Telegram Account Behind ASOS Rogue Notification Tied to Gaming Trading

Written by

New findings from Group-IB, shared with Infosecurity, show that the Telegram account linked to the alleged ASOS hack used to be active in a forum for gaming-item trading.

Anastasia Tikhonova, global head of threat research at Group-IB, investigated the Telegram channel t.me/xuanyewengateway, included in the bizarre push notification sent to ASOS customers on October 6 where a threat actor claimed to have hacked the company via a Snowflake instance.

She has found that the channel was brand new – created on October 6 – and that the Telegram account behind it, now ‘Xuanyewen’ (@@xuanyegroup), previously carried other names, largely in gaming-item trading.

These include JohnCZ (@JohnCzwartacki) and Moon Transfers (@NFTmoonstock).

Activity of the ‘Xuanyewen’ Telegram account on September 7, 2026. Source: Group-IB
Activity of the ‘Xuanyewen’ Telegram account on September 7, 2026. Source: Group-IB

“That suggests an identity set up or reorganized around this incident. It does not tell us who controls it, how experienced they are or how access was gained, and we have no evidence on the entry route,” Tikhonova explained.

She also told Infosecurity she has not yet found any evidence to verify the claims that the group has access to ASOS customer data. “We have seen no sample, dump or other evidence,” she said.

Tikhonova emphasized that, at this stage, it is important to separate what has been confirmed, what has likely happened and what remains unproven claims.

ASOS Incident: Confirmed Facts and Unverified Claims

ASOS’ first communication regarding the hacker claims confirmed the firm was investigating unauthorized activity "involving third-party platforms that we use to communicate with customers."

The company said it took "immediate action to restrict access to the notification platforms" and is "working with our internal and external specialist advisers, as well as all relevant authorities."

The company also acknowledged that basic personal information including names and contact details may have been accessed by the threat actor, but the investigators do not believe payment-card information or account passwords were impacted.

The administrator of the Telegram channel linked in the notification also said that payment information is not affected.

Additionally, ASOS confirmed that its website and app are operating as normal, and that the company's operations are fully unaffected.

However, the fashion retailer did not mention Snowflake in any of its statements and the cloud service firm told Infosecurity it has found “no compromise of the Snowflake platform.”

Group-IB’s Tikhonova noted that “being able to send a notification shows access to a customer-messaging channel, not possession of a customer database.”

UK Retailers Face Rising SaaS and Data Extortion Threats

Will Thomas, senior threat intelligence advisor at Team Cymru, assessed that this incident likely points in the direction of some form of a software-as-a-service (SaaS) platform compromise, an approach that has been used in high-profile attacks on UK retailers over recent years.

“Whether the helpdesk was socially engineered to trigger a password reset, an API key was found in some exposed JavaScript on the website, a credentials were reused from infostealer logs or another vulnerability was introduced by a vibe-coding developer, it’s unclear right now,” he cautioned.

He highlighted that all of these techniques have been repeatedly leveraged by other data extortion cybercriminals, such as FulcrumeSec, ExfilSquad, Scattered Spider, and Lapsus$, to target UK organizations over the last couple years.

“This attack on ASOS is yet another reminder of the persistent threat of data extortion campaigns to UK organizations,” he added.

Tikhonova also stressed that attackers target the platforms and integrations companies depend on, “because one point of access reaches a long way” and retailers are particularly vulnerable to such techniques.

“The systems retailers use to talk to their customers, often run by third parties, carry as much trust as the data platform behind them and deserve the same monitoring,” she noted.

What ASOS Customers Should Do to Mitigate the Threat

Nick Dyer, RVP solutions engineering for UK, Ireland and Benelux at Arctic Wolf, warned that the compromised data could include customer, sales, order, marketing or operational datasets, potentially exposing clients to fraud, phishing or identity theft.

“While we don’t know how if users have been compromised, ASOS has around 17 million customers globally, meaning the scale of this breach could be significant,” he added.

He advised ASOS customers to “be vigilant, but not to panic and shared some basic measures to mitigate the threat:

  • Do not click or interact with any unexpected notifications, emails or messages claiming to be from ASOS, particularly if they ask you to click a link or provide personal information
  • Be on the lookout for phone calls or text communications from unknown numbers trying to instil urgency. Instead, go directly to the ASOS website
  • Change your password given that ASOS, like many retailers, may not have deployed multifactor authentication (MFA) as a standard for your login

The UK’s National Cyber Security Centre (NCSC) has also shared advice for ASOS customers. These are similar Dyer’s recommendations, but the agency also shared its Stop! Think Fraud guidance on how to report fraud in the UK, as well as top tips for staying secure online.

Image credits: Casimiro PT / photo_gonzo / Shutterstock.com

What’s Hot on Infosecurity Magazine?