INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ASOS suffers data breach, hackers steal customer details and searches
| 2026-10-09 10:56 CRITICAL MEDIUM DATA BREACH
Executive Summary
AI-generated
On October 9, 2026, hackers stole customer details and shopping searches from ASOS, a global fashion retailer. The attackers accessed this information after tricking an employee into handing over login credentials, using the stolen login details to access third-party platforms used by ASOS. The exposed data includes names and home addresses, phone numbers and email addresses, customer numbers and dates of birth, as well as shopping-related information such as search terms and browsing history. This breach is categorized under a targeted phishing tactic, with no reported vulnerabilities in the Snowflake or Simon AI platforms used for customer personalization. ASOS has strengthened its security controls and will contact customers directly where necessary to provide further support or action; however, some experts have criticized the company's initial response as inadequate.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity.
• Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
NORDICS
NORDICS
FIVE_EYES
FIVE_EYES
financefinance
healthhealth
technologytechnology
retailretail
Incident Timeline
2026/10/09
Threat actors used social engineering to impersonate Astrana Health personnel and spoof the company's main corporate telephone number.
Click on any entity below to view its context and source!
organisation
Denmark’s Central Person Register
Related:
8.8 Million Impacted by Data Breach at Denmark’s Central Person Register
Related:
250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms
Related:
organisation
Texas Healthcare Firms
Related:
8.8 Million Impacted by Data Breach at Denmark’s Central Person Register
Related:
250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms
Related:
organisation
Data Breach
ASOS Confirms Cyberattack, Data Breach.
organisation
Pentagon Personnel Agency Data
Pentagon Personnel Agency Data Breach Impacts 3 Million People
Related:
DC Health Agency Exposes 400,000 Beneficiary Records
data_breach
400,000 Beneficiary Records
Pentagon Personnel Agency Data Breach Impacts 3 Million People
Related:
DC Health Agency Exposes 400,000 Beneficiary Records
organisation
ASOS
UK fashion retailer ASOS confirmed a data breach Tuesday aft....
UK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company's Snowflake environment.
ASOS breach update: Hackers stole customer details and shopping searches.
According to the BBC, which received a sample from the attackers, the exposed data includes:
Names and home addresses
Phone numbers and email addresses
Customer numbers and dates of birth
Searches customers made on the ASOS website
Details such as when a customer started using ASOS
The BBC reported search terms including “reclaimed vintage,” “glamorous wide fit,” and “Asos petite.”
organisation
Astrana Health Data Breach Impacts Private
Astrana Health Data Breach Impacts Private, Confidential Information.
organisation
Confidential Information
Astrana Health Data Breach Impacts Private, Confidential Information.
threat_actor
ShinyHunters
Related:
ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report
Related:
BigCommerce Data Stolen via Ribon Apps Hack
Related:
CrowdSec Confirms Source Code Stolen in Supply Chain Attack
Related:
280,000 Impacted by Premier Medical Group Data Breach
In 2024,
ShinyHunters
hacked Snowflake instances of over 160 organizations and stole sensitive data that was used for extortion.
organisation
BigCommerce
Related:
ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report
Related:
BigCommerce Data Stolen via Ribon Apps Hack
Related:
CrowdSec Confirms Source Code Stolen in Supply Chain Attack
Related:
280,000 Impacted by Premier Medical Group Data Breach
organisation
Premier Medical Group Data Breach
Related:
ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report
Related:
BigCommerce Data Stolen via Ribon Apps Hack
Related:
CrowdSec Confirms Source Code Stolen in Supply Chain Attack
Related:
280,000 Impacted by Premier Medical Group Data Breach
organisation
SEC
Astrana latest healthcare tech firm to report data breach to SEC.
The incident involved the company’s subsidiary Astrana Health Management, according to a
filing
with the US Securities and Exchange Commission (SEC).
organisation
Veradigm
Electronic health records company Veradigm recently
told
the SEC about a data breach involving Social Security numbers and healthcare firms like
Nutex
,
AnMed
,
Aesto
,
Baylor Genetics
,
CareCloud
,
Paylogix
and
Boston Scientific
have all reported cyberattacks over the last six months.
organisation
Social Security
Electronic health records company Veradigm recently
told
the SEC about a data breach involving Social Security numbers and healthcare firms like
Nutex
,
AnMed
,
Aesto
,
Baylor Genetics
,
CareCloud
,
Paylogix
and
Boston Scientific
have all reported cyberattacks over the last six months.
organisation
Boston Scientific
Electronic health records company Veradigm recently
told
the SEC about a data breach involving Social Security numbers and healthcare firms like
Nutex
,
AnMed
,
Aesto
,
Baylor Genetics
,
CareCloud
,
Paylogix
and
Boston Scientific
have all reported cyberattacks over the last six months.
organisation
BBC
While the retailer says payment card information and customer passwords were not accessed,
reporting by the BBC
shows the stolen information includes more than the “basic personal information” initially mentioned by the company.
organisation
Snowflake
The attackers’ original notification named Snowflake, a data storage and analysis platform.
“Dear ASOS DPO [data protection officer] and IT, we have fully compromised the Snowflake instance.
organisation
M&S
Security expert Kevin Beaumont criticized the response:
“ASOS are experiencing the exact same PR gaffs as Co-op and M&S by not being honest with customers.
organisation
Telegram
Don’t follow links in unexpected messages, and don’t follow the Telegram link in the attackers’ message or engage with them.
In response to ATB’s statement, the hackers published samples of the allegedly stolen data on their Telegram channel.
organisation
Malwarebytes Personal Data Remover
Malwarebytes Personal Data Remover finds them and gets your information removed, then keeps watch so it stays that way.
organisation
Astrana Health Management
The incident involved the company’s subsidiary Astrana Health Management, according to a
filing
with the US Securities and Exchange Commission (SEC).
organisation
the US Securities and Exchange Commission
The incident involved the company’s subsidiary Astrana Health Management, according to a
filing
with the US Securities and Exchange Commission (SEC).
victims
160 organizations
In 2024,
ShinyHunters
hacked Snowflake instances of over 160 organizations and stole sensitive data that was used for extortion.
organisation
ATB
Ukraine’s largest grocery store chain, ATB, confirmed Monday that it was hit by a cyberattack after hackers posted an extortion demand on its website.
organisation
SecurityWeek
The company did not name the threat actor behind the attack, and SecurityWeek has not seen any known ransomware or extortion group claiming responsibility for the incident.
organisation
the London Stock Exchange
In a Tuesday
filing
with the London Stock Exchange, the clothing and cosmetics retailer confirmed that its users received unauthorized notifications after a third-party platform used for customer communication was hacked.
organisation
Forescout Research
This recent hack may be similar, although it is not confirmed what the initial access was,” said Forescout Research – Vedere Labs VP of research Daniel dos Santos.
organisation
Xuanye Group
The incident was claimed by a hacking group calling itself Xuanye Group, on a newly created Telegram channel.
organisation
DataSuckers
The hacker group DataSuckers claimed responsibility for the attack and demanded $400,000, threatening to publish data it claimed to have stolen from millions of ATB customers.
financial
$400,000 attack
The hacker group DataSuckers claimed responsibility for the attack and demanded $400,000, threatening to publish data it claimed to have stolen from millions of ATB customers.
victims
7.9 customers
The group claimed to have obtained data belonging to 7.9 million customers, including names, phone numbers, email and physical addresses, password hashes, as well as employees’ passport information and records of more than 11 million orders.
organisation
Astrana Health
Astrana Health says private and confidential information was stolen from its servers after employees were targeted in a social engineering attack.
financial
$972.5 U.S.
Astrana is one of the largest healthcare tech companies in the U.S.,
reporting
$972.5 million in revenue last quarter through the sale of its operations technology platform to about 20,000 medical providers.
organisation
the Securities and Exchange Commission
The company
filed
a report with the Securities and Exchange Commission (SEC) on Tuesday evening about a recent incident in which hackers impersonated Astrana personnel and spoofed the company’s main corporate telephone number.
organisation
Company
“Based on the current status of the Company’s ongoing investigation, the Company believes that certain private and/or confidential information maintained on the Company’s servers has been accessed and/or acquired without authorization,” Astrana said.
early 2026
Threat actors successfully breached the data of ATB's 1,300 stores and employed more than 60,000 people.
Click on any entity below to view its context and source!
Tactical Metrics
Metrics
victims
160
Organizations
Click for context!
In 2024,
ShinyHunters
hacked Snowflake instances of over 160 organizations and stole sensitive data that was used for extortion.
Metrics
data_breach
400,000
Beneficiary Records
Pentagon Personnel Agency Data Breach Impacts 3 Million People
Related:
DC Health Agency Exposes 400,000 Beneficiary Records
Metrics
financial
400,000
Financial Impact / Stolen Funds
The hacker group DataSuckers claimed responsibility for the attack and demanded $400,000, threatening to publish data it claimed to have stolen from millions of ATB customers.
Metrics
victims
7,900,000
Customers
The group claimed to have obtained data belonging to 7.9 million customers, including names, phone numbers, email and physical addresses, password hashes, as well as employees’ passport information and records of more than 11 million orders.
Metrics
financial
972,500,000
U.S.
Astrana is one of the largest healthcare tech companies in the U.S.,
reporting
$972.5 million in revenue last quarter through the sale of its operations technology platform to about 20,000 medical providers.
Intelligence Sources
TheRecord
2026-09-24
SecurityWeek
2026-09-24
Malware Bytes
2026-10-09
TheRecord
2026-10-05
Mastodon BleepingComputer
2026-10-06
UK fashion retailer ASOS confirmed a data breach Tuesday aft...
Mastodon BleepingComputer
SecurityWeek
2026-10-07
ASOS Confirms Cyberattack, Data Breach
SecurityWeek
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-10T12:19
Comprehensive Tactical Telemetry
Highly Correlated Entities
29x
organisation
Identified Entity
ASOS
entity
6x
tactic
Cyber Operation Type
Phishing
tactic
6x
target region
Target Country
United Kingdom
country
5x
industry
Targeted Sector
Finance
sector
2x
timeline
Temporal Reference
2024
date
2x
general metric
People
3,000,000
people
Contextual Telemetry
Context Block
14 METRICS
general metric
Entities
8,800,000
entities
general metric
Related
250,000
related
threat actor
APT Group
ShinyHunters
actor
victims
Organizations
160
organizations
data breach
Beneficiary Records
400,000
beneficiary records
general metric
Restaurants
1,500
restaurants
general metric
Countries
28
countries
financial
Financial Impact / Stolen Funds
400,000
attack
general metric
Stores
1,300
stores
victims
Customers
7,900,000
customers
general metric
Orders
11,000,000
orders
general metric
Source Code Stolen
280,000
source code stolen
financial
U.S.
972,500,000
u.s.
general metric
Medical Providers
20,000
medical providers
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.