ASOS has disclosed a breach this week in which a threat actor, naming itself Xuanye Group, gained unauthorised access by abusing a login credentials chain starting from an employee’s trusted contact. Check Point threat intelligence briefs describe how the attacker used the compromised account to reach ASOS’s third‑party platforms and, crucially, the company’s customer-facing marketing and notification systems.
ASOS says the intruder obtained names, contact details and non‑personal account information for some customers; payment data were reportedly not at risk, according to the actor’s statements and subsequent reporting. The incident was publicly announced on 6 October 2026 and has been linked by some outlets to a broader revenue-critical channel that can reach millions of app users with unauthorised push notifications.
The breached systems include ASOS’s mobile app notification infrastructure, which allowed the attackers to deliver messages directly to customers under the retailer’s brand. BBC reporting and other sources note the attackers’ claims of access to a Snowflake instance and possible use of a “Simon AI” agent within cloud data platforms to reach customer data, though neither ASOS nor independent researchers have confirmed this pathway.
ASOS has stated that payment information was not exposed, while investigators and press reports identify exposed data such as names, addresses, phone numbers, emails, dates of birth, customer IDs and search histories. Security commentators emphasise that marketing and notification platforms can hold large volumes of customer data and effectively enable a communications channel to victims, underscoring the need to treat such platforms as part of critical security infrastructure.
ASOS and industry observers advocate heightened scrutiny of customer‑facing channels and swift incident communications to mitigate reputational and commercial damage.