Decoding the world of cybersecurity

·

ASOS describes social engineering behind customer communications breach

ASOS has provided further information about an incident involving customer communications platforms, identifying credential theft through impersonation as the apparent entry method.

ASOS describes social engineering behind customer communications breach
Summary
  • An earlier Cyber Insider report covered the initial ASOS incident on 7 October.
  • New reporting describes social engineering involving an employee credential.
  • Customer passwords and payment details are not believed to have been involved.

British online retailer ASOS has provided new information about the intrusion behind an incident affecting customer communications platforms, describing an attacker who obtained an employee’s credentials through social engineering.

The clarification follows the company’s initial disclosure and Cyber Insider’s 7 October reporting about unauthorised activity involving third-party platforms. The earlier article established the incident and customer notifications, so a further report must focus on the newly explained intrusion method and any materially changed assessment of the affected information.

According to the company account reported by Reuters on 8 October, an attacker impersonated a trusted contact to induce an employee to disclose credentials. Social engineering exploits established working relationships or apparently legitimate requests rather than necessarily breaking the technical protections of an application itself.

Credentials obtained this way can allow a malicious actor to appear as an authorised user when accessing a service. The level of access then depends on the permissions assigned to the account and any additional authentication or contextual protections in place.

ASOS linked the unauthorised activity to customer information on third-party communications platforms. The incident therefore spans the retailer’s responsibility for customer data and the technical arrangements governing access to external services used for communications.

The company said customer passwords and payment card details were not believed to have been compromised. That qualification should remain prominent, since the nature of information used for customer communications differs from the credentials or payment records needed for other account functions.

Confirmation of a social engineering route does not establish that every employee or supplier account was affected. Nor does it demonstrate that the third-party service itself contained an exploitable software vulnerability; the disclosed entry point involved an individual’s credentials.

The remaining assessment concerns which customer records were accessed, which organisations held the relevant evidence and how the incident response will address access by accounts trusted across platform boundaries.

ASOS has not publicly established that the incident included customer account takeover or fraudulent payments. Any wider consequences will depend on further verified disclosures rather than inference from the attack method.

The latest account provides information that was absent from the initial notification incident. According to ASOS’s preliminary findings, someone impersonated a trusted contact and obtained an employee’s login credentials. Those credentials were subsequently used to access third-party systems involved in customer communications.

That sequence points to a compromised identity as the entry route, although the company has not publicly identified the person impersonated, the particular credential involved or the authentication configuration of every affected service. It also does not establish that any named cloud provider suffered a compromise of its own underlying platform.

Separating the attacker’s messages from confirmed findings has been important since customers received alarming notifications on 6 October. Claims distributed through a compromised communication channel can themselves exaggerate the extent of an intrusion. The investigation therefore has to establish both how the message was sent and what records the unauthorised user could access.

ASOS now says that names and contact details were among the information exposed, while account passwords and payment-card information are not believed to have been compromised. Those qualifications reflect the company’s current assessment, rather than a final independent forensic finding. The number of affected customers remains subject to confirmation.

Access to contact information can create a secondary threat even where financial credentials are unaffected. A fraudster who knows that a customer has received an authentic incident notice may tailor subsequent messages to resemble a follow-up from the retailer. There is no confirmed public finding that such follow-on attacks have occurred in this case.

The company says its website and app remained safe to use, and it is working with law enforcement and regulators. Further detail is needed about supplier access, notification scope and the final data inventory before a complete account of the incident can be established.

×