Two days after its app sent an "ASOS HACKED" alert, ASOS said how it happened: an attacker impersonated a trusted contact, took an employee's login, and reached third-party platforms. I run AliasFleet, an email-alias service: one forwarding address per site, so a leak names its source. The hack itself is contained. What comes next is the impersonation wave, and it runs on your trust in the brand. That is the part worth understanding, because it is the part no company can contain for you.
What ASOS confirmed this time
This is the second disclosure, and it reads like a company that has spent 48 hours on forensics. On Thursday morning ASOS emailed customers with the findings, reported by Reuters and Channel News Asia, and carried in full by PA News Agency. The vector, in the company's own words: "We discovered that an unauthorised party gained access to an ASOS employee account by impersonating a trusted contact to obtain log in credentials. Those credentials were then used to access information on certain third-party platforms used by ASOS."
The honest split, updated:
| Confirmed | Still unconfirmed |
|---|---|
| The entry point was social engineering: one impersonated trusted contact, one employee login | Whether email addresses specifically are among the "contact details"; ASOS has not itemised them |
| The credentials were used to access third-party platforms ASOS uses, not ASOS's own core systems | Which third-party platforms were accessed |
| "Some personal information, including names and contact details" may have been accessed, plus certain non-personal account-related information | How many customers are affected; no victim count given |
| No payment card information and no account passwords were accessed | Whether the stolen data will be leaked, sold, or used; no secondary misuse confirmed |
| The affected platforms were locked down; the website and app were safe throughout and remain safe | The attacker's claim of a full Snowflake compromise; Snowflake says its platform shows no compromise |
| ASOS is working with law enforcement and regulators, and says it has strengthened its security controls | The attacker's claim, relayed via the BBC, of names, addresses, phone numbers, emails and customer numbers; attacker claims are not evidence |
For context on Tuesday's chaos, my piece from that day has the blow-by-blow. The short version: a push notification reading "ASOS HACKED" went out to app users at around 10am. It claimed a Snowflake breach and linked a Telegram channel. The Times reports around 16.4 million active customers: that is the pool of people this statement is aimed at, not a confirmed victim count.
The boring entry point is the point
There is a reason this disclosure is less dramatic than the first one and more important. Nobody smashed a database. Nobody exploited a zero-day. Somebody pretended to be someone an ASOS employee trusted, and the employee handed over a login. Social engineering is the entry point for a large share of major breaches, and it works for the same reason every time: the security model assumes the person holding the credentials is who they claim to be, and the attacker simply becomes that person for one conversation.
Note where the attacker went next. Not into ASOS's own systems, but into third-party platforms, the customer-communication tools sitting outside the company's direct control. Tuesday's hijacked push alert already suggested whoever did this could reach ASOS's communication layer, and now ASOS has confirmed the access went through third-party platforms. Your name and contact details did not leak from a vault. They leaked through the platforms ASOS has not named, and the notification hijack points at the customer-communication layer, which is the part of every company's stack with the widest access and the weakest scrutiny.
The warning you should pin
The most useful text in ASOS's email is not the forensic detail. It is the customer advisory, and it is worth quoting in full because it is also the script attackers will now copy:
"There is no action you need to take on your account. However, please remain cautious of unexpected messages or calls claiming to be from Asos. We will never ask you to share passwords, security codes or payment details through an unsolicited message or call."
Read that twice. The second sentence is the real instruction. In the coming weeks, "ASOS breach update" emails will land that quote the first sentence verbatim to sound legitimate, and then ask for exactly the things the third sentence says ASOS will never ask for. The advisory protects you only if you apply the third sentence to the messages that quote the first two.
Expect the next wave of phishing to impersonate this exact email, because attackers now hold the real advisory text, the real breach context, and your real name and contact details. A fake "ASOS security update" that quotes the company's own words will fool far more people than a generic scam. The only reliable test is behaviour. If the message asks for a password, a code, or payment details, it is hostile. ASOS never does.
What to do now
ASOS says there is no action you need to take on your account, and on the facts given that is fair: your password and your card details were not the things taken. The work is all on the impersonation side.
- Assume ASOS-branded messages are hostile by default. Breach updates, refund offers, password resets, delivery alerts: treat every one as suspicious until you verify it yourself. Open the app or type asos.com into your browser. Never follow a link in a message about this breach, even one that looks right.
- Use ASOS's own test. The company will never ask for passwords, security codes, or payment details through an unsolicited message or call. One request for any of those ends the conversation. Delete it.
- Do not touch the Telegram channel. The "ASOS HACKED" notification pointed at an attacker-run channel. ASOS told customers to disregard it entirely. Nothing posted there is a source of anything.
- Change your password if you reused it, because ASOS says passwords were not accessed but the contact details taken can be paired with passwords from any other breach you are in. If the ASOS password matches one you use elsewhere, that is the place to change it now: the reuse is the vulnerability ASOS cannot protect.
- Switch on two-factor authentication on your email and your banking. Leaked contact details are the raw material of account-recovery flows, and 2FA is the part the attacker cannot talk their way past.
- Check Have I Been Pwned once the incident is listed, and turn on its breach notifications so you hear about the next one without checking. The breach-response guide walks through the full order of operations.
Your ASOS address is still the receipt
The data that left is names and contact details. For an online retailer, the contact detail that matters is the email address you registered with, because that is where the impersonation wave lands. You cannot change your name. But the address you handed ASOS was a choice, and it is the one part of the file you can make expendable.
Here is what an ASOS-only alias changes. Every message arriving on it is either from ASOS or from the attacker, and there is no third option. A "security update" quoting the real advisory, carrying your real name, on an address no one but ASOS ever had: if it asks for a password, a code, or payment details, the sender has identified themselves as the impersonator. You do not need to inspect headers or hover links. The address does the sorting. Kill that alias and the whole impersonation channel dies while your real inbox stays clean. That is the leak-tracing mechanism aimed at exactly the attack this breach enables.
Retailers are the perfect case, because they hold the data that makes impersonation work: names, addresses, order history. Tuesday's notification hijack proved the point in the most literal way possible: the brand's own channel carried the attacker's message to its own customers. An alias does not stop the breach. It stops the breach from reaching you wearing the brand's face. If you have not used one before, this explains what an email alias is, and the set-up guide takes about two minutes. Undercodenews has the longer technical read on the notification hijack if you want the full breakdown.
What to watch next
Three things. First, the victim count and the data classes: "may have been accessed" is where every breach story starts, and the specifics will matter when they land. Second, whether the dataset surfaces publicly, which turns a contained intrusion into a circulating one. Third, the third-party platforms: ASOS has not named them, and other companies using the same tools will be quietly checking their own logs. The investigation continues. So does the phishing.
Top comments (0)