Asos Data Breach – Attackers Have What They Need To Make A Scam Cedible

66 Views

Whatever the final scale, it’s now confirmed that attackers have what they need to make a scam credible: verified names, addresses, phone numbers, emails and customer numbers. A message that quotes a real customer number and refers to something the person recently searched for won’t look like phishing. It will look like the personalised marketing retailers send every week.

The breaching of search data worries me most. It’s behavioural, and it can say things about a person they never chose to share, which makes it useful for tailored lures and for pressure.

Customers should treat any unexpected ASOS email or text, especially about a refund, delivery or account problem, with suspicion, and go to the app or website directly rather than clicking a link. With phone numbers involved, expect texts and calls as well as email.

For other retailers, the lesson is that the data attackers want isn’t only payment details. The question is whether you’d notice data leaving, or a vendor integration or service account behaving differently before it does.