Xuanye Group is a cybercriminal data-extortion actor associated with the October 2026 breach of British online fashion retailer ASOS. The group publicly claimed responsibility and used unauthorized push notifications delivered through the retailer’s own mobile application to threaten disclosure of customer data unless ASOS engaged with it. Customers in the United Kingdom, Ireland, and the United States received the notifications. The operation combined data-leak threats with direct customer-facing publicity to pressure the victim organization. The ASOS intrusion involved impersonating a trusted contact to obtain an employee’s legitimate login credentials, then using those credentials to access third-party platforms. Exposed information included customer names, contact details, and non-personal account-related information; ASOS stated that payment-card information and customer account passwords were not accessed. Xuanye Group used Telegram to communicate its demands. Its claims of compromising ASOS’s Snowflake environment through Simon AI were not independently confirmed, and Snowflake reported no breach of its own platform. No ransomware deployment was established. The group’s geographic origin, membership, and broader operational history remain unknown.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claims responsibility for stealing Asos customer data through Simon AI, a marketing platform connected to Asos' Snowflake instance. Asos confirmed a breach involving employee deception and stolen legitimate credentials used to access third-party platforms, but did not identify those platforms. The group threatened to leak stolen data and used Asos app notifications and Telegram to publicize its demands. Its additional SharePoint screenshot does not establish an Asos breach; displayed employee names suggest a possible Air France-KLM connection, which remains unconfirmed.
Claims responsibility for compromising British fashion retailer ASOS and obtaining customer data, including through an alleged attack on Simon AI integrated with Snowflake. ASOS confirmed employee-account compromise, unauthorized customer push notifications, and access to some personal and account information, but did not confirm data exfiltration or attribute the incident to Xuanye Group. Snowflake denied being breached. The group had published no customer-data samples to substantiate its claims.
Linked to the breach of UK fashion retailer Asos’ customer data in a third-party platform. The attackers allegedly compromised Asos’ Snowflake instance, stole customer personal information, and abused in-app notifications to pressure Asos into engaging under threat of publishing the data. The volume stolen and the method of accessing the notification system remain unknown.
Claimed responsibility for stealing customer data from UK fashion retailer ASOS and sent malicious in-app notifications urging staff to contact them on Telegram. ASOS confirmed that an attacker impersonated a trusted contact to steal an employee’s login credentials, then accessed information on third-party platforms. Exposed information included full names, contact details, and certain non-personal account-related information; payment card information and account passwords were not accessed. The article does not report independent confirmation of the attacker’s identity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.