ASOS: Hackers tricked way into employee account before sending rogue push notification
The company said its investigation, carried out with external experts, found the attackers had accessed “some personal information, including names and contact details, and certain non-personal account related information.”
Excerpt from the primary source: The Record by Recorded Future News
Who is affected
Security professionals
What you should do · Be aware
No immediate action is indicated. Share this with the relevant teams and watch for updates.
Automated guidance based on this story's classification. Check the linked advisories for specifics.
Sources
We link to original and authoritative sources. Headlines and excerpts belong to their publishers.
Related
Russian Spies Give 'MatchBoil' Malware a Stealthy Facelift
Cyber-espionage actor UAC-0099 has been steadily refining its flagship dropper in campaigns targeting Ukrainian organizations.
Leaked chats show Russian extortion gang sending ‘agents’ into US law firms
In leaked chats, members track dozens of victims, haggle over multimillion-dollar payments and direct operatives based in the United States whom they call “agents.”
Hackers target two South Korean megachurches, potentially exposing congregant data
Two of South Korea's largest Protestant churches are investigating cyberattacks that may have exposed sensitive information about hundreds of thousands of members, including personal details, financial records and internal documents.
Russian-aligned spies upgrade malware used in attacks on Ukrainian transport, energy firms
Russian-aligned hackers have targeted Ukrainian transportation, manufacturing and energy companies with a constantly evolving malware strain designed to harvest system data, according to new research.
