Asos user’s personal information may have been accessed

77 Views

Asos have shared that personal information may have been accessed in the apparent hack. The detail that matters here is the delivery channel. If the attackers pushed a message to customers through ASOS’s own app, they were operating from inside a trusted system. We don’t yet know whether that came from a compromised account, a stolen credential or token, or something else, and ASOS hasn’t confirmed the attackers’ claim. But it fits a pattern we’ve seen for years: attackers log in with access that looks legitimate rather than break in.

ASOS says payment and password data wasn’t affected. Names and contact details still matter, because they’re what make a phishing email or text convincing. Customers should expect ASOS-themed scams that arrive with real context, and be especially careful if they use the same email address elsewhere.

For other retailers, the question to ask today is whether they’d notice if a vendor integration, service account or API token started behaving differently. Most organisations can tell you who has access. Far fewer can tell you what normal looks like for that access, and that’s the difference between catching this kind of intrusion early and finding out from your customers.