Breaches

Asos breach wider than first disclosed after staff login stolen

Asos says a social engineering attack on one employee exposed customer data via third-party marketing platforms. What UK organisations should learn.

Padlock graphic with the headline Asos breach wider than first disclosed and the label Data breach

Asos now says a social engineering attack on a single employee gave an intruder access to the marketing platforms it uses to message customers, and the data taken goes beyond the names and contact details it first disclosed. With 16.5 million customers and the UK as its biggest market, this is a textbook case of third-party SaaS risk landing on a British retailer.

What happened

On the morning of Tuesday 6 October 2026, users of the Asos mobile app received a push notification headed “ASOS HACKED”. Rather than speaking to shoppers, it was written to the retailer’s data protection officer and IT team, claiming the sender had taken over a Snowflake instance and threatening a leak unless the company made contact. A link pointed to a Telegram channel run by a group calling itself Xuanye (it has also used the name Xuanyewen).

Asos confirmed the same day, in a statement to the London Stock Exchange and an apology to customers, that it was investigating unauthorised activity on third-party platforms it relies on for customer communications. It said access to those platforms had been restricted, that specialists and the relevant authorities were involved, and that it did not believe payment cards or account passwords had been touched. Its shares dropped by more than 10% that day, and it told investors it was too early to put a figure on any trading impact, while noting it holds cyber insurance.

The National Cyber Security Centre published guidance the same day and its chief executive, Dr Richard Horne, said the agency had reached out to Asos to offer support. It told every Asos customer to assume they were affected, alert or no alert.

The picture then widened. On Thursday 8 October, Asos emailed customers to say that a 48-hour investigation showed a staff member had been tricked by someone pretending to be a trusted contact, and that the stolen login was then used against those third-party systems. The company added that “certain non-personal account related information” had also been accessed, on top of names and contact details. The BBC, which had been sent a sample by the attackers, reported that it contained addresses, phone numbers, email addresses, customer numbers and app search terms, although it is unclear whether that sample has been independently checked.

The technical picture

This was not a break-in through Asos’s own perimeter, and on current evidence it was not a compromise of Snowflake either. Snowflake said it investigated and found the incident did not stem from any flaw or misconfiguration in its service, adding that its customers need take no remediation action.

Attention has instead turned to the marketing stack sitting on top of the data warehouse. The attacker told the BBC that a Simon AI instance was the route in. Simon AI is an agentic marketing platform built on Snowflake Cortex AI; it lists Asos as a customer and was acquired by Monetate in July. According to Malwarebytes, Asos’s marketing function uses Simon AI alongside Braze to drive messages such as push notifications. That would explain how one stolen login yielded both data and a broadcast channel to every app user. Asos has not named the platforms involved.

Personalisation tools typically hold search history, purchase patterns and customer segments. That fits the attackers’ claims, and explains why the “basic contact details” framing of the first statement did not survive the week.

On attribution, Group-IB found the Telegram channel was only created on 6 October, and that the account behind it had previously carried display names linked to trading in-game items. That hints at an opportunistic actor rather than an established ransomware brand, though firm conclusions would be premature.

Timeline of the Asos breach from credential theft and the rogue push notification on 6 October to the wider disclosure on 8 October 2026

Why it matters for UK organisations

Asos is the latest name in a run of high-profile attacks on UK retail and consumer brands, following Marks & Spencer, Harrods and Jaguar Land Rover. What links them is not exotic malware. It is people being talked into handing over access, and attackers then moving into systems that sit outside the traditional security boundary.

Three points stand out for UK organisations. First, the regulatory exposure: personal data of UK customers was taken, so UK GDPR breach reporting and the Information Commissioner’s Office are in play, and the volume of customer communications Asos has had to issue shows how quickly the narrative can shift. Second, the follow-on fraud risk: a dataset that combines names, addresses and shopping searches is ideal raw material for convincing, tailored phishing and delivery scams. Third, the trust channel itself was abused. Push notifications from a brand’s own app are among the most credible messages a customer receives, and that credibility was turned against the business.

Expert view

In my experience, marketing and customer engagement platforms are some of the least scrutinised systems in a typical estate. They are bought by the business, wired into the data warehouse with broad read access and handed every outbound channel. When we test organisations, these tenants rarely appear in scope, and conditional access often stops at the core Microsoft or Google tenant.

The phrase Asos used to describe the initial access, an attacker “impersonating a trusted contact”, should worry every security team. It implies a targeted pretext rather than a mass phishing email. A stolen login to a third-party console bypasses endpoint tooling, so detection rests on identity telemetry and the provider’s audit logs.

The response deserves a fair reading. Asos locked down the platforms quickly, worked with the authorities and updated customers within 48 hours. However, as one PR commentator quoted by Cyber Magazine put it, “reassurance must keep pace with the evidence”. Early statements that later need upgrading cost more trust than a cautious first message.

What to do now

  1. Inventory your SaaS estate. List every platform that holds customer data or can send messages in your name, including marketing, CRM, analytics and AI tooling. Name an owner for each.
  2. Enforce phishing-resistant MFA everywhere. Put these platforms behind SSO with passkeys or FIDO2 keys where supported. This maps directly to the Cyber Essentials user access control requirement, which expects MFA on cloud services wherever it is available.
  3. Cut standing access. Review who can export data or broadcast to customers, apply least privilege and remove dormant accounts (Cyber Essentials: user access control).
  4. Harden the human layer. Train staff, especially in marketing and customer teams, to verify unexpected requests through a second, known channel, including requests from apparent colleagues or suppliers.
  5. Watch identity and SaaS logs. Alert on new-device logins, bulk exports and unscheduled campaign sends. Confirm your contracts give you access to provider audit logs.
  6. Prepare a broadcast-abuse playbook. Know how to suspend push, SMS and email sending within minutes, and draft holding statements that separate confirmed facts from open questions.
  7. If you are an Asos customer, follow the NCSC advice: treat unexpected messages mentioning Asos with suspicion, do not click links in them, and use passkeys or unique passwords with two-step verification.

Bottom line

The Asos incident shows that a retailer’s most sensitive data and most trusted customer channel can sit in a marketing tool protected by one person’s password. Treat SaaS platforms as security assets, bring them into scope, and assume someone will try to talk their way in.

Sources