔐 Fuel the cybersecurity crusade by buying me a coffee! Why your support matters: Zero paywalls: Keep the main content 100% free for learners worldwide.

“Your coffee keeps the servers running and the knowledge flowing in our fight against cybercrime.”☕ Support My Work

Buy Me a Coffee Button

A technical analysis of the October 2026 ASOS data breach, the “XuanyeGroup” threat actor, the Simon AI and Snowflake data pipeline, and the weak points in enterprise MarTech stacks.

TL;DR

On the morning of October 6, 2026, millions of ASOS customers received an unauthorized push notification sent from the retailer’s own mobile app. The message was addressed to the company’s Data Protection Officer and IT department. It claimed the attackers had “fully compromised the Snowflake instance” and threatened to leak the stolen data unless ASOS made contact on Telegram. ASOS shares fell 15%, Downdetector filled with reports, and the story spread quickly through the e-commerce and security communities.

Snowflake has confirmed that its core platform was not compromised. The incident points instead to the seam between cloud data warehouses, Customer Data Platforms (CDPs), and third-party push notification APIs. The extortion attempt is linked to a newly surfaced group calling itself “XuanyeGroup,” which KELA researchers say was recently trying to launder money through high-value in-game assets on Roblox and Counter-Strike.

This report covers how the breach unfolded, how the compromised MarTech (marketing technology) stack is put together, what is known about the attackers, and what consumers and CISOs should do next.

The incident: a hijacked trust channel

At about 10:00 AM BST, ASOS customers in several regions got an alert that came from the genuine, signed ASOS iOS and Android apps. It read: “Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.” A deep link took users to a freshly created Telegram channel called the “Xuanye group gateway.”

Phishing usually arrives by spoofed email or SMS. This did not. Push notifications skip email spam filters and borrow the trust that iOS and Android give an installed app, so people have far less reason to suspect a hoax.

Downdetector logged nearly 500 reports of problems with the ASOS site shortly before 10:00 AM. It is unclear whether those reflected real backend trouble or panicked users logging in to check their accounts. ASOS shares, which had been recovering for a year, fell as much as 15% in early trading as investors reacted to the apparent breach and the company’s silence.

ASOS Hack Notification
ASOS Hack Notification

The crisis communication gap

The first hour of a breach is when a company can still shape the story, and ASOS said almost nothing for several hours. It pulled scheduled promotional posts from social media but did not replace them with a holding statement. The only thing customers could reach was an automated chatbot, which said ASOS was “aware of the notification and is currently investigating” while calling the alert “fraudulent.”

Aimee Speight, founder of Highland Consulting, put it bluntly: “the hackers are doing a better job of communicating than ASOS is.” Each silent hour let the attackers’ version of events settle in. In the early afternoon ASOS finally confirmed “unauthorised activity involving third-party platforms” and said payment card details and passwords were not affected.

Technical deep dive: the MarTech stack and API compromise

Sending a push notification to millions of users while also claiming a backend data warehouse breach only makes sense once you look at how a modern retailer’s marketing stack works. Companies like ASOS don’t run one monolithic database. They run a web of SaaS platforms that ingest, analyze, and activate customer data.

📬 Stay Ahead of Cyber Threats

Get the latest cybersecurity news, critical vulnerabilities, threat intelligence, tutorials, and exclusive giveaways delivered straight to your inbox. No spam. Unsubscribe anytime.

Subscribe to the Newsletter →

The pipeline: Snowflake, Simon AI, and reverse ETL

ASOS is known to use Snowflake as its main cloud data warehouse. Snowflake is a multi-tenant SaaS platform for storing large volumes of structured and semi-structured data, but it is an analytics engine and has no way to message customers. For that, ASOS uses Simon Data (often called Simon AI), a CDP.

Simon AI integrates closely with Snowflake and pulls in behavioral, transactional, and demographic data to build one-to-one customer profiles. That setup drives personalized campaigns, which previously helped ASOS generate tens of millions in incremental revenue.

Once Simon AI has segmented an audience (say, “users who bought winter coats in the last 30 days”), the campaign goes to an engagement provider such as Braze, Klaviyo, or Urban Airship (now Airship), which ASOS has historically used for push delivery. The handoff usually runs through reverse ETL tools or direct API integrations.

The likely attack vector: stolen API keys and OAuth tokens

The “fully compromised the Snowflake instance” claim probably blurs the data warehouse and the CDP sitting on top of it. Snowflake says it found “no compromise of the Snowflake platform.” That fits how most cloud breaches go: the vendor’s core infrastructure holds, and the customer’s own tenant is breached with stolen credentials.

To send the malicious push, the attackers didn’t need the core e-commerce database. They needed the API keys or OAuth tokens that connect the CDP or reverse ETL pipeline to the push provider. Admin access to a CDP’s orchestration console gives an attacker control over the brand’s entire messaging channel. They can skip the normal marketing workflow, write any payload they like, and broadcast it to every registered user through Apple Push Notification service (APNs) and Firebase Cloud Messaging (FCM).

Dan Bird, Field CTO at Horizon3, noted that sending a push requires access to a system separate from the Snowflake platform. In his reading, the attackers “got hold of credentials that opened more than one door.”

The Snowflake context: infostealers and earlier breaches

Naming Snowflake in the extortion note set off alarms because of the platform’s recent history. In mid-2024, a wave of breaches hit Snowflake customers and exposed hundreds of millions of records at companies including Santander and Ticketmaster. No flaw in Snowflake’s own code was involved. The threat actor, tracked by Mandiant as UNC5587, used infostealer malware such as RedLine, Lumma, and Vidar to harvest credentials from infected employee devices.

Those infostealers collect browser cookies, saved passwords, and command-line interface (CLI) configurations. If an ASOS data engineer or marketing analyst had Snowflake credentials saved on an infected personal or work machine, an attacker could skip the corporate network and log into the ASOS tenant directly from a residential IP address.

By mid-2026 the market for stolen cloud credentials had matured. Criminals sell “cloud access packages” on dark web forums, so extortion groups can buy access to a valuable target without running the phishing or malware campaign themselves.

What data is at risk

ASOS says “basic personal information including name and contact details may have been accessed,” and that payment information and passwords are safe. That matches standard PCI-DSS (Payment Card Industry Data Security Standard) architecture. Raw card numbers (PANs) and CVVs don’t belong in a marketing data warehouse. A payment gateway such as Adyen, Stripe, or a proprietary vault tokenizes them at the point of sale, so Snowflake only receives the token and transaction metadata, such as “User X purchased Item Y for $50 on Date Z.”

The attackers may therefore hold a lot of PII: names, home addresses, email addresses, phone numbers, purchase histories, and even the clothing sizes Simon AI stores. They would not have what they need to clone cards or commit direct financial fraud.

Threat actor intelligence: profiling XuanyeGroup

Putting a Telegram link in a mass push notification is a loud, unusual move. Established extortion groups like the now-defunct LockBit and BlackCat run Tor-based data leak sites and negotiate through private chat portals. Advertising a Telegram channel to millions of consumers tends to draw law enforcement attention fast.

The Roblox and Counter-Strike connection

KELA Cyber’s threat intelligence gives a glimpse of the actors’ operational habits and money motives. Researchers found that an account tied to the ASOS extortion attempt had tried in September 2026 to buy $100,000 worth of in-game items for Roblox and Counter-Strike.

That pattern is typical of digital asset money laundering. Criminals holding large amounts of illicit cryptocurrency or stolen fiat often can’t cash out through banks because of KYC and AML rules. Instead they spend it on liquid digital goods, such as rare CS:GO skins or limited Roblox items, then resell those on gray-market forums for clean crypto or fiat.

KELA noted that the account behind XuanyeGroup has changed usernames several times and was probably bought on the dark web. That suggests either a new syndicate working as an access broker or a splinter of a larger ransomware group.

The “generous” extortion statement

In the new Telegram channel, the group posted a strange message to calm the panic it had caused: “To clear any confusion, the affected organisations app is safe to use. The incident involves customer information, it is safe on our server, and it will not be touched for a designated period. Considering the current situation regarding incident disclosure in the cyber security landscape, you can thank us for our generous clarity regarding this incident.”

The wording looks deliberate and probably has three aims. Telling ASOS the data is safe and untouched may discourage it from cutting the compromised API connections right away, which would keep the attackers’ access alive. Downplaying the immediate danger to consumers may ease pressure on law enforcement to prioritize the case. And presenting themselves as reasonable sets up a private demand later, something like “pay us $2M in Monero and we will delete the data.”

Ian Thornton-Trump, CISO at Inversion6 UK, called it a “clear-cut data extortion attempt,” with the attackers relying on the volume of personal data in the Snowflake and Simon AI environment as leverage.

What ASOS shoppers should do

Millions of people got the notification, and they are now open to follow-on attacks. Criminals watch trending news and launch smishing and phishing campaigns while the victim company is still working out its response.

  1. Don’t click the Telegram link. It leads to a channel run by the extortionists, and engaging with it tells them your device and phone number are active and tied to an ASOS account.
  2. Expect secondary phishing. Charlotte Wilson, Head of Enterprise at Check Point, warns that criminals will exploit the confusion. Watch for emails and texts saying “Your ASOS account has been locked due to the breach. Click here to reset your password.” Don’t click them.
  3. Reset your password out of band. Type the ASOS address into your browser yourself rather than using a search result or bookmark, and change your password. If you reused it elsewhere, change it on those sites too.
  4. Watch for social engineering. With names, addresses, and purchase history potentially stolen, an attacker may call ASOS support or your mobile carrier and use that data to pass security questions. Be suspicious of unsolicited calls about your accounts.
  5. Use tokenized payment methods. ASOS says payment data wasn’t compromised, but Marijus Briedis of NordVPN recommends paying through Apple Pay, Google Pay, or PayPal in future, since those keep your real card number from the retailer.

The CISO playbook: hardening the MarTech stack

For security leaders, this incident shows the attack surface reaching well past the firewall and the production database. IT teams often treat the MarTech stack as low risk, yet it holds the brand’s direct line to its customers.

API security and secrets management

The most likely way in was theft of API keys or OAuth tokens linking the CDP to the push provider. Marketing teams and outside agencies often create these keys and then leave them in plaintext in GitHub repos, Notion pages, or Slack channels.

Store every key and token in an enterprise vault such as HashiCorp Vault, AWS Secrets Manager, or Azure Key Vault. Log access to them, rotate them automatically every 30 days, and scope them to least privilege. A key that pushes audience segments should not be able to broadcast arbitrary messages to the whole user base.

Hardware-backed MFA for cloud tenants

The Snowflake breaches of 2024 and 2025 showed that SMS codes and authenticator apps are not enough against attackers using infostealers and session cookie hijacking. Gate cloud data warehouses (Snowflake, Databricks), CDPs (Simon Data, Segment), and engagement platforms (Braze, Airship) behind FIDO2/WebAuthn hardware keys such as YubiKeys. Add strict session token timeouts, and monitor for impossible-travel logins and unusual API calls from residential IPs or known Tor exit nodes.

Third-party risk management

ASOS said the breach involved “third-party platforms that we use to communicate with customers.” A CDP or push provider has deep access to your customer base, so audit those vendors as rigorously as you audit payment processors. Review their SOC 2 Type II reports, ask for evidence of their own API security controls, and put contracts in place that hold them accountable for breaches that start in their infrastructure.

Out-of-band incident communication

The most damaging part of this incident was the communication vacuum, more than the data theft. Once the push channel is compromised, a company has lost its most direct way to reach customers.

IR plans should include pre-drafted, legally reviewed holding statements and a fallback for reaching users if the app is compromised. That could mean a separate transactional email provider such as SendGrid or Amazon SES for security alerts, a CDN banner system that can put a warning on the website within minutes, and a standing procedure to pin security updates to the top of X, Instagram, and Facebook, overriding scheduled marketing posts through API integrations.

Financial and reputational impact

The cost of a MarTech breach goes beyond forensics and possible GDPR or CCPA fines. Marty Bauer, an e-commerce expert at Omnisend, said: “People let a brand onto their phone because they trust it. Once that channel has been used to threaten them, they may start questioning genuine messages too.”

Push notifications are among the highest-converting channels in e-commerce. If millions of users switch them off for good, the long-term revenue loss could exceed the 15% share price drop. Digital retail trust is slow to rebuild, and the attackers seem to have understood that hitting customer trust does as much damage as hitting the technology.

Final analysis

The ASOS incident shows the extortion economy moving beyond ransomware on endpoints. By compromising the link between the data warehouse and the customer’s phone, XuanyeGroup caused maximum reputational damage with little technical effort.

ASOS customers can take some comfort that the PCI-DSS boundary appears to have held and their financial data is safe. The theft of behavioral and demographic data is still a serious privacy violation. For the industry, the lesson is that MarTech stacks need the same zero-trust security as the core financial ledgers. As forensic teams trace the API compromise, the assumption that marketing databases are low risk no longer holds.

Disclaimer: This article is based on breaking news reports, threat intelligence analysis, and enterprise architecture standards as of October 6, 2026. Readers should follow official guidance from ASOS and the relevant data protection authorities.

Buy me A Coffee!

Support The CyberSec Guru’s Mission

🔐 Fuel the cybersecurity crusade by buying me a coffee! Your contribution powers free tutorials, hands-on labs, and security resources.

Why your support matters:
  • Writeup Access: Get complete writeup access within 12 hours
  • Zero paywalls: Keep the main content 100% free for learners worldwide

Perks for one-time supporters:
☕️ $5: Shoutout in Buy Me a Coffee
🛡️ $8: Fast-track Access to Live Webinars
💻 $10: Vote on future tutorial topics + exclusive AMA access

“Your coffee keeps the servers running and the knowledge flowing in our fight against cybercrime.”☕ Support My Work

Buy Me a Coffee Button

If you like this post, then please share it:

News

Discover more from The CyberSec Guru

Subscribe to get the latest posts sent to your email!

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from The CyberSec Guru

Subscribe now to keep reading and get access to the full archive.

Continue reading