A Telegram account linked to the alleged ASOS hack was previously active in forums dedicated to trading gaming items, according to new findings from Group-IB shared with Infosecurity. Anastasia Tikhonova, the firm's global head of threat research, traced the channel t.me/xuanyewengateway—included in the strange push notification sent to ASOS shoppers on October 6, where an attacker claimed to have breached the retailer through a Snowflake instance. The channel was created the same day as the notification, and the Telegram account operating it, now called 'Xuanyewen,' had previously used other names tied largely to gaming-item commerce, including JohnCZ and Moon Transfers.
Tikhonova explained that the pattern "suggests an identity set up or reorganized around this incident," but noted it doesn't reveal who controls the account, their level of skill, or how entry was achieved, and no evidence has surfaced regarding the method of access. She also told Infosecurity she hasn't yet located any proof to back up the group's assertions that they hold ASOS customer information, stating, "We have seen no sample, dump or other evidence." ASOS confirmed it's investigating unauthorized activity involving third-party platforms used for customer communication, took immediate steps to restrict access to notification systems, and is working with internal and external advisers as well as authorities. The company acknowledged that basic personal details including names and contact information may have been accessed, but investigators don't believe payment-card data or account passwords were compromised, and the Telegram channel administrator also said payment information isn't affected.
According to Group-IB's Tikhonova, "being able to send a notification shows access to a customer-messaging channel, not possession of a customer database." Will Thomas, senior threat intelligence advisor at Team Cymru, assessed the incident likely points toward some form of software-as-a-service platform compromise, an approach used in high-profile attacks on UK retailers in recent years. He highlighted that techniques such as social engineering helpdesks to trigger password resets, discovering API keys in exposed JavaScript, reusing credentials from infostealer logs, or exploiting vulnerabilities introduced by developers have all been repeatedly leveraged by data extortion cybercriminals including FulcrumeSec, ExfilSquad, Scattered Spider, and Lapsus$ to target UK organizations over the past couple years, though it's unclear which method was used here.
Tikhonova stressed that attackers target the platforms and integrations companies depend on "because one point of access reaches a long way," and retailers are particularly vulnerable to such techniques. The systems retailers use to communicate with customers, often operated by third parties, carry as much trust as the data platform behind them and deserve the same monitoring, she noted. Nick Dyer, RVP solutions engineering for UK, Ireland and Benelux at Arctic Wolf, warned the compromised data could include customer, sales, order, marketing or operational datasets, potentially exposing clients to fraud, phishing or identity theft, and given ASOS has around 17 million customers globally, the scale could be significant. He advised customers to avoid clicking unexpected notifications or messages claiming to be from ASOS, be alert for urgent phone calls or texts from unknown numbers, go directly to the ASOS website instead, and change their passwords since the retailer may not have deployed multifactor authentication as standard. For enterprises managing sprawling ecosystems of third-party integrations, the incident highlights a structural tension between operational velocity and control surface—speed to market through external platforms comes bundled with trust assumptions that may no longer hold under adversarial pressure.

