Business strategy, corporate ownership, and operational authority behind the October 2026 breach.
Analysis based on public information available as of October 10, 2026.
Abstract
On October 6, 2026, customers of ASOS received an unauthorised push notification through the British fashion retailer’s official mobile application. The message claimed that attackers had compromised a Snowflake environment and threatened to expose customer information. Two days later, ASOS told customers that an unauthorised party had impersonated a trusted contact, obtained an employee’s login credentials, and used them to access information held on third-party platforms.
The incident exposed two different capabilities: access to customer information and the ability to speak to customers through an official ASOS channel. The public record does not show whether one application, an integration, or separate permissions connected them.
ASOS had deliberately made customer knowledge actionable. By April 2026, it reported a fourfold increase in personalised communications; product- and intent-triggered activity accounted for more than two-thirds of its CRM contribution. A contemporary CRM leadership role was designed to join communication strategy with responsibility for the platforms that delivered it.
This investigation reconstructs the passage from one commercial decision to several technical acts: selecting customers, determining what they see, and delivering a message under ASOS’s name. The October push makes that passage an incident question. ASOS reported credential-based access to customer information and confirmed an unauthorised notification, but has not identified which principals selected its recipients, supplied its words, or dispatched it.
1. Incident Overview
At approximately 10:00 a.m. UK time on October 6, 2026, ASOS customers received an unexpected notification through the retailer’s mobile application. The notification announced that ASOS had been hacked, claimed that its Snowflake environment had been compromised, and threatened to leak data. ITPro
The significance of the message was not merely the allegation it contained. It was delivered through a legitimate ASOS communication channel. Customers received the attacker’s statement through an application they already recognised as belonging to the retailer.
Later that day, ASOS published a regulatory announcement confirming that an unauthorised customer notification had been sent. The company said it was investigating unauthorised activity involving third-party platforms used to communicate with customers and had restricted access to the affected notification systems.
Its initial assessment indicated that basic customer information, including names and contact details, might have been accessed. Payment-card information and account passwords were not believed to be affected. ASOS reported that its website and application remained operational. 1
On October 8, ASOS told customers that an attacker had impersonated a trusted contact to obtain login credentials associated with an employee account. Those credentials were subsequently used to access information on third-party platforms. 2
The BBC also received a sample of data from the attackers. Its reporting described customer names, contact information, addresses, dates of birth, and search histories among the information reportedly exposed. The attackers claimed that Simon AI, a customer-data platform used by ASOS, had been involved. 2
The public evidence does not establish the complete intrusion sequence. ASOS has not identified the particular accounts or products through which the notification was created. The attackers’ claim concerning Snowflake does not independently demonstrate direct access to a Snowflake database. Their identification of Simon AI is an investigative lead rather than a verified reconstruction of the incident.
The two outcomes raise a question about authority in ASOS’s customer operation: which permissions allowed access to customer information, which allowed a message through the official app, and did those permissions intersect?
2. Timeline: The Formation of an Integrated Business
ASOS’s customer infrastructure developed alongside a series of organisational and commercial changes. The early examples concern different problems; the more direct evidence for a coordinated customer decision cycle appears in the 2025–26 CRM records.
| Date | Development |
|---|---|
| 2017 | ASOS researchers describe a production system for estimating customer lifetime value daily, demonstrating the established use of customer-level analytics in marketing decisions. |
| 2021 | ASOS describes earlier difficulties aligning Azure resource provisioning with central financial responsibility, and the introduction of improved cost governance. |
| February 2024 | ASOS engineering describes a Backstage-based catalogue intended to identify services, components, dependencies, and ownership across a large decentralised engineering organisation. |
| October 2024 | ASOS completes the Topshop and Topman joint venture with Heartland, separating majority ownership of the brands from continuing ASOS commercial activities. |
| June 2025 | Simon AI publishes an ASOS interview describing unified customer profiles, behavioural segmentation, automated campaign activation, and personalised Web and app experiences. |
| September 2025 | ASOS creates an EVP Customer & Commercial role combining customer and commercial functions under one executive responsibility. |
| April 2026 | ASOS reports a fourfold increase in personalised communications and the substantial contribution of automated product-triggered CRM. |
| Spring 2026 | ASOS advertises a Head of CRM and Lifecycle Product role combining responsibility for communications, CRM execution, and the underlying platforms. The listing also refers to planned re-platforming and a new data platform. |
| July 2026 | Monetate acquires Simon AI, combining corporate ownership while retaining separately operated products. |
| October 6, 2026 | Attackers distribute an unauthorised notification through the ASOS app. ASOS confirms unauthorised activity involving external communication platforms. |
| October 8, 2026 | ASOS identifies employee credential theft through impersonation as an entry mechanism and acknowledges customer-data exposure. |
The 2017 customer-lifetime-value system establishes an earlier use of customer analytics, but no source makes it a predecessor of Simon AI. The Azure cost and Backstage initiatives concerned financial governance and service ownership, respectively. They show the setting in which ASOS operated, not stages of one CRM programme.
The more direct history begins in 2025. An ASOS CRM lead described building customer segments in Simon with SQL and passing them to preconfigured Braze campaigns for rapid activation. ASOS then placed customer and commercial functions under one executive. 46 By April 2026, ASOS reported four times as many personalised communications, with product- and intent-led triggers making a substantial CRM contribution. Its CRM leadership vacancy assigned one role responsibility for both what the company communicated and the platforms used to do it. 57
Here “integration” has a specific object: a repeatable decision about the audience, message, and moment of contact. The published workflow also reveals its limit. A segment, a configured campaign, and a delivery credential can remain under different effective authorities even when the business treats their result as one ASOS communication.
3. What Integration Was Supposed to Achieve
ASOS was integrating a customer decision cycle: recognise behaviour, choose an audience and message, and deliver through its own channels. It wanted this cycle to be timely and accountable even though the data, teams, and platforms involved remained separate. The incident makes the authority behind each step worth examining; it does not establish that the attacker traversed the documented cycle.
3.1 A Customer Response That Could Keep Pace with Behaviour
The intended result was timely, relevant contact. ASOS wanted a customer’s browsing, purchases, preferences, and engagement to influence what the company showed or sent next.
Simon AI’s published ASOS materials describe unified customer profiles, behavioural segmentation, and activation through CRM, Web, app, and paid channels. A June 2025 interview identified Braze as a campaign destination. The commercial aim was to make customer information usable for timely action across channels. 34
ASOS’s April 2026 interim results show the commercial outcome the company sought. Personalised communications had increased fourfold. Intent-led triggers such as Back in Stock, Low in Stock, and Price Drop accounted for more than two-thirds of CRM contribution. ASOS also described its iOS app as its highest-value customer channel and reported that newly acquired app customers delivered nearly twice the lifetime value of newly acquired Web customers. 5
The tension was in the handoff from knowledge to action. A unified customer experience could involve one system identifying an audience, another deciding or storing a message, and an authorised channel delivering it. The customer saw ASOS throughout; the permissions behind each step could remain separate.
The October incident exposed the importance of that handoff. An attacker-authored push arrived through the official app, a channel ASOS had made central to customer engagement. The reported data access involved customer information of the kind this business model used, but the public record does not show that the same system, account, or integration produced both outcomes. The contradiction is between the intended continuity of ASOS’s customer voice and the unauthorised voice that the official channel carried.
3.2 One Accountable Process, Several Effective Operators
The intended result was coordinated responsibility for what ASOS said and how it delivered it. In September 2025, ASOS brought Customer, Global Commercial & Trading, ASOS Media Group, and Customer Care under an EVP Customer & Commercial. The stated aim was a coherent experience on and off the platform. 6
A 2026 Head of CRM and Lifecycle Product vacancy translated that aim into an operating plan. The advertised leader was accountable for both the content of customer communication and the means of delivering it: CRM strategy and execution, Braze as a product, and associated data and decisioning capabilities. The listing said ASOS did more through push than email and wanted rapid decisions without unnecessary escalation, even while planning CRM re-platforming and a new data platform. It joined automated lifecycle messages to trading requests that could require action within the week. This describes the intended operating model, not who held the role or what any employee could access in October. 7
A Topshop and Topman CRM Executive vacancy showed the work beneath that strategy: building and scheduling Braze campaigns, setting segments and exclusions, checking content and links, and quality-assuring targeting before a send. 9
The tension was that accountability and effective permission were different things. A manager could own a communication without holding its delivery credential. A CRM operator could select recipients without administering the customer-data platform. A machine credential could send a request prepared by a human in another system.
ASOS said an attacker obtained an employee’s credentials by impersonating a trusted contact and used them to access customer information on third-party platforms. That establishes an identity crossing into customer data. It does not identify the employee’s role, the affected application, or the permission that authored the push.
3.3 Commercial Continuity Across Corporate Boundaries
The intended result was to preserve commercial capability while ownership changed. In October 2024, Heartland obtained a 75% interest in the entity holding Topshop and Topman, while ASOS retained 25%. A later ASOS vacancy described a dedicated Topshop and Topman team within ASOS, supporting expansion through Topshop.com while using ASOS infrastructure and resources. 89
In July 2026, Monetate acquired Simon AI. It described a strategy connecting customer intelligence to digital experiences while saying the products would continue to operate separately with integrations between them. 10
The tension was that ownership, operational work, and tenant access were different relationships. The two transactions make the distinction concrete:
| Transaction | Continuing operation | Authority the ownership record cannot identify |
|---|---|---|
| Topshop and Topman joint venture | ASOS retained an operating role and described work using its infrastructure after Heartland took the majority interest | Which user, campaign, or app permissions served either brand |
| Monetate’s acquisition of Simon AI | Simon and Monetate described connected customer journeys while retaining separate products | Who administered ASOS’s Simon environment or its connected Braze credentials |
These are examples of business relationships crossing legal boundaries, not evidence that either transaction enabled the intrusion. Their relevance to the central question is narrower: knowing who owned a brand or product cannot tell us who could choose an audience, change a message, or cause its delivery. The attackers’ reference to Simon AI remains an investigative lead.
4. Reverse-Engineering the Architecture
The business history explains what ASOS wanted its customer operation to do. The published technical record shows which systems and interfaces could carry it out. It supports a reconstruction of documented functions, not a verified deployment diagram for October 6. The Simon–Braze relationship was described in 2025; ASOS’s 2026 recruitment materials still named Braze but also referred to CRM re-platforming and a new data platform. 47
4.1 The Customer-Data and Delivery Components
Simon’s ASOS case study says its platform combined data from ASOS systems and third-party vendors into customer profiles. A June 2025 interview describes two routes out of those profiles: ASOS’s CRM team could define audiences with SQL in Simon and pass them to preconfigured campaigns in Braze; Simon also connected directly to ASOS’s Web and app platforms for personalisation. These are related uses of customer information, but the direct Web and app connection is not itself a description of how a push notification was sent. 34
| Component or connection | Documented function |
|---|---|
| ASOS systems and third-party sources | Supply customer information combined by Simon |
| Simon AI | Combine profiles, define segments and Flows, and activate audiences |
| Simon–Braze connection | Sync profile or segment information and trigger configured campaigns through a REST API key |
| Braze | Hold campaign configuration and execute messages through its configured channels |
| Simon–ASOS Web and app connection | Use customer information for direct on-site and in-app personalisation |
The two outbound paths should not be collapsed. A direct connection for Web and app personalisation does not identify the service that authored or dispatched an app push. Nor does the published Simon–Braze connection establish that it was the route used in October 2026. 4
Simon describes both managed deployments using its own Snowflake environment and connected deployments using a customer’s Snowflake environment. ASOS’s arrangement is not public. These product options do not confirm the attackers’ Snowflake claim or establish a direct path from ASOS’s internal data systems to Simon. 16
4.2 The Boundary Between a User and an API
Simon’s documented standard User role can create and edit segments, export membership, and create and launch Flows; custom roles can limit those actions. Its Braze integration uses a configured API key with permissions such as campaigns.trigger.send and canvas.trigger.send. A person who launches a Flow may therefore cause an action executed downstream under a machine credential. 1112
The point where a decision becomes an action requires specific authority:
| Action | Authority that would need to permit it | What the public record establishes |
|---|---|---|
| Read or export customer information | Application or data-store access | Simon documents customer profiles and export permissions; the source of the exposed ASOS records is unknown |
| Choose recipients and start a Flow | Customer-platform role, campaign configuration, or trigger request | Simon’s standard User role includes segment editing and Flow launch; Braze’s trigger API can also accept recipients or an audience; ASOS’s actual selection route is unknown |
| Trigger a configured campaign | Downstream integration credential | Simon’s documented Braze connection uses a REST API key with campaign and Canvas trigger permissions |
| Determine the words displayed | Campaign editor, permitted template input, or broader messaging API | The route that produced the attacker’s text is unknown |
| Deliver through the app | Authorised messaging service and channel configuration | ASOS confirmed the unauthorised notification; it did not identify the sending principal |
The business decision becomes an official message only when three authorities compose: who selects the recipients, who can determine the words they see, and whose credential dispatches the result. One person may be responsible for the whole decision without exercising every permission. Conversely, a user who starts a Flow can invoke a downstream integration credential without possessing it. The final ASOS sender identity tells the customer none of this.
The content boundary is particularly important. Braze’s campaign-trigger API normally holds message content in a preconfigured campaign and requires campaigns.trigger.send; its API-only messaging endpoint accepts content in the request and requires the separate messages.send scope. Simon’s standard Braze integration lists campaign-trigger permissions, not messages.send. Yet the trigger API also accepts trigger_properties, which a campaign template can render as part of its text. Trigger authority is therefore neither automatically content authority nor proof that content is fixed. 1213
A fixed-content campaign could be launched without changing its words. An attacker-authored message would require editing the campaign, control over values rendered by a suitable template, or a separate content-supplying interface. The published Simon integration guide does not establish that a Simon Flow could supply arbitrary trigger properties in ASOS’s environment. ASOS’s actual templates, payloads, and API scopes are not public.
Braze also documents campaign and Canvas approval workflows. They are not enabled by default, and Braze says campaign approval does not support its API campaign type. That product category should not be read as every campaign triggered through an API. The documentation identifies possible control boundaries, not the controls ASOS had configured. 14
4.3 Responsibility Is Not a Credential
ASOS’s 2025 annual report assigned ownership of its principal personal-data-loss risk to the EVP Commercial & Customer and described security and privacy oversight by the CISO and DPO. Those governance responsibilities do not identify any individual’s application permissions or service credentials. 15
A CRM employee could prepare a communication, a customer-data platform could select recipients, and an integration credential could cause a vendor to deliver it. Those steps have separate permissions and records even when they form one customer-facing action. The public record does not show which of them produced the October notification.
5. The Incident as a Test of the Integrated Operation
ASOS reported that stolen employee credentials were used to access customer information. Its official app also carried an attacker-authored push. These outcomes concern both ends of the decision cycle ASOS was building, but the public record does not join them into a single technical route. ASOS has not identified the account, product, campaign, API call, or approval step that produced the push. The attackers’ references to Simon AI and Snowflake cannot supply those missing links.
5.1 What the Push Required
The notification establishes two results: attacker-authored words reached customers, and a channel authorised to send through ASOS’s app delivered them. It does not show who chose the recipients, whether the audience had been set beforehand, or whether the reported customer-data access played any part in dispatch.
The missing transition is specific. Some principal had to supply or alter the meaning of the message before an authorised delivery path carried it. In the documented Simon–Braze model, a campaign trigger alone would explain when a configured message was sent and to whom; it would explain the attacker’s words only if the campaign content had been changed or a template rendered attacker-controlled values. A different messaging platform could combine those powers in one account. Neither is established as the October route.
5.2 Three Ways the Authorities Could Be Composed
These configurations differ in how recipient selection, content authority, and dispatch authority combine. The reported data access could occur in any of them; it does not identify the notification path.
| Configuration | Who could select recipients | Who could determine the words | Whose authority could dispatch |
|---|---|---|---|
| One application | A compromised account or an existing audience in one messaging product | The same account if its role allowed editing or API content submission | That product’s authorised app channel |
| Delegated integration | A customer-platform user or a preconfigured campaign audience | A separate campaign editor, controlled template values, or another content interface | A downstream API key triggering the configured campaign |
| Separate applications | An account or audience in a messaging product, regardless of where customer data was accessed | An account or API in that messaging product | Its configured app delivery service |
Consider one conditional route all the way through. If the stolen employee credential belonged to a Simon user with its documented standard User role, that user could inspect datasets, export segment membership, choose an audience, and launch a Flow. If the attacker also had permission in Braze to edit the content of a campaign configured for app push, they could put their words in that campaign. A Simon Flow connected to it could then use a configured Braze API key to trigger the campaign under a different technical identity, and Braze could deliver the words through the authorised app channel, provided no configured control blocked the change or send. This sequence composes data access, audience selection, content editing, delegated triggering, and delivery; it assumes several permissions beyond the stolen login reported by ASOS. Simon’s standard User role does not itself establish access to the particular records reported stolen or permission to edit Braze content. 111213
Without that content-editing step, merely triggering a fixed-content campaign cannot account for the attacker’s words. Other routes could supply text through a suitable dynamic template or a separate content-supplying interface such as Braze’s messages.send API. That API requires a permission distinct from the campaign-trigger scopes listed in Simon’s standard integration guide. 1213
Braze’s approval workflow is off by default, and campaign approval does not support its API campaign type. That does not establish whether the October message was an API campaign or what approval controls ASOS used. 14
To distinguish these routes, investigators would need the compromised identity’s effective permissions and authentication sessions, customer-data access logs, Flow history if relevant, campaign and template revisions, API-key scopes and request payloads, and the notification’s dispatch identifier. These records would show which principal selected the audience, which supplied the words, and which dispatched them. None has been released publicly.
5.3 What the Contradiction Reveals
ASOS intended to turn customer information and commercial decisions into timely communication under its own name. The 2025 interview described audience construction flowing into ready Braze campaigns; the 2026 role joined responsibility for communication and its platforms. The technical boundary remained divided among selecting recipients, determining content, and dispatching under a channel credential. The October push shows that unauthorised words crossed some such boundary into official delivery. It does not show that the documented Simon–Braze path was used or that the integration strategy caused the breach.
6. Conclusion
Integration did not simply connect ASOS’s systems. It converted distributed information, decisions, and execution into a customer-facing capability that could be exercised through delegated authority. ASOS wanted customer knowledge, audience choice, message content, and timing to operate as one fast commercial decision. Its published workflow put customer segments next to ready campaigns; its CRM plan put the message and its delivery platforms under one accountable role. In the systems that implemented such work, recipient selection, control of the words, and dispatch could still belong to different principals.
Customers saw one corporate sender. In the documented operating model, that result could depend on separate acts of audience selection, content control, and delegated dispatch; the sender identity alone cannot establish a single approval. The October incident does not prove that this distribution of authority caused the breach or identify the platform that sent the push. It gives the investigation a precise question: where did attacker-controlled words become an ASOS message eligible for delivery, and which identity or credential allowed that transition?
References
Incident disclosures and reporting
- ASOS plc — Update regarding cyber incident, October 6, 2026.
- BBC News — ASOS hackers took more personal details than first revealed, October 8, 2026; The Guardian — ASOS customer data accessed, October 8, 2026, quoting ASOS’s customer message.
Historical, financial, and operational records
- Simon AI — How ASOS generated $77.5 million in incremental revenue.
- Simon AI — How ASOS uses AI to personalise fashion for 20 million customers, June 2025.
- ASOS — Interim Results for the 26 Weeks to March 1, 2026, especially pages 7–8.
- ASOS — Appointment of Ben Blake as EVP Customer & Commercial, September 2025.
- ASOS — Head of CRM and Lifecycle Product, 2026 recruitment listing.
Corporate ownership and operations
- ASOS — Completion of Topshop and Topman Joint Venture, October 2024.
- ASOS — CRM Executive, Lifecycle & Campaign Operations, Topshop and Topman, 2026.
- Monetate — Acquisition of Simon AI, July 30, 2026.
Technical architecture, authority, and governance
- Simon AI — Manage Users and Access.
- Simon AI — Braze Integration.
- Braze — API-triggered Campaign Delivery, Trigger Properties Object, and API-only Messaging.
- Braze — Campaign and Canvas Approvals.
- ASOS — Annual Report and Accounts 2025, particularly the Principal Risks and Audit Committee sections.
- Simon AI — Data and Technology solutions, managed and connected deployments.