Skip to content
Asos Hackers Claim Breach of Snowflake-Connected Simon AI

Asos Hackers Claim Breach of Snowflake-Connected Simon AI

Bankinfosecurity • October 9, 2026

The threat actor who hacked fast-fashion retailer Asos claims to have breached a third-party artificial intelligence tool to steal its customer data.

See Also: Scattered Spider Exposed: Critical Takeaways for Cyber Defenders

The cybercriminals, calling themselves Xuanye Group, on Thursday claimed to the BBC to have breached Simon AI, a service integrated with cloud-based data warehousing platform Snowflake, allowing them to exfiltrate extensive amounts of customer data, although no payment card information.

On Tuesday, customers across Great Britain, Ireland, the United States and other countries reported seeing an "ASOS HACKED" pop-up notification from their Asos mobile app (see: Attackers Hijack Asos App to Say Store is Hacked ).

"We have fully compromised the Snowflake instance," the pop-up message read, demanding Asos "engage with us, or we will leak it." The message included a link to a Telegram channel for Xuanye Group with a further extortion demand.

Confirming the breach on Tuesday, London-based Asos told customers and investors that "basic personal information including name and details may have been accessed. We do not believe that payment-card information or account passwords were impacted." Asos said its app remains safe to use.

The criminals now claim to have obtained customer numbers, dates of birth and histories in addition to names, addresses, phone numbers and email addresses. "The criminals also have access to the searches customers have made on the website. Terms like 'reclaimed vintage', 'glamorous wide fit' and 'Asos petite' are visible in the data," the BBC reported.

Asos on Thursday said investigators found the breach traced to an attacker tricking an employee into believing they were a legitimate , allowing them to obtain legitimate access credentials. "Those credentials were then used to access information on certain third-party platforms used by Asos," it said, without specifying which platforms that involved.

One of the platforms appears to have been Simon AI, which Asos uses atop its Snowflake instance. Formerly known as Simon Data, Simon AI is owned by Dallas-based Monetate, which said the "composable AI agents" marketing tool is designed to add context to customers' buying decisions.

Snowflake offers a native version of the technology. "Built with Snowflake Cortex AI and powered by Claude from Anthropic, these composable AI agents - which run directly in Snowflake's AI Data Cloud - give marketers governed, real-time access to first-, second- and third-party structured and unstructured data," Snowflake said on its website.

An undated case study published on Monetate's Simon AI site details how the tool is being used by Asos' marketing department. "To increase shopper engagement and conversion, Simon enabled Asos to trigger push notifications in response to a shopper's activity in-app. Simon was also able to leverage livestream website and app data to trigger emails for shoppers who abandoned browsing, encouraging shoppers to return with personalized product recommendations while they were in the early consideration phase of their journey," it says .

Apparently attempting to add pressure on Asos to pay a ransom in return for a promise to delete their data, Xuanye Group on Thursday also posted to its Telegram channel a screenshot purportedly for a Microsoft SharePoint instance titled "Digital Commercial Cargo," showing a list of folders with such names as "CMD," "Sales API," "SalesForce," "Service API." The screenshot also shows multiple downloads, including an in-progress download of a 14.3 gigabyte file titled OneDrive_1_9-28-2026 (1).zip , suggesting a breach that dates to at least Sept. 28.

But nothing on that screenshot says "Asos." Also, while multiple names are listed in columns titled "modified by" and "created by." Multiple individuals with the displayed names do appear to be current or former Air France-KLM Group employees associated with its digital booking platform.

Security Alert: Simon AI Users

All Simon AI users should ensure they've activated multifactor authentication for their account, which isn't required by default, said British cybersecurity expert Kevin Beaumont in a post to social platform Mastodon.

Simon AI "connects directly into Snowflake but doesn't require MFA for accounts, has one common login portal and isn't enabled by default. The portal is all over infostealer logs," he said. "This was the route into Asos."

Montana-based Snowflake in 2024 made MFA mandatory for all new accounts, alongside complex passwords. The move followed cyberextortion group ShinyHunters popping 165 instances of customers that weren't using MFA, stealing data and holding it to ransom (see: Breach-Weary Snowflake Moves to MFA, 14-Character Passwords ).

Extracted Entities