Hackers behind the ASOS data breach claimed to have access to users' search history. According to the BBC, the data the threat actors possess showed search terms used by customers like "reclaimed vintage", "glamorous wide fit" and "Asos petite.”
Allegedly, the hacker group namely, ‘Xuanyewen group’ may have been behind the data breach. The BBC noted that they might have additional information such as customer numbers, addresses, contact details and names.
However, this seems to contradict ASOS’ statement, which noted that “basic personal information” was breached.
Natalie Page, Cyber Security Head of Threat Intelligence at Talion, claims that this specific data breach “is a typical tactic of extortion groups” who usually seek “media attention and publicity” around breaches to pressurise big retail companies such as ASOS.
Regarding the specific message left by the attackers, Page strongly believes that this data breach is an extortion attack. Additionally, she suspects that threat actors will want a ransom.
After a 48-hour investigation of the data breach that hit the online retail platform, cybersecurity experts have come to conclude that hackers obtained log-in credentials by gaining access to an employee account.
The threat actors successfully managed to impersonate a trusted contact. They used the employee account details to access ASOS’s “information on third-party platforms,” according to the BBC.
ASOS is a well-renowned online British fashion retailer that had 23 million active buyers in 2023, the majority of whom were based in the UK, as per Business of Apps. BBC reported that ASOS has a global footprint catering to about 17 million customers each year across 150 markets.
This data breach has now raised significant concerns over the security of customer information the company holds.
ASOS Shares Drop By 10%
On Tuesday, Reuters noted ASOS shares dropped by 10 per cent; however, earlier today the retailer’s shares were up by 3 per cent, “pairing losses for the week to 8 per cent.”
ASOS has not asked their customers to take any action at this moment. However, cybersecurity experts are warning people to take extra precautions by changing passwords in case of any future potential attacks.
Although passwords were reportedly not stolen during the data breach, Trevor Dearing, Senior Director of Critical Infrastructure at Illumio, says to “be highly suspicious of any unsolicited text or email asking you to change or share yours,” as reported by the BBC.
The BBC also warned that customers could face an increased risk of phishing emails and scam calls following the breach.
Scammers may refer to the ASOS attack and use customers' personal information to make their communications look genuine. They may also create a sense of urgency, such as by threatening to lock an account unless immediate action is taken.
ASOS has reassured customers that their website and application remain safe to use, announcing “we know our customers trust us with their information”.
They further stated that the company takes their “responsibility seriously” and has already introduced additional measures to advance their security protocols.
When Fraud Becomes Infrastructure
World Cup scams show fraud evolving into pre-built cyber infrastructure, forcing boards to treat digital trust as a core enterprise asset.
What Really Happened During the ASOS Cyberattack?
Allegedly, a hacker group named ‘Xuanyewen group ’, suspected to hail from China, posed as a trusted contact and gained unauthorised access to third-party platforms used by ASOS. Snowflake has surfaced as one of the platforms subjected to the data breach scrutiny.

The online retail enterprise, in an official statement, said that personal and customer data had been infiltrated. However, it has also insisted that customers' payment information was not compromised, and operations weren’t impacted.
The data breach spotlights issues with how the hackers could manipulate ASOS’s own systems to communicate with customers. Muhammad Yahya Patel, vCISO and Cybersecurity Adviser at Huntress, stated:
"The attackers didn't just steal from ASOS. They used ASOS's own voice to tell its customers about it. That's a complete loss of operational control, and the reputational damage from that alone is significant”.
The BBC reported that a data sample sent by the hacker contained more than basic contact details, including emails, customer numbers and search history. The media outlet has also said that the cyber criminals professed to have accessed ASOS customer data using Simon AI, a Snowflake AI technology.
Inside Modern Phishing Workflows
How sandboxes, SSL decryption and TI pipelines reshape SOC workflows, cutting triage time while strengthening phishing detection.
How is Snowflake Relevant to the ASOS Cyberattack?
ASOS’s login credentials to a Snowflake instance were allegedly jeopardised as part of the cyberattack.
The BBC reported that the ‘Xuanyewen group’ attained access through a compromised Simon AI instance, which may explain why the breach was labelled as a Snowflake compromise. Snowflake, though, maintains that its platform was not breached.
Simon AI is an “agentic marketing” platform, built on “Snowflake Cortex AI,” a Snowflake AI technology. However, this claim has not yet been confirmed by the platform.

Snowflake is a well-known cloud-based storage company used by thousands of companies worldwide. According to Land Base, 14,547 verified companies used the platform as of 2026. ASOS was one such client that uses Snowflake to store its customer data.
According to Bleeping Computer, ASOS said that the threat actors impersonated a trusted contact to steal login credentials and access third-party customer communication platforms. The hackers claim they got in through a marketing tool linked to Snowflake, though Snowflake denies being breached and ASOS has not confirmed that route.
However, Snowflake has a history of cyberattacks targeting customer accounts, resulting in “unauthorised” logins, such as the 2024 data breach, which involved inadequate security controls and compromised login credentials, as reported by Huntress.
This alleged Simon AI intrusion resulted in ASOS application users receiving a push notification stating: “We have fully compromised the Snowflake instance. Engage with us, or we will leak it”.
A spokesperson at Snowflake told Infosecurity: “We can confirm this issue did not in any way result from a vuln, weakness, flaw or misconfiguration with the Snowflake service, platform or internal environments, and was not caused by Snowflake. No remediation is required for Snowflake customers.”
Why Do Employees Ignore Cybersecurity Warnings?
Employees are surrounded by security warnings. So why do they stop paying attention? The answer has less to do with carelessness and more with how the brain responds to repetition, interruption and perceived risk.
What Should You Do If Your Online Fashion Retail Account Was Compromised?
ASOS announced that the data breach is still being investigated. The company plans to reach out to customers who could have been exposed to the cyberattack for “additional information, support or action” that may be required, according to the BBC.
Following the recent data breach, customers could be confronted with an increased risk of scam calls and phishing attacks.
Paul Arnold, the Chief Executive of the Information Commission's Office (ICO), released a statement on behalf of ASOS recognising that receiving a message from potential threat actors can be upsetting. He recommends to “stay alert” and be “cautious of any links or attachments”.
The ICO also advises users to log into their accounts through official websites or applications and monitor their bank accounts for unusual activity. They also suggest “never share personal or financial information in response to unexpected contact.”
“Using strong, unique passwords and enabling multi-factor authentication” can help protect customer accounts.
Comments ( 0 )