Opens in a new tab

How one borrowed login opened up ASOS’s customer data

A smartphone displaying the ASOS logo, a company recently impacted by a data breach, on a white screen.

Asos has confirmed that the attackers behind this week’s breach took detailed customer profiles, including names, home addresses, phone numbers, email addresses, customer numbers and dates of birth. The way they got in is the useful part for any SME. One employee was tricked into handing over a login, and that login was enough.

What happened at Asos

On the morning of Tuesday 6 October, ASOS app users received a push notification headed “ASOS HACKED”. The attackers had sent it through Asos’s own app messaging, claiming they’d compromised the company’s Snowflake data platform and threatening to leak what they’d taken.

Later that day, ASOS told the London Stock Exchange that an unauthorised third party was responsible and that basic contact details might have been accessed. It said it didn’t believe payment card details or account passwords were affected, and that’s still its position.

The picture changed on Wednesday evening, when the attackers sent the BBC a sample of the data. After the BBC raised it with Asos, the retailer emailed customers confirming that fuller profiles had been taken. The BBC also reports that customers’ search history on the site appears in the sample. Asos has around 16.5 million active customers, though it hasn’t said how many are affected.

How the attackers got in

Asos says the attackers reached an employee account “by impersonating a trusted contact to obtain login credentials”. With that login, they accessed a third-party service and downloaded the customer data. Asos hasn’t named the service.

The attackers claim it was Simon AI, a marketing platform that runs on top of Snowflake and lists Asos among its customers. Neither company has confirmed that, and Snowflake has previously said its own platform wasn’t breached. So the exact route is still an allegation.

The confirmed part is enough to learn from. Nothing Asos has said points to a software flaw. Someone convincing asked for a login, got it, and the account it opened could reach customer data in bulk.

The logins outside your main sign-in

Most SMEs we support have their core accounts in reasonable shape. Microsoft 365 or Google Workspace sits behind MFA, leavers get switched off, and someone owns the admin roles.

The weaker spot is usually everything around it: the CRM, the email marketing tool, the analytics platform, the client portal someone signed up to during a pitch. These often have their own usernames and passwords, sit outside single sign-on, and get added by whoever needed them that week.

Those tools also tend to hold the data an attacker wants most. A marketing platform with your full customer list and purchase history is very close to what was taken from Asos.

If that sounds like your setup, we’re happy to look at which of your tools sit outside your main sign-in and what each one can reach.

What we’d check this month

In Dr Logic’s experience, four checks cover most of the gap, and none needs new software.

  1. List every tool that holds customer or client data, and who has a login to each.
  2. Move as many as you can behind single sign-on with your Microsoft 365 or Google Workspace account, so your MFA and leaver process apply automatically. Where a tool doesn’t support single sign-on, switch on its own MFA.
  3. Check what each account can export. Most staff don’t need to download a full customer list, and most tools let you restrict it.
  4. Agree how staff verify anyone asking for credentials or access, even someone they think they know. A call back on a number you already have, or a quick check with IT, is enough.

A password manager helps with the last one too. 1Password only fills a login on the site it was saved for, so a convincing fake sign-in page gets an empty form, which is often the first clue something’s off.

If your team shop at Asos

ASOS is popular enough that some of your staff are probably in this data. Dates of birth, home addresses and phone numbers make impersonation calls and emails much more convincing, and those don’t always stay personal. A message that knows someone’s address and birthday is easier to trust when it then asks about work.

Trevor Dearing of Illumio, speaking to the BBC, expects scammers to mention the breach by name and push for a quick decision, such as threatening to lock an account. Asos says it’ll never ask for passwords, security codes or payment details in an unsolicited message or call. A two-line note to staff this week, repeating that, costs nothing.

Asos is still investigating, so expect more detail over the coming weeks. If you’d like help with any of the checks above, from the tool list to single sign-on, chat to the team.

A man with light brown hair, glasses, and a beard smiles at the camera. He is wearing a black shirt with the logo “DR Logic.” The background shows tall, modern glass buildings.
Shaun

CTO

Shaun is Chief Technology Officer at Dr Logic, overseeing the technical direction of the business and the infrastructure that underpins client environments. He brings hands-on experience across Apple device management, cloud architecture, and enterprise IT strategy, and his articles focus on the technology decisions that help growing businesses scale securely and efficiently.

Explore More Articles