October 7, 2026
Blog

When a trusted channel goes rogue: What the ASOS incident tells us

The ASOS security incident highlights how cybercriminals can exploit trusted communication channels and third-party platforms, potentially turning an organisation’s established customer trust into a powerful security vulnerability.

The ASOS incident reported on October 6th caught our attention, though not for the most obvious reason.

Customers received an unauthorised push notification through a platform ASOS uses to communicate with them, as reported by Infosecurity Magazine.

We spend a lot of time teaching people to spot suspicious emails, links and messages. But what happens when a malicious message arrives through a channel the customer already trusts? Suppose that, instead of announcing the compromise, the message had simply said: "Your account has been locked. Tap here to verify your account." How many people would question a notification that appears to come straight from an app they already use?

There's a second angle. The attackers claim to have compromised ASOS's Snowflake environment, although that remains unverified, according to Cybersecurity News. That recalls the 2024 campaign investigated by Mandiant, in which UNC5537 used stolen credentials to access Snowflake customer instances for data theft and extortion. Mandiant found no evidence that Snowflake itself had been breached.

This is a different incident, and we don't yet know the full picture. But the lesson holds: security isn't only about protecting the data. It's about protecting every system and third party that carries your organisation's identity and customer trust.

Once an attacker controls a trusted communication channel, they potentially inherit some of that trust too.

‍

We're here to help

Our experts are on hand to learn about your organisation and suggest the best approach to meet your needs. Contact an expert today.

Get in touch
hexes