Skip to content
HackInvasionCybersecurity Knowledge Hub

Daily Cyber Threat Brief — October 7, 2026: ASOS Confirms Breach After "HACKED" Push Notifications; Advantest Ransomware Notices

🗂️ CASE FILE — October 7, 2026

Lead story: UK fashion retailer ASOS confirmed a data breach on Tuesday, October 6, after hackers sent "ASOS HACKED" push notifications through the retailer's official mobile app — addressed to the company's own DPO and IT staff — claiming to have fully compromised the Snowflake instance. The notifications, which began around 5:00 a.m. ET, directed the company to a Telegram channel run by a threat actor calling itself the "Xuanye group." ASOS confirmed third-party platforms used to communicate with customers were accessed without authorization and said basic personal information, including names and contact details, may have been exposed. The company has not confirmed the actor's Snowflake claim, has not disclosed how many customers are affected, and says it does not believe payment-card information or account passwords were impacted, per BleepingComputer.

Also covered: Advantest mails ransomware breach notices dated October 6 — eight months after detecting the February intrusion that took personal data including SSNs · ShinyHunters fallout: Dutch police confirm arrest of a 24-year-old Amsterdam man; FBI's Brett Leatherman says the group and conspirators breached 140+ organizations and extorted at least $70 million since last year · ransomware claims roundup (all Oct 6, unverified): Qilin lists financial-sector victim BNYH, EndZone claims Philander Smith University (500GB), Deadlock hits Italy's Greggio Argento (500GB), Incransom names magnals.com, Panzer posts EDFelectronics.

Sources: 6 linked at the end of this brief.

Today's top stories

Tuesday's biggest story wrote itself across thousands of phones: hackers hijacked ASOS's own push-notification channel to announce a breach — from inside the company's app — naming Snowflake as the claimed entry point. ASOS confirmed the intrusion into customer-communication platforms and possible exposure of names and contact details, while declining to validate the Snowflake claim. Elsewhere, Advantest finally mailed breach notices eight months after its February ransomware detection, the ShinyHunters investigation widened with new arrest details, and the leak sites added five fresh claims on October 6.

ASOS confirms breach after hackers send "ASOS HACKED" alerts through the official app

UK fashion retailer ASOS confirmed a data breach on Tuesday, October 6, after hackers sent unauthorized push notifications through its official mobile app while claiming to have stolen customer data from the company's Snowflake environment, BleepingComputer reported. The notifications began appearing at approximately 5:00 a.m. ET, with multiple readers contacting BleepingComputer after receiving them. The message was addressed pointedly to the company's own security team: "Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it."

The notification directed ASOS to a Telegram channel operated by a threat actor calling itself the "Xuanye group." In messages posted Tuesday morning, the group claimed the breach did not affect payment information — then later published a "FINAL STATEMENT" claiming customer information was stolen, without disclosing what data, how many customers were affected, or providing evidence of the claimed Snowflake compromise. BleepingComputer attempted to contact the actors, but the only contact point required payment — which the outlet declined on editorial grounds.

ASOS confirmed that third-party platforms used to communicate with customers were accessed without authorization and says basic personal information, including names and contact details, may have been exposed. The company is now showing an in-app notice telling customers to disregard the unauthorized alert and not click the external link it contained. What ASOS has not said is nearly as important: it has not confirmed the Snowflake claim, has not disclosed a customer count, and has not described the initial access vector into the third-party communication platforms. It says it does not believe payment-card information or account passwords were impacted.

🔍 Investigation notes — defender takeaway (click to expand)

This is a breach announcement delivered through the victim's own notification channel — the attackers understood ASOS's comms stack well enough to push a message to every app user, which is itself a strong indicator of deep access into customer-engagement platforms. Note the claimed vector: Snowflake, the same brand of environment at the center of the 2024 credential-stuffing waves. If the Snowflake claim holds, it likely traces back to credential hygiene on a data-warehouse account, not a Snowflake product flaw. For defenders: audit which third parties can send messages as you to customers (push providers, email vendors, SMS gateways), and treat any of those integrations as a reputation-risk control point — an attacker who reaches one can speak to your entire customer base in your voice.

Advantest mails ransomware breach notices eight months after February detection

Japanese chip-test-equipment maker Advantest — whose U.S. arm, Advantest America, is based in San Jose, California — began mailing notice letters dated October 6, 2026 to people affected by a ransomware attack the company detected in February 2026, Emery Reddy reported. According to its Notice of Data Breach letter, Advantest became aware in February 2026 that an unauthorized third party had accessed its systems and taken data from its servers; in a February 19, 2026 statement, the company said it detected unusual activity on February 15 and that the attacker may have deployed ransomware. The stolen data includes personal information — including Social Security numbers for some individuals — and the letter warns recipients of increased identity-theft and fraud risk.

The timeline shows a striking gap: nearly eight months between detection and individual notice. The California Attorney General listing gives an even earlier breach date of January 23, 2026, and filings with the California and Vermont Attorneys General were submitted on October 5, 2026. Advantest has not disclosed the total number of people affected; the Vermont filing lists 8 residents, while a California filing is required when more than 500 California residents are affected. The company says it has no information suggesting the data has been published or misused.

🔍 Investigation notes — defender takeaway (click to expand)

Eight months from detection to notice is the kind of timeline regulators and class-action firms read closely. The gap usually reflects long forensic scoping, but notification laws measure the clock from determination, not from convenience — and the AG filings landed the day before the letters. For defenders: document your scoping timeline defensibly, because it will be read by people whose job is to question it. Also note the company still says it has no evidence of publication or misuse — in ransomware cases that claim often ages poorly, so affected individuals should treat the eight-month exposure window as live fraud risk, not a closed file.

ShinyHunters fallout: Dutch arrest confirmed; FBI cites 140+ victims and $70M extorted

New details emerged in the investigation of ShinyHunters, the extortion group behind last month's claimed FBI breach. Dutch police confirmed the September 15 arrest of a 24-year-old Amsterdam man in the ShinyHunters investigation, SecurityWeek reported. Independent reporting by journalist Brian Krebs and DataBreaches identified the suspect as Pepijn van der Stap — a convicted 2023 hacker (alias "Umbreon") employed as offensive security lead at Neo Security at the time of his arrest; he is being held under a 90-day detention order. Notably, the FBI's defacement claim in the FBIjobs incident included an oversized Umbreon Pokémon image, and there is speculation that the group's current leadership may have pinned the hack on van der Stap amid an internal dispute — which the group denies.

Separately, FBI Cyber Division deputy director Brett Leatherman said ShinyHunters and associated conspirators have allegedly breached more than 140 organizations since last year and collected at least $70 million through extortion, frequently by targeting third-party vendors on cloud platforms, per Tallwire. Dutch investigators also say they found material on the suspect's seized laptop pointing to an alleged attempt to incite two murders abroad — a separate investigation unrelated to the hacking case.

🔍 Investigation notes — defender takeaway (click to expand)

The 140 organizations / $70 million figure is the official scale statement from the FBI, and the targeting pattern — third-party vendors on cloud platforms — is the defender-relevant part. ShinyHunters is not picking locks; it is walking through vendor and SaaS relationships at scale. The Snowflake-adjacent ASOS story above rhymes with this pattern: cloud data platforms and vendor comms integrations are the shared attack surface. For defenders: inventory the vendors that hold your customer data and the credentials that reach your cloud data stores, and monitor those relationships as first-class attack surface, not procurement line items.

Unverified claims desk: Qilin, EndZone, Deadlock, Incransom, Panzer post five claims on October 6

A crowded 24 hours on the leak sites, all filed as unverified threat-actor claims. The Qilin group listed BNYH (financial sector) on October 6, per ransomware.live-tracked disclosures aggregated by Cyber Threat Intelligence — a financial-services victim in a sector where regulatory and reputational costs amplify any breach. The EndZone group claimed an attack on Philander Smith University, a private historically Black university in Little Rock, Arkansas, claiming to have taken more than 500 gigabytes of student, staff, and financial data; the university has not publicly confirmed a breach, per classactionu.org. Deadlock listed Greggio Argento, a long-established Italian family business founded in 1948, with approximately 500 GB of data claimed, per hendryadrian.com (ransomware.live monitoring). Incransom listed magnals.com (US), per ransomware.live tracking, and the Panzer group listed EDFelectronics, a US manufacturer, per Cyber Threat Intelligence.

Disclosure dates reflect when victims appeared on leak sites, not when any compromise began. None of these claims has been independently confirmed, and victim counts and data volumes come from the actors' own postings.

🔍 Investigation notes — defender takeaway (click to expand)

Five claims in a day, three with data-volume assertions in the hundreds of gigabytes — all unverified, all from the actors' own marketing. The education-sector claim stands out: universities combine rich identity data with thin security budgets, and Philander Smith is the second HBCU-adjacent target this cycle is worth watching. For defenders: leak-site volume claims are leverage math until verified — but treat the appearance of a sector peer on a leak site as a prompt to re-verify your own backups, exfiltration detection, and incident-response contacts before you need them.

Incident timeline — October 6 to October 7, 2026

DateEventStatus
Oct 5Advantest files breach notifications with the California and Vermont Attorneys General; individual letters dated Oct 6Confirmed (AG filings)
Oct 6"ASOS HACKED" push notifications sent ~5:00 a.m. ET via the official app; ASOS confirms unauthorized access to customer-communication platforms, basic personal data possibly exposedConfirmed by company (BleepingComputer)
Oct 6Xuanye group claims via Telegram to have fully compromised ASOS's Snowflake instance; later posts "FINAL STATEMENT" claiming customer data stolen — no evidence providedUnverified claim
Oct 6Advantest breach notice letters dated; February detection to October notice = ~8 months; SSNs for some individuals; company cites no evidence of publication or misuseConfirmed (company letters)
Oct 6Dutch police confirm Sept 15 arrest of 24-year-old Amsterdam man in ShinyHunters probe; FBI's Leatherman cites 140+ victim organizations, $70M+ extorted since last yearConfirmed (police, FBI)
Oct 6Ransomware groups post new claims: Qilin/BNYH, EndZone/Philander Smith University, Deadlock/Greggio Argento, Incransom/magnals.com, Panzer/EDFelectronicsUnverified claims

Source links


EmoticonEmoticon