The ASOS breach just got worse — and in a way that matters more to defenders than the headline suggests. Updated reporting confirms that the stolen data set includes not just customer personal details, but shopping search histories. That single addition transforms this from a routine PII exposure into a feedstock for highly convincing, hyper-personalized social engineering.
I've worked enough post-breach IR engagements to tell you: the breach itself is often the least dangerous phase. What follows — the weaponization phase — is where organizations and individuals actually get hurt. When an attacker knows you searched for "men's black chelsea boots size 10" last Tuesday, a follow-up email offering a "restock alert" or "price drop" on exactly that item isn't spam. It's a precision-guided lure.
If your organization has employees who are ASOS customers (statistically, you do), your SOC should treat this as an active phishing campaign seeding event, not a passive privacy headline.
Technical Analysis
What Was Taken
Based on the updated breach disclosure, the compromised data set includes:
- Customer personal details — names, contact information (email addresses, phone numbers), and account-associated data
- Shopping search history — the queries customers typed into the ASOS platform
No CVE is associated with this incident — this is a data breach of a retail platform, not a software vulnerability. The exploitation vector from this point forward is human, not technical. That distinction drives everything about how you defend against it.
Why Search History Is a Force Multiplier for Phishing
Traditional breach-derived phishing relies on static PII: name, email, maybe a physical address. Lures are generic — "your package couldn't be delivered," "verify your account." Sophisticated users and even basic secure email gateways filter most of it.
Search history changes the economics of the lure:
- Personalization at scale. Attackers can programmatically generate thousands of unique emails referencing the exact brands, sizes, styles, or categories each victim browsed. Open rates and click rates on personalized lures are dramatically higher than generic phishing.
- Contextual plausibility. A fake ASOS order-confirmation, refund notification, or "item back in stock" email referencing products the victim actually searched for bypasses the victim's own mental filter. This is the social engineering equivalent of a zero-day — no signature exists for it.
- Follow-on payload flexibility. These lures are delivery vehicles for credential harvesting (fake ASOS login pages), payment card skimming (fake checkout for a "discounted" searched item), or malware delivery disguised as invoices/receipts.
- Credential stuffing and account takeover. Breached email/password combinations from retail breaches are routinely replayed against corporate SSO, VPN, and SaaS portals due to password reuse.
Exploitation Status
This is confirmed active data theft with imminent weaponization risk. There is no "PoC vs. theoretical" debate here — breached retail data of this specificity has historically been monetized within days to weeks via phishing kits, credential stuffing lists, and resale on criminal marketplaces. Defenders should assume the data is already in circulation and act accordingly.
Expected Attack Chain (Defender's View)
- Victim receives personalized lure referencing real ASOS search activity (email or SMS — smishing is equally likely given phone numbers in the data set).
- Lure links to a typosquatted or lookalike ASOS domain (e.g.,
asos-deals.com,asos.support-track.net, homoglyph variants). - Landing page harvests credentials and/or payment data, or delivers a malicious "invoice"/"receipt" payload.
- Harvested credentials replayed against the victim's other accounts — including corporate resources where password reuse exists.
- If malware was delivered, expect common phishing follow-ons: script interpreters (wscript/mshta), Office child processes, or rundll32 execution of staged payloads.
Detection & Response
The detections below target the weaponization phase: lookalike ASOS infrastructure on your network, Office-based payload execution from phishing lures, and credential replay against your identity systems.
Sigma Rules
The following rules focus on the two most reliable observable behaviors: ASOS lookalike domain resolution, and the classic phishing payload execution chain (Office spawning script interpreters or LOLBins). Both are tuned to minimize false positives.
---
title: ASOS Typosquat or Lookalike Domain Resolution
description: Detects DNS resolution of domains impersonating the ASOS brand, consistent with phishing campaigns leveraging data stolen in the 2026 ASOS breach (personalized lures referencing customer shopping searches).
author: Security Arsenal
status: experimental
date: 2026/10/15
references:
- https://www.malwarebytes.com/blog/data-breaches/2026/10/asos-breach-update-hackers-stole-customer-details-and-shopping-searches
- https://attack.mitre.org/techniques/T1566/002/
logsource:
category: dns
product: windows
detection:
selection_pattern:
query|contains:
- 'asos-'
- '-asos'
- 'asos.'
- 'as0s'
- 'asos-support'
- 'asos-deals'
- 'asos-track'
- 'asos-refund'
filter_legitimate:
query|contains:
- '.asos.com'
- 'asos.com.'
condition: selection_pattern and not filter_legitimate
falsepositives:
- Legitimate regional or partner ASOS domains (maintain an allowlist)
level: high
---
title: Office Application Spawning Script Interpreter or LOLBin
description: Detects Microsoft Office applications spawning script interpreters, mshta, rundll32, or download cradles, consistent with execution of malicious attachments delivered via phishing lures such as fake ASOS order confirmations or refund notices.
author: Security Arsenal
status: experimental
date: 2026/10/15
references:
- https://attack.mitre.org/techniques/T1566/001/
- https://attack.mitre.org/techniques/T1059/
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith:
- '\winword.exe'
- '\excel.exe'
- '\powerpnt.exe'
- '\outlook.exe'
- '\mspub.exe'
selection_child:
Image|endswith:
- '\wscript.exe'
- '\cscript.exe'
- '\mshta.exe'
- '\rundll32.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\cmd.exe'
- '\certutil.exe'
- '\bitsadmin.exe'
- '\curl.exe'
condition: selection_parent and selection_child
falsepositives:
- Rare legitimate Office add-ins or templates (investigate before allowlisting)
level: high
---
title: Browser Followed by Credential Entry on Newly Observed ASOS Lookalike via Rundll32 or Script Drop
description: Detects script interpreters executing content from user-writable download or temp directories shortly after browser activity, a common chain when phishing pages deliver fake invoices or receipts tied to breached retail data.
author: Security Arsenal
status: experimental
date: 2026/10/15
references:
- https://attack.mitre.org/techniques/T1204/002/
logsource:
category: process_creation
product: windows
detection:
selection_exec:
Image|endswith:
- '\wscript.exe'
- '\cscript.exe'
- '\mshta.exe'
selection_path:
CommandLine|contains:
- '\Downloads\'
- '\AppData\Local\Temp\'
- '\AppData\Roaming\'
condition: selection_exec and selection_path
falsepositives:
- User-executed legitimate scripts from Downloads (low frequency in most environments)
level: medium
KQL — Microsoft Sentinel / Defender
This hunt combines ASOS lookalike domain network activity with subsequent suspicious process execution on the same device — the full phishing kill chain in one query. Run it across the last 14 days, then pivot on any hits by user and device.
let lookback = 14d;
let asos_lookalikes = dynamic(["asos-", "-asos", "as0s", "asos-support", "asos-deals", "asos-track", "asos-refund", "asos-billing", "asos-verify"]);
let DomainHits = DeviceNetworkEvents
| where TimeGenerated > ago(lookback)
| where RemoteUrl has_any (asos_lookalikes)
and not (RemoteUrl endswith "asos.com")
| project NetworkTime = TimeGenerated, DeviceName, DeviceId, RemoteUrl, RemoteIP, InitiatingProcessFileName, InitiatingProcessAccountName;
DomainHits
| join kind=leftouter (
DeviceProcessEvents
| where TimeGenerated > ago(lookback)
| where InitiatingProcessParentFileName in~ ("winword.exe","excel.exe","outlook.exe","chrome.exe","msedge.exe","firefox.exe")
| where FileName in~ ("wscript.exe","cscript.exe","mshta.exe","rundll32.exe","powershell.exe","cmd.exe","certutil.exe")
| project ProcTime = TimeGenerated, DeviceId, FileName, ProcessCommandLine, InitiatingProcessParentFileName, AccountName
) on DeviceId
| where isnotempty(ProcTime) and ProcTime between (NetworkTime .. NetworkTime + 10m)
| project NetworkTime, DeviceName, InitiatingProcessAccountName, RemoteUrl, RemoteIP, FileName, ProcessCommandLine
| sort by NetworkTime desc;
A second, simpler identity-side hunt for credential replay against your tenant following the breach:
SigninLogs
| where TimeGenerated > ago(7d)
| where ResultType != 0
| summarize FailedAttempts = count(), DistinctIPs = dcount(IPAddress), IPs = make_set(IPAddress, 5) by UserPrincipalName, AppDisplayName, bin(TimeGenerated, 1h)
| where FailedAttempts >= 5 and DistinctIPs >= 3
| sort by FailedAttempts desc;
Bursts of multi-IP authentication failures per user are a strong indicator that breached credential pairs are being replayed against your environment.
Velociraptor VQL
Use this hunt across your fleet to surface script interpreters executing from user-writable paths — the most common endpoint artifact of phishing-delivered payloads:
-- Hunt for script interpreter execution from user-writable paths (phishing payload staging)
SELECT Pid, Ppid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE (Name =~ '(?i)wscript|cscript|mshta|rundll32|powershell'
AND CommandLine =~ '(?i)Downloads|AppData\\Local\\Temp|AppData\\Roaming')
OR CommandLine =~ '(?i)asos'
The additional asos CommandLine match catches any lure-named payloads (e.g., ASOS_Invoice.pdf.js, asos_refund.vbs) directly.
Remediation / Hardening Script
This PowerShell script performs three defensive actions: it creates an Exchange Online transport rule to flag/quarantine external ASOS-impersonation mail, audits your tenant for suspicious inbox rules created around ASOS-themed mail (a common post-phish persistence mechanism), and enables Defender Safe Links verification if not already active. Run from a workstation with Exchange Online PowerShell installed and appropriate admin credentials.
# ASOS Breach Phishing Defense — Exchange Online hardening and audit
# Prerequisites: Install-Module ExchangeOnlineManagement; admin credentials
Connect-ExchangeOnline
# 1) Transport rule: quarantine external mail impersonating ASOS
$ruleName = "SEC-Quarantine-ASOS-Lookalike-Phish"
$existing = Get-TransportRule -Identity $ruleName -ErrorAction SilentlyContinue
if (-not $existing) {
New-TransportRule -Name $ruleName `
-FromScope NotInOrganization `
-SubjectOrBodyMatchesPatterns "asos[-_. ]?(support|deals|refund|track|billing|verify|order)","as0s" `
-SenderDomainIsNot @("asos.com") `
-Quarantine $true `
-SetAuditSeverity High `
-Comments "Blocks personalized phishing leveraging 2026 ASOS breach data. Created by Security Arsenal response script."
Write-Host "[+] Transport rule '$ruleName' created. External ASOS-impersonation mail will be quarantined." -ForegroundColor Green
} else {
Write-Host "[=] Transport rule already exists." -ForegroundColor Yellow
}
# 2) Audit all mailboxes for inbox rules referencing ASOS (post-compromise persistence)
Write-Host "[*] Auditing inbox rules for ASOS-themed forwarding/deletion rules..." -ForegroundColor Cyan
$report = @()
Get-Mailbox -ResultSize Unlimited | ForEach-Object {
$mbx = $_.PrimarySmtpAddress
Get-InboxRule -Mailbox $mbx -ErrorAction SilentlyContinue | Where-Object {
$_.SubjectContainsWords -match "asos" -or $_.BodyContainsWords -match "asos" -or $_.From -match "asos"
} | ForEach-Object {
$report += [PSCustomObject]@{
Mailbox = $mbx
RuleName = $_.Name
ForwardTo = ($_.ForwardTo -join ';')
RedirectTo = ($_.RedirectTo -join ';')
DeleteMsg = $_.DeleteMessage
Enabled = $_.Enabled
}
}
}
if ($report.Count -gt 0) {
$report | Export-Csv -Path ".\ASOS_InboxRule_Audit_$(Get-Date -Format 'yyyyMMdd').csv" -NoTypeInformation
Write-Host "[!] $($report.Count) suspicious inbox rule(s) found — exported to CSV. Investigate ForwardTo/RedirectTo for external addresses." -ForegroundColor Red
$report | Format-Table -AutoSize
} else {
Write-Host "[+] No ASOS-themed inbox rules found." -ForegroundColor Green
}
# 3) Verify Safe Links protection is enabled
$sl = Get-SafeLinksPolicy | Select-Object Name, IsEnabled, EnableSafeLinksForEmail, EnableSafeLinksForTeams
$sl | Format-Table -AutoSize
if ($sl | Where-Object { $_.IsEnabled -eq $false }) {
Write-Host "[!] One or more Safe Links policies are DISABLED. Enable them before this campaign matures." -ForegroundColor Red
}
Disconnect-ExchangeOnline -Confirm:$false
Write-Host "[*] Done. Review quarantine daily for the next 30 days." -ForegroundColor Cyan
Remediation
For Organizations (Defenders)
- Alert your user base — specifically. Generic "watch out for phishing" emails get ignored. Tell employees that attackers have real ASOS search data and that lures may reference products they actually browsed. Specificity is what makes warnings land.
- Deploy the transport rule and detections above. Quarantine, don't just tag, external ASOS-impersonation mail for the next 60–90 days.
- Block ASOS typosquat domains at DNS/proxy. Add the lookalike patterns from the Sigma rule to your DNS filtering (and monitor newly registered domains containing
asosvia services like DNSTwist feeds or your TI provider). - Enforce phishing-resistant MFA now. This breach's secondary risk is credential stuffing from password reuse. FIDO2/passkeys defeat replay; SMS and push-without-number-matching do not.
- Run the KQL credential-replay hunt weekly for at least the next quarter. Correlate spikes with your IdP's impossible-travel and anonymizing-proxy detections.
- Audit inbox rules across the tenant (script above) — BEC actors routinely create hidden forwarding rules within minutes of a credential phish.
For ASOS Customers (Advise Your Employees)
- Treat any ASOS-themed email or SMS as hostile by default, especially if it references specific products, refunds, restocks, or order issues. Navigate to asos.com directly — never via a link.
- Reset the ASOS account password and any other account sharing that password. Use a password manager to eliminate reuse.
- Enable MFA on the ASOS account and on any account that reused the same credentials.
- Watch financial statements — the data set enables convincing fake checkout/payment pages.
- Expect smishing. Phone numbers were in the data set; text-based lures referencing real searches are equally likely and bypass corporate email controls entirely.
Breach Response Timeline Expectation
From IR experience with retail breaches of this profile: expect the first wave of phishing within 1–2 weeks, credential stuffing waves within days, and resale of the enriched data set (PII + behavioral search data commands a premium) on criminal marketplaces within 30 days. Your detection window is now.
Related Resources
Security Arsenal Incident Response Services AlertMonitor Platform Book a SOC Assessment incident-response Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.