Skip to main content

Morning Overview

ASOS says its breach began when an attacker posed as a trusted contact

ASOS has traced its breach to a single impersonation. In an update sent to customers on October 8, the British online fashion retailer said an unauthorized party “impersonated a trusted contact” to obtain an employee’s login credentials, then used those credentials to reach information held on certain third-party platforms the company uses.

The disclosure follows two days of confusion that began on October 6, when ASOS app users received a push notification announcing the retailer had been hacked. The retailer’s account is its first explanation of the mechanism, and it points at a person rather than a software flaw. Shares in ASOS fell sharply after the October 6 alert, by as much as 11% in one report and about 14% in another, which gave the explanation commercial weight beyond the security community.

The credential theft ASOS describes

According to BleepingComputer’s report on the customer update, ASOS said it locked down the affected platforms after the credentials were misused and opened an investigation with external experts, law enforcement and regulatory authorities. The wording describes social engineering: the attacker did not break a lock, it convinced someone to hand over the key by appearing to be someone the employee already dealt with.

The statement leaves large gaps. ASOS has not said who the impersonated contact was, which employee was targeted, or which third-party platforms were reached. It also has not said how many customers are affected, a figure BleepingComputer says it requested without receiving an answer.

Tom Exelby of Red Helix, quoted by Cyber Magazine, called the use of ASOS’s own app to deliver a ransom note a brazen escalation and tied the pattern to the 2024 Snowflake campaign, in which attackers used stolen credentials rather than exploiting the platform itself. Marie Wilcox of Binalyze described the message as psychological pressure meant to induce panic and push ASOS toward paying, and said the priority should be closing the gap that allowed a mass notification to go out. Those comments are analysis from outside the company, not findings, and ASOS has said only that its investigation continues and that it has added security measures.

The app notification that came first

The public episode started earlier. On Tuesday, October 6, push notifications began reaching ASOS app users carrying the words “ASOS HACKED” and claiming the sender had “fully compromised the Snowflake instance,” BleepingComputer reported at the time. The message told recipients to engage or the data would be leaked, and it linked to a Telegram channel run by a group calling itself Xuanye.

ASOS responded in the app by telling customers to ignore the alert and avoid the link. It confirmed a breach that day but has not confirmed the Snowflake claim, and Xuanye has offered no evidence of it. A later message from the group asserted that customer information had been stolen and kept, while earlier ones said payment information was not affected.

Security specialists quoted in the coverage read the delivery method as a clue. Jonathan Lee of TrendAI, cited by Cyber Magazine, noted that sending a push notification would typically require access beyond a cloud data platform, so the compromise could be wider than claimed. Dan Bird of Horizon3 made a similar point in IBTimes UK’s account: an app push normally comes from a system separate from Snowflake, so stolen credentials may have opened more than one door. That reading fits ASOS’s own description of credentials used across several third-party platforms, though ASOS has not linked the two events.

Names and contact details on ASOS’s exposure list

ASOS says the exposed information is full names, contact details and certain non-personal account-related information. It says payment card information and account passwords were not accessed, and that its website and app remain safe to use. The customer update states there is no action customers need to take on their accounts.

The residual risk is the contact list itself, and ASOS’s own caution about unexpected calls points straight at it. A name paired with an email address or phone number is enough to stage a convincing follow-up, and ASOS asked customers to stay cautious of unexpected messages or calls claiming to be from the retailer. It said it will never ask for passwords, security codes or payment details through an unsolicited message or call.

The UK National Cyber Security Centre’s phishing guidance gives the standard test for such contacts: verify any important request through a second channel, such as logging in directly or phoning a number found independently. The NCSC also says reports of suspected phishing should be made even after a link has been clicked, since fear of blame is what keeps people from reporting.

The ASOS case turns on that same human step, only on the employee side. The retailer’s statement says one employee’s credentials were enough, and it has not yet said whether a second check was in place when the trusted-contact request arrived.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview


Morning Overview is reader-supported. Some links in our articles are affiliate links, and we may earn a commission at no extra cost to you. As an Amazon Associate I earn from qualifying purchases. Full disclosure.