ASOS Breach Investigation: Insights from Group-IB and Industry Experts
Recent revelations from Group-IB, shared exclusively with Infosecurity, indicate a significant connection between a Telegram account linked to the alleged ASOS hack and a forum previously frequented by gaming-item traders. The investigation led by Anastasia Tikhonova, Global Head of Threat Research at Group-IB, highlights the suspicious activity surrounding the Telegram channel t.me/xuanyewengateway, which was notably associated with a bizarre push notification sent to ASOS customers on October 6. In this notification, a threat actor claimed to have breached the company’s security through a Snowflake instance.
Upon further examination, Tikhonova discovered that this particular Telegram channel was newly established on the same day that the notification was sent. The account in question, now recognized as “Xuanyewen” (@xuanyegroup), had previously operated under different monikers, primarily within the gaming domain. The account’s earlier aliases include JohnCZ (@JohnCzwartacki) and Moon Transfers (@NFTmoonstock).
Utilizing their instant messaging monitoring system, Group-IB was able to retain historical changes made to Telegram account display names and usernames. This documentation revealed that the previous identities of the now-identified account were the same, indicating a possible rebranding or repurposing in light of the current situation. Tikhonova remarked, "This suggests an identity set-up or reorganized around this incident. It does not tell us who controls it, how experienced they are, or how access was gained. Furthermore, we currently have no evidence regarding the entry route."
Despite her thorough investigation, Tikhonova stated she had not uncovered any substantiating evidence confirming the hacker group’s claim of possessing ASOS customer data. “We have seen no sample, dump, or other evidence,” she emphasized, urging for clarity about the differences between verified events and unproven assertions.
ASOS Incident: Confirmed Facts and Unverified Claims
In response to the claims regarding unauthorized activities, ASOS initially communicated that it was investigating the matter, highlighting the involvement of third-party platforms used for customer communication. The organization asserted that it took “immediate action” to restrict access to these communication platforms and is collaborating with both internal and external specialists, as well as relevant authorities.
ASOS acknowledged that basic personal information, including names and contact details, may have been accessed by the alleged threat actor. However, preliminary investigations suggested that sensitive information such as payment-card details and account passwords was likely unaffected. The administrator of the associated Telegram channel also asserted that payment information had not been compromised.
Additionally, the company confirmed that its website and mobile application continued to operate normally, assuring that overall operations remained uninterrupted. Despite this, ASOS has not mentioned Snowflake in its statements. The cloud service provider subsequently informed Infosecurity that it had found “no compromise of the Snowflake platform.” Group-IB’s Tikhonova indicated that the ability to send notifications indicates access to a messaging channel rather than direct possession of customer data.
UK Retailers Face Rising SaaS and Data Extortion Threats
Will Thomas, Senior Threat Intelligence Advisor at Team Cymru, assessed that the ASOS incident likely indicates a compromise involving a software-as-a-service (SaaS) platform. This approach has become prevalent in high-profile cyberattacks targeting UK retailers over recent years. He highlighted the speculation around various potential attack vectors, such as social engineering to exploit helpdesk resources for password resets, discovering API keys in exposed JavaScript code, or using credentials recycled from earlier data leaks.
Thomas noted that these tactics have been employed by other data-extortion cybercriminals like FulcrumeSec and Lapsus$. He underscored the attack on ASOS as yet another alert to the ongoing threat of data extortion campaigns faced by UK businesses. Tikhonova elaborated that attackers are increasingly targeting the software systems and integrations that companies rely on, as a single point of access can yield extensive reach. Retailers, in particular, are seen as vulnerable to such tactics.
What ASOS Customers Should Do to Mitigate the Threat
Nick Dyer, RVP of Solutions Engineering for the UK, Ireland, and Benelux at Arctic Wolf, raised concerns that the potentially compromised data may encompass customer, sales, and operational datasets, leading to risks such as fraud, phishing, and identity theft. He noted the vast scale of ASOS’ operations, with around 17 million global customers, further amplifying the potential impact of the breach.
Dyer advised customers to remain vigilant while also advising against panic. He recommended basic protective measures, such as avoiding interaction with any unexpected notifications or messages claiming to be from ASOS, particularly those soliciting personal information. Customers were urged to scrutinize potential communications from unknown numbers and, if in doubt, to directly visit the ASOS website.
Furthermore, given that ASOS may not have implemented multifactor authentication (MFA) as a standard for logins, customers were encouraged to change their passwords as a precaution. The UK’s National Cyber Security Centre (NCSC) also shared guidance for ASOS customers, which aligns closely with Dyer’s recommendations. Their resources include advice on how to report potential fraud and tips for enhancing online security.
In summary, the recent investigations and assessments underscore the pressing cybersecurity landscape that retailers face and the critical need for robust protective measures to safeguard customer data. The ongoing scrutiny of the ASOS incident serves as a cautionary tale for organizations reliant on third-party platforms for customer engagement.

