- Cybersecurity Docket
- Posts
- Asos Investigating Potential Hack
Asos Investigating Potential Hack
Plus, Georgia Power is investigating an unauthorized data breach

SPONSORED BY
Good morning, I’m Jaclyn Jaeger! Here’s the latest in cybersecurity news.

People
Thomas Loeser has joined law firm Hausfeld as a partner, based in in the firm’s San Francisco office, and as a member of its Technology & Data Breach practice. Loeser joins Hausfeld from Cotchett Pitre & McCarthy, where he was a partner. He brings more than 27 years of legal experience to Hausfeld, including nearly two decades leading complex consumer and data breach and privacy class actions and nearly five years as a federal prosecutor in the U.S. Attorney’s Office in Los Angeles, where he served in the Cyber and Intellectual Property Crimes Section.

Clips ✂️
Asos customers receive ‘hack’ notification threatening leak
Asos is investigating after users of its mobile app received a notification claiming hackers had “fully compromised” the online fashion retailer’s data.
The value of Asos’s shares on the London Stock Exchange dived almost 10% after thousands of customers received a notification titled “Asos hacked” with a link that sent them to the Telegram messaging service.
The website and app appeared to be continuing to operate on Tuesday morning and it is understood that Asos is still investigating whether any hack has taken place.
The message sent out to customers said: “Dear Asos DPO [data protection officer] and IT, we have fully compromised the Snowflake instance.”
Snowflake is a cloud platform used to store, process and analyse data including transactions and demographic information such as clothing sizes and body measurements. It also enables push notifications to clients’ phones.
👉 Key takeaway: Asos customers were directed to a telegram channel operated by a cyber gang, unfamiliar to cyber experts, called the Xuanye group, the Guardian reported.
“It’s not unusual to see new groups emerge, and often they wait until they have what they see as a significant opportunity before they announce themselves so as to enter the ecosystem with ‘credibility’,” Aiden Sinnot, principal threat researcher at cybersecurity firm Sophos, told the Guardian.
Georgia Power customer data may have been accessed in data breach, company says
Georgia Power is investigating an unauthorized data breach that may have accessed some of its customers' information.
In an email sent to some Georgia Power customers, the company said that it detected unauthorized activity by a third party on some accounts recently.
The company said that the unauthorized party had access to some information connected to accounts, including names, addresses, phone numbers, emails, and the last four digits of social security numbers. The breach did not allow the third party to see information such as bank account, payment card or driver's license numbers, Georgia Power said.
"Upon detection, we took immediate steps to stop the activity. We have engaged law enforcement and are conducting a thorough investigation," the email read in part.
Georgia Power does not believe the unauthorized access to accounts is still going. The identity of the third party behind the data breach has not been released.
EXCLUSIVE: Accenture contractor removed from FBI following damaging data breach, sources say
The Federal Bureau of Investigation removed an Accenture contractor on Monday over their role in a damaging data breach that exposed sensitive personal details of thousands of bureau employees, two sources familiar with the matter told Reuters.
The development comes as the FBI is still trying to ascertain the ramifications of the breach, which some former bureau officials have described as a major blow to the organization's operational security.
In a statement to Reuters, a senior FBI official confirmed that an unidentified contractor had failed to properly update — or patch — the system they were responsible for.
"To date, our review has determined that the incident occurred as the result of a security failure of a platform managed by a third-party organization — after a contractor failed to implement a security patch explicitly issued to secure the platform," FBI cyber chief Brett Leatherman said in the statement. "As such, the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce."
👉 While the FBI did not identify the platform or third-party organization, sources familiar with the matter told Reuters that the platform was Oracle's PeopleSoft, and that the third-party organization was Accenture.
Police Urge Passkey Use After Surge in Cybercrime Profits
The UK’s Report Fraud service has launched a new public awareness campaign urging internet users to switch to passkeys, after revealing a major increase in sums stolen from victims.
The fraud reporting service said that cybercrime linked to email and social media hacking netted scammers £6.3m ($8.3m) in 2025/6, up from £1.2m ($1.6m) the year previously.
The number of reports for this type of account takeover increased by a third (34%) over the same period.
Report Fraud didn’t go into much detail about the tactics cybercriminals use to monetize their access to victims’ accounts, aside from claiming that one of the most common is impersonating family and friends.
Impersonation can come in various forms, but one of the most popular techniques to trick victims into sending funds is to impersonate the account owner and pretend to be in trouble.
👉 Key quotes: In an official press statement, Chief Superintendent Amanda Wolf, head of Report Fraud Operations, said, “Switching to passkeys and enabling two-step verification adds a strong extra layer of security and makes it much harder for criminals to gain access to your accounts.”
Jonathon Ellison, director for National Resilience at the National Cyber Security Center (NCSC), added, “We know that most cyber harm to individuals starts with criminals attempting to steal login details, which is why we strongly encourage users to choose passkeys where they are available across digital services and use two-step verification where they aren’t. Passkeys are simpler, faster and more secure to use, raising our national resilience against phishing attacks whilst leaving password headaches behind.”
Ransomware Affiliate Double-Crosses Operator to Steal Victim Funds
A Russian-speaking cybercriminal betrayed his ransomware-as-a-service (RaaS) partners to make off with funds extorted from over two dozen global victims, CloudSEK has revealed.
The threat intelligence specialist detailed the double cross in a new report, The Gentlemen Files, published on October 5.
They researchers found two exposed servers managed by “Azazel” – an affiliate of The Gentlemen RaaS outfit – containing several terabytes of data stolen from logistics, insurance, pharmaceutical, AI, medical device, and government victims across six countries.
“Azazel was not running a standard affiliate playbook,” the report revealed.
“He built and operated his own independent leak site under the brand Leakned, publishing victim data and collecting extortion proceeds without routing them through the Gentlemen program, a betrayal of the RaaS operator running alongside the betrayal of victims.”
Ukraine grocery chain ATB confirms cyberattack as hackers threaten to leak data
Ukraine’s largest grocery store chain, ATB, confirmed Monday that it was hit by a cyberattack after hackers posted an extortion demand on its website.
The hacker group DataSuckers claimed responsibility for the attack and demanded $400,000, threatening to publish data it claimed to have stolen from millions of ATB customers. A countdown timer for the ransom demand appeared on the retailer’s website but was later removed. The website was unavailable at the time of writing.
ATB denied that customer data had been compromised. The company temporarily took some online services offline for what it described as technical maintenance.
“The temporary message displayed on the website did not affect the security of your data,” ATB said. “The website remains fully under ATB’s control, and all information is securely protected.”
In response to ATB’s statement, the hackers published samples of the allegedly stolen data on their Telegram channel. They said they would not leak the entire database but would instead sell it “for a substantial amount.”

SPONSORED BY
Incident Response Forum West 2026 is set for Tuesday, October 13, 2026, at the extraordinary Waldorf Astoria Beverly Hills! It will also be available for attendees to view live online.

Incident Response Forum is the only conference of its kind, bringing together hundreds of cybersecurity and incident response attorneys, in-house counsel and compliance executives, and other top professionals in the field. It is focused solely on the field of Incident Response – the work that begins after a data breach that has quickly become the fastest growing practice area at law firms and consulting firms – and is geared specifically for the legal and compliance professionals who have emerged as critical players during the aftermath of a data security incident.
Join us in person or tune in virtually to hear from over 40 luminaries in the incident response field—including senior officials from the DOJ and lawyers and consultants from the best firms and in the world. The full Agenda is here.
👉 In-person registration fee is $1,500; virtual registration fee is $750. Please register here:
In-person attendance: UPDATE606W25
Virtual attendance: UPDATE606V25


