
Does AI mean the end of MFA?
“The report of my death was an exaggeration.”


What would you say to a company’s customers if you broke in and took control of an agentic AI used for sending targeted marketing messages intended to drum up online sales?
Would you use the AI to predict the product that customers are least likely to want, and spam them with mysterious ads insisting how much they need those items, perhaps to belittle and embarrass the company you just breached?
Would you advertise bizarre and non-existent products such as perpetual motion machines or self-laundering trousers in an attempt at showing you have an ironic sense of humor?
Well, the multi billion-dollar British fast-fashion company ASOS just found out what a cybergang calling itself xuanyewengateway chose to do.
Briefly explained, it looks as though the attackers broke into a massive ASOS marketing database full of customer data.
Although the database runs on a combination of the latest automation tools from Simon AI and Snowflake, the intrusion itself seems to have been achieved by the good old social engineering trick of persuading someone at ASOS, presumably in IT support, to reset access to a legitimate user’s account, but to give the new access credentials to the criminals instead.
In ASOS’s own words, the attackers succeeed by “impersonating a trusted contact to obtain [login] credentials.”
Intrusions of this sort can be hard to detect proactively, because the illegal access happens under the account of someone who’s supposed to be there.
Fortunately, it seems that the breached marketing tools didn’t have access to actual transaction and payment details, or to passwords and authentication data, or to identity-related verification information such as licenses or passports․․․
․․․but the database did include customers’ personal data such as names, home addresses, phone numbers, ASOS customer numbers, dates of birth, and search histories.
As you can probably imagine, by knowing who you are, where you live, how to contact you, your age, and what searches you’ve done for ASOS products, the company can use AI-based techniques to mine that data efficiently.
That means they can create marketing campaigns at scale that are nevetheless tightly tailored for each individual recipient.
Some people, of course, wouldn’t be happy to hand over this sort of marketing power to a fast-fashion retailer, but many would – and if you’re one of them, you may well have installed the ASOS app, and found the company’s offers useful.
In theory, there’s nothing wrong with that, as long the company collecting the data looks after it with the care you might expect (and with the care that they probably claimed they would take when you signed up for the service).
But if you were to give a cybercriminal access to an targeted marketing system of this sort, you can just imagine the sort of mass-messaging mayhem that might ensue:
This gang, it seems, took a different tack.
They used ASOS’s messaging system to tell the company’s own Data Protection Officer (DPO) and IT department about the intrusion – in a crushingly embarrassing way.
They spammed out exactly the same smug but disconcerting message to all (or at least very many of) the company’s customers:
ASOS HACKED Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.
The message also linked to a Telegram account to make contact with xuanyewengateway.
What a way to get the attention of the company, its customers, and the media!

Why not ask how SolCyber can help you do cybersecurity in the most human-friendly way? Don’t get stuck behind an ever-expanding convoy of security tools that leave you at the whim of policies and procedures that are dictated by the tools, even though they don’t suit your IT team, your colleagues, or your customers!
Paul Ducklin is a respected expert with more than 30 years of experience as a programmer, reverser, researcher and educator in the cybersecurity industry. Duck, as he is known, is also a globally respected writer, presenter and podcaster with an unmatched knack for explaining even the most complex technical issues in plain English. Read, learn, enjoy!

“The report of my death was an exaggeration.”

Why does it sometimes sound as though no one ever thought of using AI in cybersecurity until now?

“All without people’s knowledge, let alone authorization.!

By subscribing you agree to our Privacy Policy and provide consent to receive updates from our company.






