Stolen employee login exposes ASOS customer contact details
Daily Cyber News: Stolen employee login exposes ASOS customer contact details
ASOS says a social engineering attack exposed some customer personal and contact information. An attacker impersonated a trusted contact, obtained an employee’s login credentials, and used them to access third-party platforms used by the retailer. The company said payment card information and customer account passwords were not accessed.
Key context: For leaders, the incident shows how one employee account can extend risk into several external platforms.
Additional detail: The larger lesson is that third-party access and trusted-contact impersonation need to be included in identity threat models.
For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
Cybersecurity training, courses, books, and resources: BareMetalCyber.com.
Topics: cybersecurity news, cybersecurity, cyber risk, phishing, Stolen, employee, login, exposes, ASOS, customer.