One borrowed login turned the ASOS app into the ransom note
Somewhere in your business there is a service that can message every customer you have. It might be the email marketing tool, the text message service, the app notification platform, or the customer database behind all three. Somebody on your team logs in to it most days.
Ask two questions about that service. What would a stranger be able to do with that colleague's login? And how hard would it be to talk them out of it?
ASOS has spent this week finding out.
What happened
On Tuesday 6 October, at about 10am, people with the ASOS app got a notification on their phones headed "ASOS HACKED". The BBC reported the text: "Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it." It was a ransom demand addressed to the company's data protection officer and delivered to its customers. The Record reported that ASOS shares fell more than 10% that day.
ASOS confirmed the notification was unauthorised and said it was investigating activity on "third-party platforms that we use to communicate with customers". At that point it said only that "basic personal information including name and contact details may have been accessed".
Two days later the picture changed. Criminals sent the BBC a sample of the data, and the BBC found it went well beyond basic contact details: names, addresses, phone numbers, emails, customer numbers, dates of birth, and the searches people had made on the site. ASOS then wrote to customers again. It says no payment card details or passwords were taken.
That second message also explained the way in. According to the email, quoted by Infosecurity Magazine, an attacker got into an employee's account "by impersonating a trusted contact to obtain log in credentials". Those credentials were then used to "access information on certain third-party platforms used by ASOS".
Some things are still claims. The attackers told the BBC they got to the data through a marketing platform that sits on top of Snowflake, a widely used data storage service. Neither ASOS nor that supplier has confirmed it. Snowflake says it has found no compromise of its own platform.
Nobody broke in
Read ASOS's account again and notice what is missing. No software flaw. No malware. The company says its website and app stayed safe to use throughout.
Somebody pretended to be a person an employee trusted, and was given a username and password. That login worked on services run by other companies, on those companies' servers, where ASOS's own defences could not see it being used.
This is the ordinary shape of a modern business, not a peculiarity of a big retailer. Your customer list does not live in one place. A copy sits in the email tool, another in the accounts package, another in whatever sends your appointment reminders. Each was connected so that the tool could do its job. Each is opened by a staff login, and usually by more staff logins than anyone remembers granting.
Dan Bird of the security firm Horizon3 saw it coming on the first day. If the claims held up, he told the BBC, it suggested the attackers "got hold of credentials that opened more than one door".
The channel is the prize
The notification was not a side effect. A message that arrives through your own app, or from your own email address, carries your name and your customers' trust with it. The National Cyber Security Centre has told ASOS customers to assume they are affected and to be wary of links, "including those you receive in push notifications".
Think about what that means for a smaller firm. A fake invoice reminder sent from your real billing system, to your real customer list, would be believed. Access to the tool that talks to your customers is worth as much to a criminal as the data inside it.
What to do
- List what can reach your customers. Write down every service that can send them an email, a text, or a notification, and every service holding a copy of the customer list. Most firms find more than they expected.
- Count the logins on each. Remove former colleagues, shared accounts, and anyone who no longer needs it. Fewer people with access means fewer people who can be talked round.
- Make a stolen password useless on its own. Turn on two-step verification, the code or prompt you get after typing your password, on every one of those services. Where a service offers passkeys, which cannot be read out over the phone, use them.
- Agree a rule for requests to share access. Nobody gives a password, a code, or a login link to someone who contacts them, whoever they say they are. They end the conversation and ring the person back on a number they already hold. We set that rule out in the call that comes from your own IT desk.
- Ask marketing suppliers what they can read. A tool that sends offers does not need dates of birth. If it has more of your customer data than its job requires, ask for that to be narrowed.
- Decide how you would tell customers. ASOS said "basic" on Tuesday and had to correct it on Thursday. In a first statement, say what is confirmed, say what is still being investigated, and promise an update. That holds up when the facts move.
How Steelwise can help
Working out which outside services can reach your customers, and who can log in to each, is a short and practical piece of security advisory work. Get in touch if you would like help with it.
Further reading
- NCSC: Supply chain security guidance
- NCSC: Phishing attacks, defending your organisation
- ICO: Personal data breaches