Tendvane

← All articles

SecurityOctober 8, 2026

ASOS says the break-in started with one employee and a convincing contact

On Tuesday morning ASOS customers got a push notification from the shop's own app addressed to its data protection officer and demanding engagement. The obvious question was how anyone got far enough inside to send it. ASOS has now answered.

"We discovered that an unauthorised party gained access to an ASOS employee account by impersonating a trusted contact to obtain log in credentials," the company's notice says. Those credentials opened the third-party platforms ASOS uses to talk to customers. Full names, contact details and some non-personal account information may have been exposed; payment card details and account passwords were not. ASOS says there is no action customers need to take on their account, and to treat unsolicited messages claiming to come from the company with suspicion. Worth noting that the attackers' own message had claimed a fully compromised Snowflake instance, which is not the picture ASOS describes.

There was no clever exploit here. No unpatched server, no zero-day. Somebody was convincing on a phone call or in a chat window, and that was enough to reach millions of customers. This is now the ordinary shape of a breach, and it is the reason the dull advice keeps getting repeated: when a message asks you to confirm something, go back through a route you chose yourself rather than the one you were handed.

For your own accounts, the thing that blunts a stolen password is a second step on the sign-ins that matter. Tendvane's privacy and accounts check will show you which of the ones on your PC still have nothing behind them but a password.

Sources

Download Tendvane