Group-IB found no evidence of leaked data or files to support extortionists’ allegations that were shared with ASOS app users on October 6, 2026. ASOS is currently conducting an investigation into unauthorized activity on third-party messaging channels used to communicate with customers.
What Happened?
- ASOS says names and contact details may have been accessed, but it does not believe card data or passwords were hit.
- Attackers used the ASOS app’s own notification system to send a ransom note addressed to the retailer’s data protection officer.
- Group-IB traced the linked Telegram account to a new identity with a past in trading Roblox and CS:GO game items.
- Snowflake says it has found no compromise of its platform so far, and its own investigation remains open.
- ASOS has 16.5 million active customers in more than 100 markets and has not said how many got the alert.
The ransom note came through the ASOS app
The alert came through at about 10am. It was sent to the DPO and IT team within the firm. The note was not really aimed at consumers. It said they had access to an ASOS instance on Snowflake. The note ended with a hard message: “Deal with us or we will release.” It included a link to a Telegram channel for a new group named Xuanye Group.
Users notified the BBC in their dozens. The alerts were initially reported by the broadcaster. Charlotte Wilson, head of enterprise at Check Point, said it was a particularly worrying situation, assuming it was genuine, because the threat was on the retailer’s app.
The company said it has limited access to the notification channels for users. It is liaising with third-party experts and relevant authorities. “We do not believe that payment card information and account passwords, were impacted,” it told investors.
There are reportedly over 10M downloads on Google Play for the Android app. So potentially millions of users. Reuters said subsequently that the group wrote that payment info was not impacted. The app was safe to use. The group also said it had data from users on its server and it was not touched for a period of time.
ASOS confirms security breach after customers receive push notification from attackers via the app. https://t.co/b4LxMqYMhn
— Malwarebytes (@Malwarebytes) October 6, 2026
Researchers find no proof the data left ASOS
Anastasia Tikhonova, global head of threat research at Group-IB, splits the incident into layers. ASOS has confirmed unauthorized activity on its third-party communication platforms. Access to a messaging channel is possible. Theft of a full customer database is only claimed, and Group-IB found no files or samples to support it.
The Telegram identity surfaced the same day as the alert. Its history shows Roblox and CS:GO item trading under names including “JohnCZ” and “Moon Transfers.” Tikhonova cautioned that this trail doesn’t reveal who controls the account, how skilled they are, or how they got in.
Pieter Arntz, senior malware intelligence researcher at Malwarebytes, said ASOS uses Simon AI for marketing, and that tool runs on Snowflake. Exposure there could reveal buying habits, location, and loyalty status, the raw material for scams covered in what happens to data after a breach. Arntz added that the link alone doesn’t show what the attackers could actually reach.
We don’t have a source that connects the two. ASOS has yet to tell us how many people received this, or how the hackers were able to access the messaging system. They haven’t told us if customer data was exfiltrated or if any customer data left their systems, and haven’t said if they tampered with the Simon AI data.
Treat every ASOS message as suspect for now
Alan Snyder, CEO at NowSecure, argued that the same access could make a fake payment request look like routine customer service.
Marie Wilcox of Binalyze called the alert psychological pressure aimed at ASOS, but customers carry the follow-on risk. Andrew Curtis of Gadget Access warned that an order history can hand scammers a convincing script. The UK National Cyber Security Centre (NCSC) advises ASOS customers to assume they’ve been affected, and the basics of spotting phishing apply in full. Steps that help reduce risk:
- Don’t open the Telegram link from the alert, or any message that repeats it.
- Check order and account updates by opening the ASOS website or app yourself, never through a link in an email or text.
- Treat unexpected emails or texts claiming to be ASOS support as suspect, even when they name a real recent order.
- Call your bank straight away if you see transactions you didn’t make.
Neither ASOS nor Snowflake has published findings yet. Until one does, the only timeline on the table is the one the attackers set themselves. That leaves a self-described extortion crew holding the clock.
































































