Skip to content

Security1 publisherNot yet confirmed elsewhere2 min readPublished

Group-IB traces ASOS's rogue push alert to a renamed gaming-trade Telegram account

Group-IB found the Telegram channel in ASOS's October 6 rogue push alert was opened that day by an account once used for gaming-item trading. Until data surfaces, the Snowflake claim is unproven and the abused messaging platform is the lead to work.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying Group-IB traces ASOS's rogue push alert to a renamed gaming-trade Telegram account
Generated illustration

What happened

  • Snowflake told Infosecurity it found no compromise of its platform, and ASOS has not mentioned Snowflake in any of its statements.
  • ASOS says unauthorized activity involved third-party platforms it uses to message customers, and it has restricted access to those notification platforms.
  • ASOS says names and contact details may have been accessed but does not believe payment-card data or account passwords were affected.
  • Group-IB's Anastasia Tikhonova says she has seen no sample, dump or other evidence that the group holds ASOS customer data.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure The same notification access that delivered a Telegram link could deliver a phishing link under the ASOS name, and that attack needs no customer database.
  • constraint With Snowflake reporting no platform compromise and no data sample public, defenders get no Snowflake indicator to hunt for from this incident.
  • decision Retailers running third-party push and messaging tools have to decide whether those accounts get data-warehouse-level monitoring; Tikhonova argues they carry the same trust.
  • precedent If the entry route turns out to be a SaaS credential or exposed API key, ASOS fits the method Thomas ties to Scattered Spider and Lapsus$ attacks on UK organizations.

The account behind the channel now goes by Xuanyewen (@xuanyegroup). Group-IB found it previously ran as JohnCZ (@JohnCzwartacki) and Moon Transfers (@NFTmoonstock), names mostly used for gaming-item trading [3]. Anastasia Tikhonova, Group-IB's global head of threat research, drew a narrow conclusion from the renames [2]. "That suggests an identity set up or reorganized around this incident. It does not tell us who controls it, how experienced they are or how access was gained, and we have no evidence on the entry route," she said [4].

The access on record is the ability to send a push message carrying an outside link to ASOS customers [2]. Tikhonova said that "being able to send a notification shows access to a customer-messaging channel, not possession of a customer database" [12]. The channel's administrator also says payment information is not affected, a point where attacker and company agree [9][8]. ASOS says its website and app are running normally [10].

That leaves the entry route as the question with operational value. Team Cymru's Will Thomas assessed the incident as likely a software-as-a-service platform compromise [16]. He listed four possible routes: a helpdesk socially engineered into a password reset, an API key in exposed website JavaScript, credentials reused from infostealer logs, or a flaw introduced by a vibe-coding developer. He said which one was used is "unclear right now" [17].

Thomas said FulcrumeSec, ExfilSquad, Scattered Spider and Lapsus$ have used those techniques against UK organizations over the last couple of years [18]. The overlap is in method. Group-IB's work does not show who controls the Xuanyewen account [4], so no crew is attached to this incident on the public evidence.

Tikhonova said attackers go after the platforms and integrations companies depend on "because one point of access reaches a long way," and that retailers are particularly exposed [13]. "The systems retailers use to talk to their customers, often run by third parties, carry as much trust as the data platform behind them and deserve the same monitoring," she said [14].

Arctic Wolf's Nick Dyer cited ASOS's roughly 17 million customers as the possible scale of a breach, while saying it is not known whether users were compromised [15].

What to watch

  • Any sample or dump posted by the Xuanyewen account; Group-IB says it has seen none so far.
  • ASOS naming the third-party notification platform involved and how access to it was obtained.
  • Any attribution tying the Xuanyewen account, or its earlier JohnCZ and Moon Transfers identities, to a known data-extortion crew.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence55
Adoption
Insufficient
Hype gap+20
Incentives45
Confidence50
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Group-IB findings shared with Infosecurity show that the Telegram account linked to the alleged ASOS hack used to be a forum for gaming-item trading.

    ReportedSupportedSource: Group-IB via Infosecurity MagazineView cited source
  2. [2]

    Anastasia Tikhonova, global head of threat research at Group-IB, investigated the Telegram channel t.me/xuanyewengateway, which was included in a push notification sent to ASOS customers on October 6 claiming the company had been hacked via a Snowflake instance.

    ReportedSupportedSource: Infosecurity MagazineView cited source
  3. [3]

    The channel was created on October 6, and the Telegram account behind it, now 'Xuanyewen' (@xuanyegroup), previously carried other names largely in gaming-item trading, including JohnCZ (@JohnCzwartacki) and Moon Transfers (@NFTmoonstock).

    ReportedSupportedSource: Anastasia Tikhonova, Group-IBView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. infosecurity-magazine.com

    1 article · October 7, 2026

    Telegram Account Behind ASOS Rogue Notification Tied to Gaming Trading

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories