ASOS Attack: Cyber Extortion Is Becoming a Public Pressure Campaign

For those not in the know. ASOS is a company that makes high performance cycling clothing. The pro team EF Education use their gear. And I own a number of their items myself. And they have been pwned. But it’s different There has been a major shift in cyber extortion because of this attack: Attackers are bypassing private negotiations and going directly to customers, using trusted channels to create immediate public and market pressure.

More details here: ASOS app users receive notifications from hackers in apparent breach

Gina Cardelli, Director, Product Management at Fortra, shares what this attack means for organizations:

“The ASOS incident is still developing, but what is fact is that the attackers have demonstrated access to a trusted ASOS communication channel by sending a push notification directly to customers. If the Snowflake claim is legitimate, the potential impact could be significant. The standard dataset could apply like names, email address, billing/shipping addresses, but with the age of AI, retailers are also increasingly centralizing their customers behavioral, transactional, and demographic information to build better customer profiles. These profiles can provide attackers with material needed for highly convincing phishing, social engineering, account takeover, etc. 

This attack also reflects a shift in extortion tactics, to tell ASOS’s customers about the breach before the company does. The attackers bypassed the normal private negotiation between victim and attacker and brought customers, media, and investors to the table to watch. ASOS stocks dropped 13% after the push notification hit their customer base. Even if the attacker doesn’t have the data, they were able to create market pressure on ASOS with a single push notification. 

What I would watch for over the next 24 – 48 hours:

  1. A Formal statement from ASOS to confirm what has been compromised and the depth and breadth of the compromise
  2. A response from Snowflake, to understand if its isolated to the tenant or a Snowflake platform vulnerability 
  3. The attackers publishing sample records”

While there are a lot of hacks out there, given that this is a cycling clothing manufacturer, I will be watching this with interest in order to see what happens next.

UPDATE: Borja Rodriguez, Head of Threat Intelligence, Outpost24 has this to say:

“We found logins for 118 ASOS work email accounts in places where stolen passwords are shared online. For 22 of them, the password was recently stolen by malware, including staff sign-in and VPN logins. Exposure is not proof of involvement, but leaked logins like these are exactly what attackers look for.”

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading