Business strategy, corporate ownership, and operational authority behind the October 2026 breach.

Analysis based on public information available as of October 10, 2026.

Abstract

On October 6, 2026, customers of ASOS received an unauthorised push notification through the British fashion retailer’s official mobile application. The message claimed that attackers had compromised a Snowflake environment and threatened to expose customer information. Two days later, ASOS told customers that an unauthorised party had impersonated a trusted contact, obtained an employee’s login credentials, and used them to access information held on third-party platforms.

The incident exposed two different capabilities: access to customer information and the ability to speak to customers through an official ASOS channel. The public record does not show whether one application, an integration, or separate permissions connected them.

ASOS had deliberately made customer knowledge actionable. By April 2026, it reported a fourfold increase in personalised communications; product- and intent-triggered activity accounted for more than two-thirds of its CRM contribution. A contemporary CRM leadership role was designed to join communication strategy with responsibility for the platforms that delivered it.

This investigation reconstructs the passage from one commercial decision to several technical acts: selecting customers, determining what they see, and delivering a message under ASOS’s name. The October push makes that passage an incident question. ASOS reported credential-based access to customer information and confirmed an unauthorised notification, but has not identified which principals selected its recipients, supplied its words, or dispatched it.

1. Incident Overview

At approximately 10:00 a.m. UK time on October 6, 2026, ASOS customers received an unexpected notification through the retailer’s mobile application. The notification announced that ASOS had been hacked, claimed that its Snowflake environment had been compromised, and threatened to leak data. ITPro

The significance of the message was not merely the allegation it contained. It was delivered through a legitimate ASOS communication channel. Customers received the attacker’s statement through an application they already recognised as belonging to the retailer.

Later that day, ASOS published a regulatory announcement confirming that an unauthorised customer notification had been sent. The company said it was investigating unauthorised activity involving third-party platforms used to communicate with customers and had restricted access to the affected notification systems.

Its initial assessment indicated that basic customer information, including names and contact details, might have been accessed. Payment-card information and account passwords were not believed to be affected. ASOS reported that its website and application remained operational. 1

On October 8, ASOS told customers that an attacker had impersonated a trusted contact to obtain login credentials associated with an employee account. Those credentials were subsequently used to access information on third-party platforms. 2

The BBC also received a sample of data from the attackers. Its reporting described customer names, contact information, addresses, dates of birth, and search histories among the information reportedly exposed. The attackers claimed that Simon AI, a customer-data platform used by ASOS, had been involved. 2

The public evidence does not establish the complete intrusion sequence. ASOS has not identified the particular accounts or products through which the notification was created. The attackers’ claim concerning Snowflake does not independently demonstrate direct access to a Snowflake database. Their identification of Simon AI is an investigative lead rather than a verified reconstruction of the incident.

The two outcomes raise a question about authority in ASOS’s customer operation: which permissions allowed access to customer information, which allowed a message through the official app, and did those permissions intersect?

2. Timeline: The Formation of an Integrated Business

ASOS’s customer infrastructure developed alongside a series of organisational and commercial changes. The early examples concern different problems; the more direct evidence for a coordinated customer decision cycle appears in the 2025–26 CRM records.

DateDevelopment
2017ASOS researchers describe a production system for estimating customer lifetime value daily, demonstrating the established use of customer-level analytics in marketing decisions.
2021ASOS describes earlier difficulties aligning Azure resource provisioning with central financial responsibility, and the introduction of improved cost governance.
February 2024ASOS engineering describes a Backstage-based catalogue intended to identify services, components, dependencies, and ownership across a large decentralised engineering organisation.
October 2024ASOS completes the Topshop and Topman joint venture with Heartland, separating majority ownership of the brands from continuing ASOS commercial activities.
June 2025Simon AI publishes an ASOS interview describing unified customer profiles, behavioural segmentation, automated campaign activation, and personalised Web and app experiences.
September 2025ASOS creates an EVP Customer & Commercial role combining customer and commercial functions under one executive responsibility.
April 2026ASOS reports a fourfold increase in personalised communications and the substantial contribution of automated product-triggered CRM.
Spring 2026ASOS advertises a Head of CRM and Lifecycle Product role combining responsibility for communications, CRM execution, and the underlying platforms. The listing also refers to planned re-platforming and a new data platform.
July 2026Monetate acquires Simon AI, combining corporate ownership while retaining separately operated products.
October 6, 2026Attackers distribute an unauthorised notification through the ASOS app. ASOS confirms unauthorised activity involving external communication platforms.
October 8, 2026ASOS identifies employee credential theft through impersonation as an entry mechanism and acknowledges customer-data exposure.

The 2017 customer-lifetime-value system establishes an earlier use of customer analytics, but no source makes it a predecessor of Simon AI. The Azure cost and Backstage initiatives concerned financial governance and service ownership, respectively. They show the setting in which ASOS operated, not stages of one CRM programme.

The more direct history begins in 2025. An ASOS CRM lead described building customer segments in Simon with SQL and passing them to preconfigured Braze campaigns for rapid activation. ASOS then placed customer and commercial functions under one executive. 46 By April 2026, ASOS reported four times as many personalised communications, with product- and intent-led triggers making a substantial CRM contribution. Its CRM leadership vacancy assigned one role responsibility for both what the company communicated and the platforms used to do it. 57

Here “integration” has a specific object: a repeatable decision about the audience, message, and moment of contact. The published workflow also reveals its limit. A segment, a configured campaign, and a delivery credential can remain under different effective authorities even when the business treats their result as one ASOS communication.

3. What Integration Was Supposed to Achieve

ASOS was integrating a customer decision cycle: recognise behaviour, choose an audience and message, and deliver through its own channels. It wanted this cycle to be timely and accountable even though the data, teams, and platforms involved remained separate. The incident makes the authority behind each step worth examining; it does not establish that the attacker traversed the documented cycle.

3.1 A Customer Response That Could Keep Pace with Behaviour

The intended result was timely, relevant contact. ASOS wanted a customer’s browsing, purchases, preferences, and engagement to influence what the company showed or sent next.

Simon AI’s published ASOS materials describe unified customer profiles, behavioural segmentation, and activation through CRM, Web, app, and paid channels. A June 2025 interview identified Braze as a campaign destination. The commercial aim was to make customer information usable for timely action across channels. 34

ASOS’s April 2026 interim results show the commercial outcome the company sought. Personalised communications had increased fourfold. Intent-led triggers such as Back in Stock, Low in Stock, and Price Drop accounted for more than two-thirds of CRM contribution. ASOS also described its iOS app as its highest-value customer channel and reported that newly acquired app customers delivered nearly twice the lifetime value of newly acquired Web customers. 5

The tension was in the handoff from knowledge to action. A unified customer experience could involve one system identifying an audience, another deciding or storing a message, and an authorised channel delivering it. The customer saw ASOS throughout; the permissions behind each step could remain separate.

The October incident exposed the importance of that handoff. An attacker-authored push arrived through the official app, a channel ASOS had made central to customer engagement. The reported data access involved customer information of the kind this business model used, but the public record does not show that the same system, account, or integration produced both outcomes. The contradiction is between the intended continuity of ASOS’s customer voice and the unauthorised voice that the official channel carried.

3.2 One Accountable Process, Several Effective Operators

The intended result was coordinated responsibility for what ASOS said and how it delivered it. In September 2025, ASOS brought Customer, Global Commercial & Trading, ASOS Media Group, and Customer Care under an EVP Customer & Commercial. The stated aim was a coherent experience on and off the platform. 6

A 2026 Head of CRM and Lifecycle Product vacancy translated that aim into an operating plan. The advertised leader was accountable for both the content of customer communication and the means of delivering it: CRM strategy and execution, Braze as a product, and associated data and decisioning capabilities. The listing said ASOS did more through push than email and wanted rapid decisions without unnecessary escalation, even while planning CRM re-platforming and a new data platform. It joined automated lifecycle messages to trading requests that could require action within the week. This describes the intended operating model, not who held the role or what any employee could access in October. 7

A Topshop and Topman CRM Executive vacancy showed the work beneath that strategy: building and scheduling Braze campaigns, setting segments and exclusions, checking content and links, and quality-assuring targeting before a send. 9

The tension was that accountability and effective permission were different things. A manager could own a communication without holding its delivery credential. A CRM operator could select recipients without administering the customer-data platform. A machine credential could send a request prepared by a human in another system.

ASOS said an attacker obtained an employee’s credentials by impersonating a trusted contact and used them to access customer information on third-party platforms. That establishes an identity crossing into customer data. It does not identify the employee’s role, the affected application, or the permission that authored the push.

3.3 Commercial Continuity Across Corporate Boundaries

The intended result was to preserve commercial capability while ownership changed. In October 2024, Heartland obtained a 75% interest in the entity holding Topshop and Topman, while ASOS retained 25%. A later ASOS vacancy described a dedicated Topshop and Topman team within ASOS, supporting expansion through Topshop.com while using ASOS infrastructure and resources. 89

In July 2026, Monetate acquired Simon AI. It described a strategy connecting customer intelligence to digital experiences while saying the products would continue to operate separately with integrations between them. 10

The tension was that ownership, operational work, and tenant access were different relationships. The two transactions make the distinction concrete:

TransactionContinuing operationAuthority the ownership record cannot identify
Topshop and Topman joint ventureASOS retained an operating role and described work using its infrastructure after Heartland took the majority interestWhich user, campaign, or app permissions served either brand
Monetate’s acquisition of Simon AISimon and Monetate described connected customer journeys while retaining separate productsWho administered ASOS’s Simon environment or its connected Braze credentials

These are examples of business relationships crossing legal boundaries, not evidence that either transaction enabled the intrusion. Their relevance to the central question is narrower: knowing who owned a brand or product cannot tell us who could choose an audience, change a message, or cause its delivery. The attackers’ reference to Simon AI remains an investigative lead.

4. Reverse-Engineering the Architecture

The business history explains what ASOS wanted its customer operation to do. The published technical record shows which systems and interfaces could carry it out. It supports a reconstruction of documented functions, not a verified deployment diagram for October 6. The Simon–Braze relationship was described in 2025; ASOS’s 2026 recruitment materials still named Braze but also referred to CRM re-platforming and a new data platform. 47

4.1 The Customer-Data and Delivery Components

Simon’s ASOS case study says its platform combined data from ASOS systems and third-party vendors into customer profiles. A June 2025 interview describes two routes out of those profiles: ASOS’s CRM team could define audiences with SQL in Simon and pass them to preconfigured campaigns in Braze; Simon also connected directly to ASOS’s Web and app platforms for personalisation. These are related uses of customer information, but the direct Web and app connection is not itself a description of how a push notification was sent. 34

Component or connectionDocumented function
ASOS systems and third-party sourcesSupply customer information combined by Simon
Simon AICombine profiles, define segments and Flows, and activate audiences
Simon–Braze connectionSync profile or segment information and trigger configured campaigns through a REST API key
BrazeHold campaign configuration and execute messages through its configured channels
Simon–ASOS Web and app connectionUse customer information for direct on-site and in-app personalisation

The two outbound paths should not be collapsed. A direct connection for Web and app personalisation does not identify the service that authored or dispatched an app push. Nor does the published Simon–Braze connection establish that it was the route used in October 2026. 4

Architecture overview: ASOS and third-party customer data feed Simon AI profiles and segments. Simon connects to Braze campaign messaging and, separately, directly to ASOS Web and app personalisation. ASOS CRM responsibility spans the operation, while the October 2026 app-push path remains unknown.
Figure 1. The documented 2025 customer operation had two outbound routes: Simon-to-Braze campaign activation and direct Simon-to-ASOS Web/app personalisation. User, content, and API authority are separate. The diagram does not identify the service that sent the October 2026 push.

Open Figure 1 at full size.

Simon describes both managed deployments using its own Snowflake environment and connected deployments using a customer’s Snowflake environment. ASOS’s arrangement is not public. These product options do not confirm the attackers’ Snowflake claim or establish a direct path from ASOS’s internal data systems to Simon. 16

4.2 The Boundary Between a User and an API

Simon’s documented standard User role can create and edit segments, export membership, and create and launch Flows; custom roles can limit those actions. Its Braze integration uses a configured API key with permissions such as campaigns.trigger.send and canvas.trigger.send. A person who launches a Flow may therefore cause an action executed downstream under a machine credential. 1112

The point where a decision becomes an action requires specific authority:

ActionAuthority that would need to permit itWhat the public record establishes
Read or export customer informationApplication or data-store accessSimon documents customer profiles and export permissions; the source of the exposed ASOS records is unknown
Choose recipients and start a FlowCustomer-platform role, campaign configuration, or trigger requestSimon’s standard User role includes segment editing and Flow launch; Braze’s trigger API can also accept recipients or an audience; ASOS’s actual selection route is unknown
Trigger a configured campaignDownstream integration credentialSimon’s documented Braze connection uses a REST API key with campaign and Canvas trigger permissions
Determine the words displayedCampaign editor, permitted template input, or broader messaging APIThe route that produced the attacker’s text is unknown
Deliver through the appAuthorised messaging service and channel configurationASOS confirmed the unauthorised notification; it did not identify the sending principal

The business decision becomes an official message only when three authorities compose: who selects the recipients, who can determine the words they see, and whose credential dispatches the result. One person may be responsible for the whole decision without exercising every permission. Conversely, a user who starts a Flow can invoke a downstream integration credential without possessing it. The final ASOS sender identity tells the customer none of this.

The content boundary is particularly important. Braze’s campaign-trigger API normally holds message content in a preconfigured campaign and requires campaigns.trigger.send; its API-only messaging endpoint accepts content in the request and requires the separate messages.send scope. Simon’s standard Braze integration lists campaign-trigger permissions, not messages.send. Yet the trigger API also accepts trigger_properties, which a campaign template can render as part of its text. Trigger authority is therefore neither automatically content authority nor proof that content is fixed. 1213

A fixed-content campaign could be launched without changing its words. An attacker-authored message would require editing the campaign, control over values rendered by a suitable template, or a separate content-supplying interface. The published Simon integration guide does not establish that a Simon Flow could supply arbitrary trigger properties in ASOS’s environment. ASOS’s actual templates, payloads, and API scopes are not public.

Braze also documents campaign and Canvas approval workflows. They are not enabled by default, and Braze says campaign approval does not support its API campaign type. That product category should not be read as every campaign triggered through an API. The documentation identifies possible control boundaries, not the controls ASOS had configured. 14

4.3 Responsibility Is Not a Credential

ASOS’s 2025 annual report assigned ownership of its principal personal-data-loss risk to the EVP Commercial & Customer and described security and privacy oversight by the CISO and DPO. Those governance responsibilities do not identify any individual’s application permissions or service credentials. 15

A CRM employee could prepare a communication, a customer-data platform could select recipients, and an integration credential could cause a vendor to deliver it. Those steps have separate permissions and records even when they form one customer-facing action. The public record does not show which of them produced the October notification.

5. The Incident as a Test of the Integrated Operation

ASOS reported that stolen employee credentials were used to access customer information. Its official app also carried an attacker-authored push. These outcomes concern both ends of the decision cycle ASOS was building, but the public record does not join them into a single technical route. ASOS has not identified the account, product, campaign, API call, or approval step that produced the push. The attackers’ references to Simon AI and Snowflake cannot supply those missing links.

5.1 What the Push Required

The notification establishes two results: attacker-authored words reached customers, and a channel authorised to send through ASOS’s app delivered them. It does not show who chose the recipients, whether the audience had been set beforehand, or whether the reported customer-data access played any part in dispatch.

The missing transition is specific. Some principal had to supply or alter the meaning of the message before an authorised delivery path carried it. In the documented Simon–Braze model, a campaign trigger alone would explain when a configured message was sent and to whom; it would explain the attacker’s words only if the campaign content had been changed or a template rendered attacker-controlled values. A different messaging platform could combine those powers in one account. Neither is established as the October route.

Reported employee credential theft and customer-data access, and the observed app notification, with unresolved links through permissions and message authorship.
Figure 2. Credential theft and customer-data access were reported, and the app notification was observed. The affected products, effective roles, and route for authoring its text remain unknown. Dashed arrows are questions, not established incident connections.

5.2 Three Ways the Authorities Could Be Composed

These configurations differ in how recipient selection, content authority, and dispatch authority combine. The reported data access could occur in any of them; it does not identify the notification path.

ConfigurationWho could select recipientsWho could determine the wordsWhose authority could dispatch
One applicationA compromised account or an existing audience in one messaging productThe same account if its role allowed editing or API content submissionThat product’s authorised app channel
Delegated integrationA customer-platform user or a preconfigured campaign audienceA separate campaign editor, controlled template values, or another content interfaceA downstream API key triggering the configured campaign
Separate applicationsAn account or audience in a messaging product, regardless of where customer data was accessedAn account or API in that messaging productIts configured app delivery service

Consider one conditional route all the way through. If the stolen employee credential belonged to a Simon user with its documented standard User role, that user could inspect datasets, export segment membership, choose an audience, and launch a Flow. If the attacker also had permission in Braze to edit the content of a campaign configured for app push, they could put their words in that campaign. A Simon Flow connected to it could then use a configured Braze API key to trigger the campaign under a different technical identity, and Braze could deliver the words through the authorised app channel, provided no configured control blocked the change or send. This sequence composes data access, audience selection, content editing, delegated triggering, and delivery; it assumes several permissions beyond the stolen login reported by ASOS. Simon’s standard User role does not itself establish access to the particular records reported stolen or permission to edit Braze content. 111213

Without that content-editing step, merely triggering a fixed-content campaign cannot account for the attacker’s words. Other routes could supply text through a suitable dynamic template or a separate content-supplying interface such as Braze’s messages.send API. That API requires a permission distinct from the campaign-trigger scopes listed in Simon’s standard integration guide. 1213

Braze’s approval workflow is off by default, and campaign approval does not support its API campaign type. That does not establish whether the October message was an API campaign or what approval controls ASOS used. 14

To distinguish these routes, investigators would need the compromised identity’s effective permissions and authentication sessions, customer-data access logs, Flow history if relevant, campaign and template revisions, API-key scopes and request payloads, and the notification’s dispatch identifier. These records would show which principal selected the audience, which supplied the words, and which dispatched them. None has been released publicly.

5.3 What the Contradiction Reveals

ASOS intended to turn customer information and commercial decisions into timely communication under its own name. The 2025 interview described audience construction flowing into ready Braze campaigns; the 2026 role joined responsibility for communication and its platforms. The technical boundary remained divided among selecting recipients, determining content, and dispatching under a channel credential. The October push shows that unauthorised words crossed some such boundary into official delivery. It does not show that the documented Simon–Braze path was used or that the integration strategy caused the breach.

6. Conclusion

Integration did not simply connect ASOS’s systems. It converted distributed information, decisions, and execution into a customer-facing capability that could be exercised through delegated authority. ASOS wanted customer knowledge, audience choice, message content, and timing to operate as one fast commercial decision. Its published workflow put customer segments next to ready campaigns; its CRM plan put the message and its delivery platforms under one accountable role. In the systems that implemented such work, recipient selection, control of the words, and dispatch could still belong to different principals.

Customers saw one corporate sender. In the documented operating model, that result could depend on separate acts of audience selection, content control, and delegated dispatch; the sender identity alone cannot establish a single approval. The October incident does not prove that this distribution of authority caused the breach or identify the platform that sent the push. It gives the investigation a precise question: where did attacker-controlled words become an ASOS message eligible for delivery, and which identity or credential allowed that transition?


References

Incident disclosures and reporting

  1. ASOS plc — Update regarding cyber incident, October 6, 2026.
  2. BBC News — ASOS hackers took more personal details than first revealed, October 8, 2026; The Guardian — ASOS customer data accessed, October 8, 2026, quoting ASOS’s customer message.

Historical, financial, and operational records

  1. Simon AI — How ASOS generated $77.5 million in incremental revenue.
  2. Simon AI — How ASOS uses AI to personalise fashion for 20 million customers, June 2025.
  3. ASOS — Interim Results for the 26 Weeks to March 1, 2026, especially pages 7–8.
  4. ASOS — Appointment of Ben Blake as EVP Customer & Commercial, September 2025.
  5. ASOS — Head of CRM and Lifecycle Product, 2026 recruitment listing.

Corporate ownership and operations

  1. ASOS — Completion of Topshop and Topman Joint Venture, October 2024.
  2. ASOS — CRM Executive, Lifecycle & Campaign Operations, Topshop and Topman, 2026.
  3. Monetate — Acquisition of Simon AI, July 30, 2026.

Technical architecture, authority, and governance

  1. Simon AI — Manage Users and Access.
  2. Simon AI — Braze Integration.
  3. Braze — API-triggered Campaign Delivery, Trigger Properties Object, and API-only Messaging.
  4. Braze — Campaign and Canvas Approvals.
  5. ASOS — Annual Report and Accounts 2025, particularly the Principal Risks and Audit Committee sections.
  6. Simon AI — Data and Technology solutions, managed and connected deployments.