ASOS investigates breach exposing customer data
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
ASOS customers may have had names and contact details accessed after an unauthorised push notification was sent, NCSC warns.
The UK's National Cyber Security Centre has issued guidance following a cyber incident affecting ASOS, the online fashion retailer. On Tuesday 6 October, some ASOS customers received an unauthorised push notification, prompting an investigation by the company. ASOS has confirmed that basic personal information - including customer names and contact details - may have been accessed by the unauthorised party, though the company states it does not believe payment card information or account passwords were compromised.
The NCSC advises that all ASOS customers should assume they are affected by this incident, even those who did not personally receive the unauthorised notification. This suggests the scope of the data access may extend beyond the subset of customers who received the push notification, indicating broader exposure of the customer database or contact information.
Defenders and affected individuals should be alert to follow-on phishing or smishing attempts, which often arrive some time after an initial data breach is disclosed, exploiting the leaked contact details. The NCSC recommends standard post-breach hygiene: avoiding suspicious links in notifications, emails, or messages purporting to be from ASOS, and strengthening account security using passkeys or strong, unique passwords combined with two-step verification, even though passwords are not believed to be affected in this instance.
Source reporting: https://www.ncsc.gov.uk/news/incident-affecting-asos-customers
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 10,850 reports from 149 sources, 467 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs