Articles
Cyber security and digital communication

ASOS cyberattack exposes risks in digital communications

The British retailer reported unauthorised activity involving third-party communication platforms after a notification was sent on 6 October. Names and contact details may be affected.

ASOS acknowledged a cyberattack after an unauthorised notification was sent to customers on 6 October. The British retailer said it was investigating activity involving third-party communication platforms and had restricted access to its notification systems. ASOS

Which information might be affected?

According to that statement, names and contact details may have been accessed. ASOS did not believe passwords or payment-card details were affected. That initial assessment does not mean the investigation is complete. ASOS

Snowflake: separating the threat from the evidence

ITPro documented a message claiming that a Snowflake instance had been compromised and threatening to release information. The outlet also reported a Snowflake spokesperson’s response: its investigation had, at that point, found no compromise of the platform and was continuing. ITPro

In its 7 October follow-up, Infosecurity Magazine reported the assessment of Anastasia Tikhonova, Group-IB’s head of threat research: she had found no evidence establishing that the group held customer data. That assessment limits what is established about the data; it does not negate the attack on the communication channel. Infosecurity Magazine

Why this matters for communication

The case offers a way to examine an everyday expectation: recognising a company’s app may make us trust what appears on screen. REDES’ editorial recommendation is to check the content of an alert too, particularly when it demands immediate action or asks you to open a link.

A business needs to be able to guide the public while it investigates. The NCSC’s incident-response guidance recommends preparing alternative channels, assigning responsibilities and communicating clearly, accurately and promptly, without speculation. NCSC: communications strategy

Applied to this case, each update would benefit from distinguishing what is known, what remains under investigation and what customers should do. This is an editorial recommendation for communicating during an investigation.

What to do if you are a customer

The NCSC advises taking precautions even if you did not receive the notification. It recommends avoiding suspicious links in alerts, emails and messages, and watching for subsequent scams. It also advises securing accounts with passkeys or unique passwords and two-step verification, where available. NCSC: customer advice

As a practical way to follow that advice, check updates through an official address you already know. If a message asks you to pay, disclose a password or provide an access code, verify the request through an independent channel before responding. A brand name alone does not authenticate an instruction.

Trust also needs explanations

For REDES, the communications lesson is that a useful update should help readers decide what to do without overstating what is known. Being clear about the limits of the evidence makes it possible to warn people without presenting a threat as an established fact. Accuracy is also part of caring for the public.

Sources

Share this publication

You may share links, download the resources made available and republish my own material unchanged and for non-commercial purposes. Retain my credit and include a link to the original REDES publication. Third-party resources remain subject to their own terms. Terms of use.