Xuanyewen is the name adopted by a cyber criminal group that claimed responsibility for a significant data breach at the UK-based online fashion retailer Asos in October 2026.
The Asos Data Breach
In late October 2026, Xuanyewen contacted BBC News to share samples of stolen customer data, revealing that the breach extended beyond basic contact details. The group stated they had accessed detailed profiles of potentially millions of users, including names, addresses, phone numbers, email addresses, customer numbers, dates of birth, and search histories.
The attackers initially made headlines when they used Asos’s own application system to send pop-up notifications to customers, claiming they had “compromised the Snowflake instance.” Snowflake is a data storage and analysis company; however, Snowflake subsequently stated that its core platform had not been breached. Instead, Asos explained that the hackers gained access by impersonating trusted contacts to obtain login credentials for an employee account.
Methods and Claims
Xuanyewen claimed to have utilized a platform called Simon AI, which is built natively on top of Snowflake, to facilitate the unauthorized access and download of customer data. Following their contact with media outlets, the group provided evidence of the scale of the theft, prompting Asos to issue warnings to customers about potential phishing scams and impersonation attempts using the stolen personal information.