Home
Blog
ASOS hack: If you could message every customer, what would YOU tell them?

ASOS hack: If you could message every customer, what would YOU tell them?

Paul Ducklin
10/09/2026
Share this article:

What would you say?

What would you say to a company’s customers if you broke in and took control of an agentic AI used for sending targeted marketing messages intended to drum up online sales?

Would you use the AI to predict the product that customers are least likely to want, and spam them with mysterious ads insisting how much they need those items, perhaps to belittle and embarrass the company you just breached?

Would you advertise bizarre and non-existent products such as perpetual motion machines or self-laundering trousers in an attempt at showing you have an ironic sense of humor?

Well, the multi billion-dollar British fast-fashion company ASOS just found out what a cybergang calling itself xuan­yewen­gateway chose to do.

What happened?

Briefly explained, it looks as though the attackers broke into a massive ASOS marketing database full of customer data.

Although the database runs on a combination of the latest automation tools from Simon AI and Snowflake, the intrusion itself seems to have been achieved by the good old social engineering trick of persuading someone at ASOS, presumably in IT support, to reset access to a legitimate user’s account, but to give the new access credentials to the criminals instead.

In ASOS’s own words, the attackers succeeed by “impersonating a trusted contact to obtain [login] credentials.”

Intrusions of this sort can be hard to detect proactively, because the illegal access happens under the account of someone who’s supposed to be there.

Fortunately, it seems that the breached marketing tools didn’t have access to actual transaction and payment details, or to passwords and authentication data, or to identity-related verification information such as licenses or passports․․․

․․․but the database did include customers’ personal data such as names, home addresses, phone numbers, ASOS customer numbers, dates of birth, and search histories.

As you can probably imagine, by knowing who you are, where you live, how to contact you, your age, and what searches you’ve done for ASOS products, the company can use AI-based techniques to mine that data efficiently.

That means they can create marketing campaigns at scale that are nevetheless tightly tailored for each individual recipient.

Some people, of course, wouldn’t be happy to hand over this sort of marketing power to a fast-fashion retailer, but many would – and if you’re one of them, you may well have installed the ASOS app, and found the company’s offers useful.

In theory, there’s nothing wrong with that, as long the company collecting the data looks after it with the care you might expect (and with the care that they probably claimed they would take when you signed up for the service).

But if you were to give a cybercriminal access to an targeted marketing system of this sort, you can just imagine the sort of mass-messaging mayhem that might ensue:

  • Fake offers that are personalized and therefore look legitimate, but that lure you to unofficial sites.
  • Invitations to connect with official-sounding online accounts that are actually run by scammers, not by the company.
  • Suggestions to install an “add-on” app that turns out to be malware, for example by claiming you’ve been chosen as a preferred shopper and are eligible for additional offers.
  • Phishing tricks aimed at getting you to hand over passwords or further personal information.

Dear Data Protection Officer

This gang, it seems, took a different tack.

They used ASOS’s messaging system to tell the company’s own Data Protection Officer (DPO) and IT department about the intrusion – in a crushingly embarrassing way.

They spammed out exactly the same smug but disconcerting message to all (or at least very many of) the company’s customers:

   ASOS HACKED
   Dear Asos DPO and IT, we have 
   fully compromised the Snowflake 
   instance. Engage with us, or we 
   will leak it.

The message also linked to a Telegram account to make contact with xuanyewengateway.

What a way to get the attention of the company, its customers, and the media!

What to do?

  • If you’re an ASOS customer, be wary of anyone who approaches you claiming to be able to “help you” with the breach, because they’re likely to be scammers. Although the attackers apparently didn’t get away with much personally identifiable information (PII), they do now have enough customer detail to put up a good pretence of representing ASOS itself. And even if they’re not the original attackers, they may nevertheless play on your concerns and lure you into a secondary scam.
  • If you should ever get breached, provide a single source of information via an obvious link on your own website, and keep it up to date, so that your customers can easily find the latest information about the breach. This is a good way of insulating customers from the sort of follow-up scams mentioned above, because it means they don’t need to rely on messages from possibly untrusted sources. (ASOS hadn’t done this at the time of writing [2026-10-09T10:40Z].)
  • Listen to our Exploits versus Entropy podcast for entertainingly good-humored but actionable advice on how to improve your resilience against social engineering and other common attack techniques, without drowning in technology or buying “more tools, more tools.”
  • Remember that you don’t have to do it all yourself. Stay on top of cyberthreats without distracting staff from your core business. Sign up with SolCyber to do it for you, human style.

Listen to the TALES FROM THE SOC podcast:
Exploits versus Entropy

ASOS hack: If you could message every customer, what would YOU tell them? - SolCyber

If the media player above doesn’t work in your browser, try clicking here to listen in a new browser tab.

Why not ask how SolCyber can help you do cybersecurity in the most human-friendly way? Don’t get stuck behind an ever-expanding convoy of security tools that leave you at the whim of policies and procedures that are dictated by the tools, even though they don’t suit your IT team, your colleagues, or your customers!

ASOS hack: If you could message every customer, what would YOU tell them? - SolCyber


More About Duck

Paul Ducklin is a respected expert with more than 30 years of experience as a programmer, reverser, researcher and educator in the cybersecurity industry. Duck, as he is known, is also a globally respected writer, presenter and podcaster with an unmatched knack for explaining even the most complex technical issues in plain English. Read, learn, enjoy!


Paul Ducklin
Paul Ducklin
10/09/2026
Share this article:

Table of contents:

The world doesn’t need another traditional MSSP 
or MDR or XDR.

What it requires is practicality and reason.

Related articles

Choose identity-first managed security.

We start with identity and end with transparency — protecting where attacks begin and keeping you informed, with as much visibility as you want. No black boxes, just clear, expert-driven security.
No more paying for useless bells and whistles.
No more time wasted on endless security alerts.
No more juggling multiple technologies and contracts.

Follow us!

Subscribe

Join our newsletter to stay up to date on features and releases.

By subscribing you agree to our Privacy Policy and provide consent to receive updates from our company.

©
2026
SolCyber. All rights reserved
|
Made with
by
Jason Pittock

I am interested in
SolCyber DPM++

I am interested in
SolCyber XDR++™

I am interested in
SolCyber MDR++™

I am interested in
SolCyber Extended Coverage™

I am interested in
SolCyber Foundational Coverage™

I am interested in a
Free Demo

15145