ASOS Hack Claim: Telegram Account Behind Rogue Alert Previously Used for Gaming Trades
New findings from threat intelligence firm Group-IB suggest the Telegram account tied to the alleged ASOS hack was previously used for gaming-item trading. Anastasia Tikhonova, the firm's global head of threat research, found that the channel named in a strange push notification sent to ASOS customers on October 6 was created that same day. The account behind it had earlier operated under other names, including ones linked to gaming-item trading. She said this points to an identity set up or reorganised around the incident, but it does not reveal who controls it, how experienced they are or how access was gained.
Tikhonova also said she has seen no sample, data dump or other evidence to support the claim that the group holds ASOS customer data. She stressed the need to separate what is confirmed, what has likely happened and what remains an unproven claim. The notification had claimed a breach via a Snowflake instance, but Snowflake told Infosecurity it has found no compromise of its platform, and ASOS has not mentioned Snowflake in its statements.
ASOS confirmed it is investigating unauthorised activity involving third-party platforms it uses to communicate with customers, and says it restricted access to those notification platforms. It acknowledged that basic personal details such as names and contact details may have been accessed, but investigators do not believe payment-card information or account passwords were affected. The company says its website, app and operations are running normally.