‘While Asos may have contained the breach, we know from recent history that the ramifications of this attack are likely to have a long-lasting impact,’ says vice president
Online retailer Asos has become the latest firm to fall victim to a high-profile cyber attack.
However, unlike other recent incidents, the hackers appear to have gained access beyond customer databases to send notifications to thousands of customers urging the firm the engage with ransom demands.

And with experts warning that the breach could carry long-lasting financial and reputational consequences, the insurance industry’s role in providing proactive cyber protection is increasingly under the spotlight.
Luke Fardell, lead cyber analyst at Tokio Marine Kiln, explained that this type of activity may suggest an attacker has “gained access to multiple systems rather than a single database”.
“Maintaining complete control and security becomes increasingly challenging as more people, suppliers and applications require access to large data environments.
”A single compromised account, combined with techniques such as credential theft or multifactor authentication (MFA) bypass, can potentially lead to significant operational and reputational consequences,” he added.
Moreover, the risks to Asos customers extend beyond the initial data leaks. Zain Javed, director of strategic growth and cyber services at Citation Cyber, explained that the ”biggest risk [to Asos customers] now is that criminals capitalise on the publicity around the attack”.
“Customers should be particularly suspicious of emails or text messages saying things such as ‘your Asos account has been compromised’, ‘verify your account’, ‘reset your password’, ‘confirm your payment details’ or ‘claim compensation for the Asos breach’,” he added.
“We could also see fake delivery notifications, refund messages or discount vouchers designed to look as though they have come from Asos.”
Cyber resilience
At a corporate level, many feel that the attack has reinforced the need for adequate cyber cover. Claud Bilbao, vice president of underwriting and distribution at Cowbell, highlighted where many firms may be lacking protection.
Read: Are brokers struggling to sell cyber insurance in the soft market?
Read: Beazley launches new cyber endorsements to cover firms’ internal AI use
Explore more cyber-related content here, or discover other news stories here
He said: “The Asos breach is yet another example of why every digitally-oriented business needs to prioritise cyber resiliency. Basic continuity insurance isn’t sufficient – businesses need to do everything possible to prevent cyber attacks and not just rely on cyber insurance to pay out after an attack.
“While Asos may have contained the breach, we know from recent history that the ramifications of this attack are likely to have a long-lasting impact.
“Other brands need to heed this warning, because they are only as resilient as the technology they depend on. Customer data now moves across a web of external systems and suppliers, creating potential weak points that can sit outside a company’s direct control. Businesses need to know where those exposures are before an attacker finds them.”

He graduated in 2017 from the University of Manchester with a degree in Geology. He spent the first part of his career working in consulting and tech, spending time at Citibank as a data analyst, before working as an analytics engineer with clients in the retail, technology, manufacturing and financial services sectors.View full Profile











































No comments yet