ASOS said attackers accessed an employee's account and, from it, sent a fraudulent push notification. The company described the case as one in which criminals tricked the employee into granting access, according to the version published in The Record's feed. The investigation, carried out with outside experts, concluded that the attackers accessed some personal information, including names and contact details, and certain non-personal information related to accounts. The report does not give the number of people affected or the exact form of the deception. For anyone studying the case, the key point is that a staff account with sending rights became the channel for the scam, and that exposed contact details can fuel later phishing attempts. The source is a machine translation of an English-language report; to verify the facts, consult the original article in The Record and any official statements from the company.
Cyber ·
ASOS says attackers accessed an employee account and sent a fraudulent push notification
ASOS said attackers accessed an employee's account and sent a fraudulent push notification. The investigation, conducted with outside experts, identified access to names, contact details and some non-personal account information.
Rota Nacional
Bring privacy into your workflow.
30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.