GROUP-IB researchers have traced the Telegram account used in the alleged ASOS incident to a channel formerly active in gaming-item trading. The account behind the claimed “Xuanyewen” label appears to have been newly created on 6 October 2026, with prior aliases including JohnCZ and Moon Transfers.
Threat researcher Anastasia Tikhonova emphasised that the evidence does not establish who controls the account, how access was gained, or a verifiable link to ASOS data; she cautioned that there is currently no sample, data dump or other proof of data access. The investigation thus far distinguishes confirmed facts from unproven claims.
ASOS has acknowledged ongoing investigations into unauthorized activity linked to third‑party customer‑facing platforms and has restricted access to those notification channels while working with advisers and authorities. The firm says basic personal information such as names and contact details may have been accessed, but there is no evidence that payment cards or passwords were affected.
Group-IB notes that sending a notification demonstrates access to a customer‑messaging channel, not possession of a customer database, and Snowflake has reported no compromise of its platform. Industry voices suggest this points to a possible SaaS‑level compromise rather than a direct breach of ASOS’s core systems. If data were exposed, analysts warn it could involve customer, sales, order or marketing information, with risks of fraud or phishing. UK experts urge vigilance but caution against panic, plus standard mitigations and reporting as advised by NCSC.