← All posts

The Hacker Didn't Need Your Firewall. They Needed a Phone Call From Someone You Trust.

On the morning of October 6, customers of the British fashion retailer ASOS opened their phones to an alert from the company's own app. It read, in part, "ASOS HACKED." The message was addressed to the company's data protection officer and IT team, claimed a cloud data environment had been compromised, and told ASOS to "engage with us, or we will leak it." It linked to a Telegram channel run by a previously unknown group calling itself Xuanye.

By midday, ASOS shares were down by double digits. Reports that morning put the intraday drop anywhere from roughly 11% to 14%. Two days later, the company explained how it happened. The explanation should worry every executive who has ever said, "We have good security."

What ASOS Says Happened

According to ASOS, an unauthorized party impersonated a trusted contact to obtain login credentials for an ASOS employee account. The attacker then used those credentials to reach third-party platforms the company uses to communicate with customers. Access to one of those platforms was enough to push a message to customers' phones under ASOS's own name.

ASOS says names and contact details, plus some non-personal account information, were exposed. It says it does not believe payment card details or account passwords were accessed. It has not said how many customers are affected, and its investigation is expected to run for several weeks.

The attackers made bigger claims. The group said it had compromised the company's Snowflake data environment, and told the BBC it had targeted an AI marketing service connected to it. Snowflake says the incident did not result from a vulnerability, weakness, or misconfiguration in its service. Those claims remain unverified, and ASOS has not confirmed them. Treat them as what they are: the assertions of an extortionist.

Nobody Hacked the Technology

Read the company's account again. It describes no zero-day, no unpatched server, no exotic malware. Someone was convinced to hand over a credential, and that credential opened doors at vendors the company relies on.

This is the pattern behind a large share of serious incidents, and it is the heart of the compliance-versus-security distinction in Cyber Risk Is Business Risk. A company can pass its audit, hold every certification, and still be undone by one convincing phone call, because the audit measured whether controls existed, not whether they held up against a persuasive stranger.

The second lesson is about where the damage landed. The attacker didn't break into ASOS's main systems in any way the company has described. They went through the side door: the third-party tools that sit between a company and its customers. Marketing platforms, messaging tools, and analytics services hold your customer list and, critically, your voice. A hijacked push notification is a trust problem before it is a data problem — delivered directly to every customer's lock screen.

The Market Doesn't Wait for the Investigation

Look at the timeline. The alert went out in the morning. The stock fell before ASOS had said anything publicly. Reporters were quoting "no immediate comment" while shares were sliding. Investors did not wait for a forensic report, and they never do.

This is the question the board must answer before an incident, not during one: Who speaks, what do we say, and how fast? If your first statement arrives after the market has already formed its own conclusion, you are no longer managing a breach. You are managing a narrative someone else wrote.

The Three Questions, Applied

The framework I use with boards asks three things: What are we protecting? What could realistically go wrong? What are we doing about it, and how do we know it's working?

Apply them here. A retailer's most valuable asset is customer trust, and the channel that carries it is the app. Did anyone on the ASOS board, or on yours, ask who can send a message through that channel, and what stands between a stolen employee login and that capability? The third question matters most. "We have multi-factor authentication" is an answer about a control. "We tested whether a convincing impersonator could talk an employee out of a credential, and here is what happened" is an answer about outcomes.

What to Ask Your CISO This Week

First: which third-party platforms can speak to our customers in our name? Email, text, push notifications, social accounts, support chat. Get a list. Most executives are surprised by its length.

Second: who can log in to those platforms, and how? Ask whether access requires phishing-resistant authentication, and whether one employee's stolen credential could be enough on its own.

Third: how do we verify identity when someone "from a trusted partner" asks for access? The attack here began with impersonation. Ask to see the procedure for an unexpected request, and whether staff are allowed to say no to someone who sounds senior.

Fourth: have we rehearsed the first hour? If a message went out under our brand tonight, who has the authority to shut the channel, who calls the lawyers, and who drafts the statement? If the answer involves finding a phone number, you have your finding.

Fifth: have we tested this with a live exercise? Not a policy review. A real attempt, authorized by you, to talk a real employee into a real mistake.

The Bottom Line

The uncomfortable truth in the ASOS account is how ordinary it is. A trusted voice, a stolen login, a vendor platform with too much reach. None of it requires a sophisticated adversary, which means none of it is rare.

Boards that treat cyber risk as business risk ask who can reach their customers and how that access is protected. Boards that treat it as an IT matter find out from a push notification.