<img alt="" src="https://secure.inventive52intuitive.com/789747.png" style="display:none;">
What the ASOS Hack Means For Your Business

What the ASOS Hack Means For Your Business

Posted by HTG

magine opening a notification from your favourite shopping app and finding a ransom note. That is what happened to thousands of ASOS customers on Tuesday 6 October, when a message headed “ASOS hacked” landed on their phones. Attackers had got into the tools ASOS uses to talk to its customers and used them to make their demand in public.

What we know so far

The message was actually meant for ASOS’s data protection officer and IT team. The attackers claimed to have full access to the company’s Snowflake data platform and said they would leak the lot unless ASOS got in touch. ASOS has confirmed the notification was not theirs and says it is investigating activity on third-party platforms it uses to communicate with customers.

So far, ASOS says names and contact details may have been accessed. It does not believe card details or passwords were affected, and nobody has verified the Snowflake claim. The National Cyber Security Centre is in contact with ASOS. The website and app carried on as normal, but the share price still dropped around 11% that morning.

This is not a one-off, either. Back in July, attackers used passwords stolen from other websites to get into ASOS customer accounts, exposing details belonging to an estimated 138,828 people.

Why this matters if you run a smaller business

It is tempting to file this under “big company problems” and move on. Here is the thing, though: neither of these attacks needed a business the size of ASOS. Both would work just as well on a 30-person firm.

Your suppliers are part of your security. The attackers seem to have come in through third-party platforms, not ASOS’s own website. Think about how many of those your business relies on: email marketing, the CRM, the accounts package, the booking system. Each one holds customer data and each one has logins. Could you list who has admin access to all of them right now? If the answer is “not really”, you are in good company, and it is one of the easier things to fix.

Reused passwords are still the easiest way in. The July incident involved no clever hacking at all. People had used the same password on ASOS as on another site that had already been breached. The same thing happens with work accounts every day. Multi-factor authentication stops most of it, and it is not hard to switch on.

Then there is trust. ASOS did not lose a single day of trading, yet customers were deleting their card details within hours. A retailer with millions of customers can ride that out. A business with a few hundred loyal ones will feel it far more.

Where we come in

ASOS has an in-house security team, outside specialists and cyber insurance to lean on. Most small and medium-sized businesses have someone in the office who is “good with computers” and a to-do list that never quite gets to security. That is the gap we have been filling since 2001.

Overwatch, our managed IT and security service, takes care of the basics that would have made both of these attacks harder. We manage who has access to what and make sure multi-factor authentication is switched on across your Microsoft 365 accounts. We also keep an eye out for sign-ins that do not look right. If something does look off, you talk to a named team who already know your systems.

Not sure where you stand? Our Save and Secure review is a good place to start. You get a plain-English picture of your setup and where the gaps are, with no jargon and no judgement. From there we can take you through Cyber Essentials, the government-backed scheme covering the controls most attacks rely on being missing.

You do not need an ASOS-sized budget to avoid an ASOS-sized headache. You need the basics done properly and someone reliable to call when it matters.

Want to know how your business would hold up? Get in touch to book a Save and Secure review.


Contact

Want to partner with us?

Get in touch to learn more about our services or arrange a free 30-minute consultation with one of our Secure Cloud Experts.

Get in touch
HTG - Contact CTA