Security News

ASOS Breach Started With a Fake Trusted Contact and a Stolen Staff Login

Infosecurity Magazine · 8 Oct 2026
Key Takeaway Train staff to verify any unexpected request for login details through a separate, known channel, and review which third-party platforms your team can access with a single account.

UK fashion retailer ASOS has told customers that an attacker accessed personal and customer account data after a breach on October 6. In an email sent on October 8, the company said payment information was not compromised and that its operations were not affected. ASOS said the attacker got in by impersonating a trusted contact to obtain an employee's login credentials, then used those credentials to reach information on certain third-party platforms the company uses to communicate with customers.

Access to those platforms let the attacker send a legitimate-looking push notification to ASOS customers. It appeared to be addressed to the company's data protection officer and IT team, and claimed a Snowflake instance had been compromised. Snowflake told Infosecurity it found no compromise of its own platform. A Malwarebytes researcher suggested an agentic marketing platform used by ASOS, Simon AI, may be indirectly linked because it is built on Snowflake Cortex AI. The BBC reported that the attacker said a Simon AI instance was compromised. Monetate, which acquired Simon AI in July, has been contacted for comment.

The attacker, using the names 'Xuanyewen' and 'Xuanye group', claimed on Telegram that only customer information was involved. This is an early report from the opening of the story, and the investigation is continuing.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from Infosecurity Magazine, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.