ASOS Confirms That They Were Pwned

ASOS confirmed Thursday that its investigation found customer names and contact details had been accessed from a cybersecurity breach earlier this week. This differs from most hacks that I see as the threat actors used a trusted communication channel to communicate with the outside world. This takes away any doubt that they got in and ASOS got pwned.

More info here: https://www.reuters.com/business/retail-consumer/uks-asos-says-breach-exposed-some-customer-personal-data-2026-10-08/?utm_source=chatgpt.com

Danny Jenkins, CEO and Co-Founder of ThreatLocker, provided the following comments:

“Organizations must stop treating legitimate employee credentials as a trusted key to the kingdom. If an attacker can trick an employee into giving them valid credentials, the question isn’t whether that employee should have been more careful. It’s why those credentials alone are enough to compromise an entire organization. Zero Trust defenses are designed to add hardware verification to authorization checks. In this case, had a device needed to be verified, stolen credentials may have been useless to the attacker if they weren’t using them from an approved device.”

Jason Brown, Director of Customer Advisory, Counter Fraud Lead, iCOUNTER

“The ASOS breach started with one employee who was tricked into handing over their login by someone impersonating a trusted contact. From there, the attacker reached the third-party platforms ASOS uses to talk to its customers. That’s the part security teams should focus on. Every marketing, messaging and customer data platform a company connects to becomes another route to its customers, and in this case the attacker used ASOS’s own push notification channel to announce the breach directly to shoppers. The same access that sent a ‘HACKED’ message could just as easily have sent a convincing phishing message from a brand customers already trust, which is why anyone who received that notification should be on alert for follow-up scams. The attackers’ claim that they compromised ASOS’s Snowflake instance hasn’t been confirmed, and Snowflake says its platform wasn’t compromised. But the broader point holds. AI marketing tools are often given wide access to customer data so they can personalize campaigns, and that makes them valuable targets. Companies need an inventory of every third-party platform that holds or can reach their customer data, clear limits on what each one can access, and strong authentication on the employee accounts that manage them. Organizations that work with retailers like ASOS should also treat any data those partners hold on them as potentially exposed until they hear otherwise. Threat intelligence that watches for impersonation campaigns against your employees and partners, and for your vendors’ names showing up in breach claims, gives you a chance to act before an attacker uses your own channels against your customers.”

Well at least they knew how they got in. The real question is what are they going to do about it? Better training? Passwordless solutions? It all has to be on the table.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading