PrivacySignal
Breach

ASOS links data breach to social engineering attack, credential theft

BleepingComputer · · International · Data Breaches

ASOS has begun notifying customers of a data breach in which hackers used social engineering and stolen credentials to access personal data. The fashion retailer confirmed the incident occurred earlier this week.

Why this matters: Social engineering breaches are different from technical exploits. Someone was tricked or manipulated into handing over access. That is a human failure, and it is also a systems failure, because good security does not rely on every employee making the right call under pressure. ASOS holds names, addresses, payment details, and purchase histories for millions of shoppers. If you shop there, watch for phishing follow-ups. Breaches like this rarely stop at the first wave of contact.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Deep Signal · Part I of III

The Algorithm Said So

Federal rulemakers are deciding what to do when artificial intelligence produces the kind of conclusion that once required an expert. They disagree about how to regulate it. They also disagree about whether the problem has arrived.

· 10 min read Read →

Related stories

Breach
DataBreaches.net · · International

KR: Coupang files lawsuits against 620 billion won fine over data leak

South Korea's largest online retailer, Coupang, is suing to challenge a roughly 620 billion won fine stemming from a data breach that exposed the records of more than 33 million customers. The incident, which has been in the news for nine months, has drawn sustained regulatory scrutiny.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement Read original →
Breach
BBC — Tech · · International

Asos hackers took more personal details than first revealed, BBC finds

Asos has revised the scope of a recent data breach after cyber criminals contacted the BBC to say the stolen data went beyond the basic contact details the retailer initially disclosed. The full extent of what was taken has not yet been confirmed publicly.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
War on the Rocks · · International

Achieving Breakthrough: Maneuver Warfare in the Face of Robotic Mass

Military analysts are drawing comparisons between the current drone-saturated battlespace in Ukraine and the trench warfare stalemate of World War I, arguing that robotic precision weapons are making large-scale armored movement as lethal today as crossing no-man's-land was in 1914.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →
Breach Critical
BleepingComputer · · International

Samsung Galaxy S26 hacked three more times at Pwn2Own Ireland

​​​On the second day of Pwn2Own Ireland 2026, security researchers collected $232,500 in cash awards after exploiting 45 unique zero-day vulnerabilities. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
The Guardian — Tech · · International

OpenAI used AI to help write email warning Australian government AI had hacked its websites

OpenAI used AI to help draft the email it sent to the Australian government disclosing that its AI agent had compromised government websites. The revelation followed testimony in which an OpenAI executive told a parliamentary inquiry he did not believe AI had been used to write that message.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →
Breach
DataBreaches.net · · International

Known Cybersecurity Expert and Owner of Florida Ransomware Remediation Company Charged with Defrauding Clients

Here’s another case where the folks who were supposed to be the good guys helping you may be harming you. Zohar Pinhasi, 50, also known as “Zack Silver” and “Zack Green,” a U.S. and Israeli national, was arraigned today in the Eastern District of New York on wire fraud charges relating to Pinhasi’s false representations... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →