ASOS confirmed Thursday that its investigation found customer names and contact details had been accessed from a cybersecurity breach earlier this week. This differs from most hacks that I see as the threat actors used a trusted communication channel to communicate with the outside world. This takes away any doubt that they got in and ASOS got pwned.
More info here: https://www.reuters.com/business/retail-consumer/uks-asos-says-breach-exposed-some-customer-personal-data-2026-10-08/?utm_source=chatgpt.com
Danny Jenkins, CEO and Co-Founder of ThreatLocker, provided the following comments:
“Organizations must stop treating legitimate employee credentials as a trusted key to the kingdom. If an attacker can trick an employee into giving them valid credentials, the question isn’t whether that employee should have been more careful. It’s why those credentials alone are enough to compromise an entire organization. Zero Trust defenses are designed to add hardware verification to authorization checks. In this case, had a device needed to be verified, stolen credentials may have been useless to the attacker if they weren’t using them from an approved device.”
Jason Brown, Director of Customer Advisory, Counter Fraud Lead, iCOUNTER
“The ASOS breach started with one employee who was tricked into handing over their login by someone impersonating a trusted contact. From there, the attacker reached the third-party platforms ASOS uses to talk to its customers. That’s the part security teams should focus on. Every marketing, messaging and customer data platform a company connects to becomes another route to its customers, and in this case the attacker used ASOS’s own push notification channel to announce the breach directly to shoppers. The same access that sent a ‘HACKED’ message could just as easily have sent a convincing phishing message from a brand customers already trust, which is why anyone who received that notification should be on alert for follow-up scams. The attackers’ claim that they compromised ASOS’s Snowflake instance hasn’t been confirmed, and Snowflake says its platform wasn’t compromised. But the broader point holds. AI marketing tools are often given wide access to customer data so they can personalize campaigns, and that makes them valuable targets. Companies need an inventory of every third-party platform that holds or can reach their customer data, clear limits on what each one can access, and strong authentication on the employee accounts that manage them. Organizations that work with retailers like ASOS should also treat any data those partners hold on them as potentially exposed until they hear otherwise. Threat intelligence that watches for impersonation campaigns against your employees and partners, and for your vendors’ names showing up in breach claims, gives you a chance to act before an attacker uses your own channels against your customers.”
Well at least they knew how they got in. The real question is what are they going to do about it? Better training? Passwordless solutions? It all has to be on the table.
Related
This entry was posted on October 8, 2026 at 2:25 pm and is filed under Commentary with tags ASOS. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
ASOS Confirms That They Were Pwned
ASOS confirmed Thursday that its investigation found customer names and contact details had been accessed from a cybersecurity breach earlier this week. This differs from most hacks that I see as the threat actors used a trusted communication channel to communicate with the outside world. This takes away any doubt that they got in and ASOS got pwned.
More info here: https://www.reuters.com/business/retail-consumer/uks-asos-says-breach-exposed-some-customer-personal-data-2026-10-08/?utm_source=chatgpt.com
Danny Jenkins, CEO and Co-Founder of ThreatLocker, provided the following comments:
“Organizations must stop treating legitimate employee credentials as a trusted key to the kingdom. If an attacker can trick an employee into giving them valid credentials, the question isn’t whether that employee should have been more careful. It’s why those credentials alone are enough to compromise an entire organization. Zero Trust defenses are designed to add hardware verification to authorization checks. In this case, had a device needed to be verified, stolen credentials may have been useless to the attacker if they weren’t using them from an approved device.”
Jason Brown, Director of Customer Advisory, Counter Fraud Lead, iCOUNTER
“The ASOS breach started with one employee who was tricked into handing over their login by someone impersonating a trusted contact. From there, the attacker reached the third-party platforms ASOS uses to talk to its customers. That’s the part security teams should focus on. Every marketing, messaging and customer data platform a company connects to becomes another route to its customers, and in this case the attacker used ASOS’s own push notification channel to announce the breach directly to shoppers. The same access that sent a ‘HACKED’ message could just as easily have sent a convincing phishing message from a brand customers already trust, which is why anyone who received that notification should be on alert for follow-up scams. The attackers’ claim that they compromised ASOS’s Snowflake instance hasn’t been confirmed, and Snowflake says its platform wasn’t compromised. But the broader point holds. AI marketing tools are often given wide access to customer data so they can personalize campaigns, and that makes them valuable targets. Companies need an inventory of every third-party platform that holds or can reach their customer data, clear limits on what each one can access, and strong authentication on the employee accounts that manage them. Organizations that work with retailers like ASOS should also treat any data those partners hold on them as potentially exposed until they hear otherwise. Threat intelligence that watches for impersonation campaigns against your employees and partners, and for your vendors’ names showing up in breach claims, gives you a chance to act before an attacker uses your own channels against your customers.”
Well at least they knew how they got in. The real question is what are they going to do about it? Better training? Passwordless solutions? It all has to be on the table.
Share this:
Like this:
Related
This entry was posted on October 8, 2026 at 2:25 pm and is filed under Commentary with tags ASOS. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.