Security1 publisherNot yet confirmed elsewhere2 min readPublished
Group-IB traces ASOS's rogue push alert to a renamed gaming-trade Telegram account
Group-IB found the Telegram channel in ASOS's October 6 rogue push alert was opened that day by an account once used for gaming-item trading. Until data surfaces, the Snowflake claim is unproven and the abused messaging platform is the lead to work.
The Watch · Security desk

What happened
- Snowflake told Infosecurity it found no compromise of its platform, and ASOS has not mentioned Snowflake in any of its statements.
- ASOS says unauthorized activity involved third-party platforms it uses to message customers, and it has restricted access to those notification platforms.
- ASOS says names and contact details may have been accessed but does not believe payment-card data or account passwords were affected.
- Group-IB's Anastasia Tikhonova says she has seen no sample, dump or other evidence that the group holds ASOS customer data.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure The same notification access that delivered a Telegram link could deliver a phishing link under the ASOS name, and that attack needs no customer database.
- constraint With Snowflake reporting no platform compromise and no data sample public, defenders get no Snowflake indicator to hunt for from this incident.
- decision Retailers running third-party push and messaging tools have to decide whether those accounts get data-warehouse-level monitoring; Tikhonova argues they carry the same trust.
- precedent If the entry route turns out to be a SaaS credential or exposed API key, ASOS fits the method Thomas ties to Scattered Spider and Lapsus$ attacks on UK organizations.
The account behind the channel now goes by Xuanyewen (@xuanyegroup). Group-IB found it previously ran as JohnCZ (@JohnCzwartacki) and Moon Transfers (@NFTmoonstock), names mostly used for gaming-item trading [3]. Anastasia Tikhonova, Group-IB's global head of threat research, drew a narrow conclusion from the renames [2]. "That suggests an identity set up or reorganized around this incident. It does not tell us who controls it, how experienced they are or how access was gained, and we have no evidence on the entry route," she said [4].
The access on record is the ability to send a push message carrying an outside link to ASOS customers [2]. Tikhonova said that "being able to send a notification shows access to a customer-messaging channel, not possession of a customer database" [12]. The channel's administrator also says payment information is not affected, a point where attacker and company agree [9][8]. ASOS says its website and app are running normally [10].
That leaves the entry route as the question with operational value. Team Cymru's Will Thomas assessed the incident as likely a software-as-a-service platform compromise [16]. He listed four possible routes: a helpdesk socially engineered into a password reset, an API key in exposed website JavaScript, credentials reused from infostealer logs, or a flaw introduced by a vibe-coding developer. He said which one was used is "unclear right now" [17].
Thomas said FulcrumeSec, ExfilSquad, Scattered Spider and Lapsus$ have used those techniques against UK organizations over the last couple of years [18]. The overlap is in method. Group-IB's work does not show who controls the Xuanyewen account [4], so no crew is attached to this incident on the public evidence.
Tikhonova said attackers go after the platforms and integrations companies depend on "because one point of access reaches a long way," and that retailers are particularly exposed [13]. "The systems retailers use to talk to their customers, often run by third parties, carry as much trust as the data platform behind them and deserve the same monitoring," she said [14].
Arctic Wolf's Nick Dyer cited ASOS's roughly 17 million customers as the possible scale of a breach, while saying it is not known whether users were compromised [15].
What to watch
- Any sample or dump posted by the Xuanyewen account; Group-IB says it has seen none so far.
- ASOS naming the third-party notification platform involved and how access to it was obtained.
- Any attribution tying the Xuanyewen account, or its earlier JohnCZ and Moon Transfers identities, to a known data-extortion crew.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives45
- Confidence50
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Group-IB findings shared with Infosecurity show that the Telegram account linked to the alleged ASOS hack used to be a forum for gaming-item trading.
- [2]
Anastasia Tikhonova, global head of threat research at Group-IB, investigated the Telegram channel t.me/xuanyewengateway, which was included in a push notification sent to ASOS customers on October 6 claiming the company had been hacked via a Snowflake instance.
- [3]
The channel was created on October 6, and the Telegram account behind it, now 'Xuanyewen' (@xuanyegroup), previously carried other names largely in gaming-item trading, including JohnCZ (@JohnCzwartacki) and Moon Transfers (@NFTmoonstock).
- [4]
"That suggests an identity set up or reorganized around this incident. It does not tell us who controls it, how experienced they are or how access was gained, and we have no evidence on the entry route,"
- [5]
Tikhonova has not found any evidence to verify claims that the group has access to ASOS customer data: "We have seen no sample, dump or other evidence."
- [6]
ASOS confirmed it was investigating unauthorized activity "involving third-party platforms that we use to communicate with customers."
- [7]
ASOS said it took "immediate action to restrict access to the notification platforms" and is "working with our internal and external specialist advisers, as well as all relevant authorities."
- [8]
ASOS acknowledged that basic personal information including names and contact details may have been accessed, but investigators do not believe payment-card information or account passwords were impacted.
- [9]
The administrator of the Telegram channel linked in the notification also said payment information is not affected.
- [10]
ASOS confirmed its website and app are operating as normal and its operations are fully unaffected.
- [11]
ASOS did not mention Snowflake in any of its statements, and Snowflake told Infosecurity it has found "no compromise of the Snowflake platform."
- [12]
"being able to send a notification shows access to a customer-messaging channel, not possession of a customer database."
- [13]
Tikhonova said attackers target the platforms and integrations companies depend on "because one point of access reaches a long way" and that retailers are particularly vulnerable to such techniques.
- [14]
"The systems retailers use to talk to their customers, often run by third parties, carry as much trust as the data platform behind them and deserve the same monitoring,"
- [15]
Nick Dyer, RVP solutions engineering at Arctic Wolf, said ASOS has around 17 million customers globally, meaning the scale of the breach could be significant, while acknowledging it is not known whether users have been compromised.
ReportedInsufficientSource: Nick Dyer, Arctic Wolf2 sources— create a free account to open themView cited source - [16]
Will Thomas, senior threat intelligence advisor at Team Cymru, assessed that the incident likely points to some form of software-as-a-service platform compromise, an approach used in high-profile attacks on UK retailers in recent years.
- [17]
Thomas listed possible routes: a helpdesk socially engineered to trigger a password reset, an API key found in exposed JavaScript on the website, credentials reused from infostealer logs, or a vulnerability introduced by a vibe-coding developer, and said which applied is "unclear right now".
- [18]
Thomas said these techniques have been repeatedly used by data extortion groups such as FulcrumeSec, ExfilSquad, Scattered Spider and Lapsus$ against UK organizations over the last couple of years.
Sources
1 independent publisher whose own reporting we read for this story.
- infosecurity-magazine.comTelegram Account Behind ASOS Rogue Notification Tied to Gaming Trading
1 article · October 7, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Retail cybersecurityFollow
- SaaS supply chain securityFollow
- Data ExtortionFollow