Online fashion retailer ASOS has confirmed to affected customers that a cybersecurity incident earlier this week resulted in unauthorized access to personal data. According to reporting by BleepingComputer, ASOS has attributed the breach to a social engineering attack combined with credential theft — meaning the attackers did not exploit a software vulnerability. They exploited people and process, then walked through the front door with legitimate credentials.
This is the breach pattern we are seeing dominate incident response engagements in 2025 and 2026: no zero-day, no exotic malware, just a convincing phone call or phishing lure, a harvested credential, and an authenticated session that looks legitimate to every perimeter control you own. If your defensive strategy is still weighted toward patching and perimeter defense while your help desk can reset a password or MFA factor on the strength of a friendly voice, you are exposed to exactly this attack.
For defenders, the ASOS incident is a forcing function. This post breaks down the attack chain, provides production-ready detection content for credential theft and post-reset anomalies, and lays out a hardening roadmap for the identity and support workflows that these attacks abuse.
Technical Analysis
What happened
Per the BleepingComputer report, ASOS is notifying impacted customers that hackers accessed some personal data, and the company has linked the intrusion to social engineering and credential theft. Key points from the disclosure:
- Initial access vector: Social engineering — manipulation of a human target (employee, contractor, or support staff) rather than exploitation of a technical flaw.
- Access method: Stolen credentials were used to authenticate into ASOS systems, giving the attackers authorized-looking access to internal resources.
- Impact: Customer personal data was accessed. ASOS has not disclosed full scope in the initial notifications, and affected customers are being contacted directly.
Attack chain, from a defender's perspective
This intrusion class follows a well-documented identity-centric kill chain (MITRE ATT&CK mappings noted):
- Reconnaissance (TA0043): Attackers enumerate target employees via LinkedIn, corporate directories, and previous breach corpora. Support desk staff and privileged users are prioritized because they hold reset authority or broad access.
- Social engineering (T1656 / T1566): A phishing lure, vishing call to the service desk, or impersonation of an employee. In many 2025-2026 engagements, this includes MFA fatigue (push bombing, T1621) or convincing an agent to reset an MFA factor after 'verifying' the caller with OSINT-derived personal details.
- Credential theft (T1003 / T1555 / T1539): Credentials are harvested via phishing kits with adversary-in-the-middle (AiTM) capability to capture session tokens, or dumped from an already-compromised endpoint (LSASS memory access, browser credential stores).
- Initial access with valid accounts (T1078): The attacker authenticates as a legitimate user. This is the critical defensive problem: nothing about the authentication itself is malicious. Detection must key on context — source IP, device, geography, time, and what the account does next.
- Discovery and collection (TA0007 / TA0009): The attacker locates customer databases, CRM exports, or support tooling with PII visibility.
- Exfiltration (TA0010): Bulk data staged and moved out over sanctioned channels (HTTPS to cloud storage) where possible.
Exploitation status
This is confirmed, real-world exploitation — not a theoretical threat. Social-engineering-driven credential theft is among the most common confirmed initial access vectors in breaches disclosed across 2025 and into 2026, spanning retail, healthcare, telecom, and SaaS. No CVE is associated with this incident; there is nothing to patch. The vulnerability is process and identity architecture, which is precisely why so many organizations remain exposed.
Why endpoint-only defenses miss this
If the attacker phishes credentials and logs in via a web portal or VPN from their own infrastructure, your EDR never fires. Your visibility must extend to identity telemetry: authentication logs, password reset events, MFA registration changes, and post-authentication behavior. The detections below are built around that reality.
Detection & Response
The following content targets the two most reliable observable phases of this attack class: (1) credential harvesting on endpoints, and (2) anomalous account activity following password resets — the signature of help-desk social engineering.
Sigma Rules
---
title: LSASS Memory Access by Non-System Process
tid: a4f2c91d-3e6b-4a7c-9d21-5f8e0b3c7a12
status: experimental
description: Detects processes accessing LSASS memory with access rights consistent with credential dumping. Credential theft of this type was the mechanism linked to the ASOS breach attack chain. Baseline your environment before enabling at high level.
references:
- https://attack.mitre.org/techniques/T1003/001/
- https://www.bleepingcomputer.com/news/security/asos-links-data-breach-to-social-engineering-attack-credential-theft/
author: Security Arsenal
date: 2026/01/12
tags:
- attack.credential_access
- attack.t1003.001
logsource:
category: process_access
product: windows
detection:
selection:
TargetImage|endswith: '\lsass.exe'
GrantedAccess|contains:
- '0x1010'
- '0x1038'
- '0x1410'
- '0x1438'
- '0x143a'
- '0x1fffff'
filter_legitimate:
SourceImage|endswith:
- '\svchost.exe'
- '\wininit.exe'
- '\csrss.exe'
- '\MsMpEng.exe'
- '\services.exe'
condition: selection and not filter_legitimate
falsepositives:
- EDR and AV products accessing LSASS — add your security tooling to the filter after validation
level: high
---
title: Credential Theft Tool or LOLBin Memory Dump Execution
id: c7e5b802-1f4a-4d93-8c62-9a0d4e6f2b85
status: experimental
description: Detects execution of known credential dumping tools and the comsvcs.dll MiniDump LOLBin technique commonly used to extract LSASS memory for offline credential theft.
references:
- https://attack.mitre.org/techniques/T1003/
- https://attack.mitre.org/techniques/T1218/
author: Security Arsenal
date: 2026/01/12
tags:
- attack.credential_access
- attack.t1003.001
- attack.defense_evasion
logsource:
category: process_creation
product: windows
detection:
selection_toolnames:
CommandLine|contains:
- 'sekurlsa'
- 'mimikatz'
- 'pypykatz'
- 'nanodump'
- 'sharpdump'
- 'dumpert'
selection_comsvcs:
CommandLine|contains:
- 'comsvcs.dll'
- 'MiniDump'
selection_procdump:
Image|endswith: '\procdump.exe'
CommandLine|contains: 'lsass'
condition: 1 of selection_*
falsepositives:
- Authorized penetration testing or red team activity — scope by authorized user/OU
level: high
---
title: Domain Account Password Change via Net.exe Command Line
id: 3b9d1e47-8c52-4f6a-b134-7e2a5c90d4f6
status: experimental
description: Detects password changes against domain accounts performed via net.exe. Help-desk social engineering intrusions frequently result in scripted or interactive password resets using built-in tooling once an attacker reaches a foothold or coerces an agent.
references:
- https://attack.mitre.org/techniques/T1098/
- https://www.bleepingcomputer.com/news/security/asos-links-data-breach-to-social-engineering-attack-credential-theft/
author: Security Arsenal
date: 2026/01/12
tags:
- attack.persistence
- attack.t1098
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|endswith:
- '\net.exe'
- '\net1.exe'
selection_cmd:
CommandLine|re: '(?i)user\s+\S+\s+\S+\s+\/domain'
condition: selection_img and selection_cmd
falsepositives:
- Help desk and systems administration staff performing legitimate password resets — correlate with change tickets and authorized admin accounts
level: medium
KQL — Microsoft Sentinel / Defender
The highest-fidelity hunt for help-desk social engineering is correlating a password reset (Event ID 4724, an account's password was reset by someone else) with the reset account's subsequent sign-in activity from infrastructure it has never used before. This is the exact pattern produced when an attacker convinces a service desk agent to reset a victim's credentials.
// Correlate administrative password resets with first-seen logon sources within 4 hours
let lookback = 14d;
let resetWindow = 4h;
let KnownSources = SecurityEvent
| where TimeGenerated > ago(30d)
| where EventID == 4624 and LogonType in (3, 10)
| summarize by TargetUserName, IpAddress;
SecurityEvent
| where TimeGenerated > ago(lookback)
| where EventID == 4724
| extend ResetTime = TimeGenerated, ResetTarget = TargetAccountName, ResetBy = SubjectAccountName
| join kind=inner (
SecurityEvent
| where TimeGenerated > ago(lookback)
| where EventID == 4624
| extend LogonTime = TimeGenerated, LogonUser = TargetUserName
) on $left.ResetTarget == $right.LogonUser
| where LogonTime between (ResetTime .. (ResetTime + resetWindow))
| extend ResetTarget = tolower(ResetTarget)
| join kind=leftanti KnownSources on $left.ResetTarget == $right.TargetUserName, $left.IpAddress == $right.IpAddress
| summarize FirstLogon = min(LogonTime), LogonCount = count(), IPs = make_set(IpAddress), Workstations = make_set(WorkstationName1) by ResetTarget, ResetBy, ResetTime, Computer
| where LogonCount > 0
| sort by ResetTime desc
// Hunt endpoint telemetry for credential dumping behaviors across the fleet
DeviceProcessEvents
| where TimeGenerated > ago(7d)
| where (ProcessCommandLine has_any ('sekurlsa', 'mimikatz', 'pypykatz', 'nanodump', 'sharpdump', 'dumpert'))
or (ProcessCommandLine has 'comsvcs.dll' and ProcessCommandLine has 'MiniDump')
or (FileName =~ 'procdump.exe' and ProcessCommandLine has 'lsass')
or (FileName in~ ('net.exe', 'net1.exe') and ProcessCommandLine matches regex '(?i)user\s+\S+\s+\S+\s+/domain')
| project TimeGenerated, DeviceName, FileName, ProcessCommandLine, InitiatingProcessAccountName, InitiatingProcessFileName, SHA256
| sort by TimeGenerated desc
Velociraptor VQL
For IR triage on suspected compromised endpoints, this artifact hunts for LSASS dump artifacts on disk and live processes matching credential-theft indicators — the two fastest wins when scoping a credential theft incident like the ASOS intrusion.
-- Hunt for LSASS dump artifacts and credential theft tool execution
SELECT Pid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE CommandLine =~ '(?i)(sekurlsa|mimikatz|pypykatz|nanodump|sharpdump|dumpert|comsvcs.*MiniDump)'
OR (Exe =~ '(?i)procdump' AND CommandLine =~ '(?i)lsass')
-- Sweep common staging paths for memory dump files indicative of LSASS extraction
SELECT FullPath, Size, Mtime, Atime
FROM glob(globs=[
'C:/Windows/Temp/**/*.dmp',
'C:/Users/*/AppData/Local/Temp/**/*.dmp',
'C:/Users/*/Downloads/*.dmp',
'C:/ProgramData/**/*.dmp',
'C:/PerfLogs/**/*.dmp'
])
WHERE Mtime > now() - (7 * 24 * 3600)
Remediation / Verification Script
Run this PowerShell audit on Windows endpoints and servers to verify credential-theft mitigations and surface recent password reset activity. It checks LSA Protection, WDigest cleartext credential caching, Credential Guard, and lists recent administrative password resets for review.
# ASOS-pattern credential theft hardening audit — run elevated
# 1. Verify LSA Protection (RunAsPPL) is enabled
$lsa = Get-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\Lsa' -ErrorAction SilentlyContinue
if ($lsa.RunAsPPL -eq 1) { Write-Output '[PASS] LSA Protection (RunAsPPL) is enabled.' } else { Write-Output '[FAIL] LSA Protection is NOT enabled. Set HKLM:\SYSTEM\CurrentControlSet\Control\Lsa\RunAsPPL = 1 and reboot.' }
# 2. Verify WDigest cleartext credential caching is disabled
$wd = Get-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest' -ErrorAction SilentlyContinue
if ($wd.UseLogonCredential -eq 0) { Write-Output '[PASS] WDigest cleartext caching disabled.' } else { Write-Output '[FAIL] WDigest may cache cleartext credentials. Set UseLogonCredential = 0.' }
# 3. Check Credential Guard status
$cg = Get-CimInstance -ClassName Win32_DeviceGuard -Namespace root\Microsoft\Windows\DeviceGuard -ErrorAction SilentlyContinue
if ($cg.VirtualizationBasedSecurityStatus -eq 2) { Write-Output '[PASS] Virtualization-Based Security running (Credential Guard capable).' } else { Write-Output '[WARN] VBS not running. Evaluate enabling Credential Guard via policy.' }
# 4. List administrative password resets (Event 4724) from the last 72 hours for review
Write-Output '--- Administrative password resets in last 72 hours ---'
Get-WinEvent -FilterHashtable @{ LogName = 'Security'; Id = 4724; StartTime = (Get-Date).AddHours(-72) } -ErrorAction SilentlyContinue | ForEach-Object { $_.Message.Split([Environment]::NewLine)[0]; $_.TimeCreated }
# 5. Sweep for LSASS dump artifacts in common staging locations
Write-Output '--- Recent .dmp files in common staging paths ---'
Get-ChildItem -Path 'C:\Windows\Temp', 'C:\ProgramData', "$env:TEMP" -Recurse -Filter *.dmp -ErrorAction SilentlyContinue | Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-7) } | Select-Object FullName, Length, LastWriteTime
Remediation
There is no patch for this breach class — the fix is architectural and procedural. Prioritize the following, in order:
- Phishing-resistant MFA everywhere it matters. Move privileged users, help desk staff, and any account with customer-data access to FIDO2 security keys or passkeys. SMS and push-based MFA are routinely defeated by AiTM phishing kits and MFA fatigue — the techniques at the center of modern social engineering breaches.
- Lock down the service desk. Implement mandatory identity verification for password and MFA resets: callback to a number on file (not a number the caller provides), manager or second-agent approval for MFA factor changes on privileged accounts, and immutable audit logging of every reset. The KQL correlation above should alert on every reset-to-new-source sequence.
- Conditional access and session controls. Enforce compliant-device requirements, block legacy authentication, and alert on impossible travel and first-seen ASN/geography. Stolen passwords are worthless if the session cannot be established from attacker infrastructure.
- Token theft awareness. AiTM kits steal session cookies, not just passwords. Deploy token protection / continuous access evaluation where your IdP supports it, and shorten session lifetimes for sensitive applications.
- Endpoint credential hygiene. Enable LSA Protection, disable WDigest cleartext caching, and deploy Credential Guard on supported builds — verified with the script above. These controls raise the cost of LSASS dumping dramatically.
- Minimize data exposure. The reason credential theft became a customer data breach is that a compromised identity had access to PII. Enforce least-privilege access to customer databases, segment support tooling, and alert on bulk read/export operations.
- Credential exposure response. If credentials may have been exposed: force resets for affected accounts, revoke all active sessions and refresh tokens (not just password change), audit MFA registrations added in the exposure window, and hunt for the reset-to-anomalous-logon pattern.
- Customer notification and regulatory obligations. ASOS, as a UK/EU-facing retailer, operates under UK GDPR / EU GDPR notification requirements. If your organization suffers a comparable incident, engage counsel early on notification timelines and preserve forensic evidence before remediation destroys it.
For further reading, see the original BleepingComputer coverage of the ASOS incident and CISA's guidance on defending against social engineering and phishing-resistant authentication. Identity is the perimeter now — this breach is one more proof point that attackers have already internalized that fact. Defenders need to catch up.
Related Resources
Security Arsenal Managed SOC Services AlertMonitor Platform Book a SOC Assessment soc-mdr Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.