The recent run of incidents on the cyberattack beat points to a single theme: trust in the security supply chain keeps being rewarded with betrayal. Attackers are choosing the path of least resistance, subverting third-party operators and human judgment rather than breaking strong defenses outright. And in one case, the security vendor itself becomes the threat, turning the promise of recovery into another way to monetize victim desperation.

Social engineering as the primary intrusion method

ASOS, the online fashion retailer, has linked its data breach to a social engineering attack and credential theft, as BleepingComputer reported, and is now sending updates to affected customers after hackers accessed some personal data. This is not a sophisticated zero-day exploit or a novel malware strain. It is a human being persuaded, or tricked, into handing over the keys. That pattern matters because it is repeatable and cheap. An attacker does not need to defeat encryption if an employee can be convinced to reset a password, approve an MFA prompt, or read out a one-time code.

For US technology companies, the ASOS case reinforces a reality that security teams have been slow to operationalize: identity is the new perimeter, and that perimeter runs through customer support desks, contractors, and third-party service providers. Social engineering is not a training problem alone. It is an architecture problem. If a single set of stolen credentials can unlock a meaningful tranche of personal data, the organization has concentrated risk in a way that no amount of phishing awareness training will fully mitigate. The US market implications are direct. Customers of breached retailers face identity theft risk, and the retailers face regulatory scrutiny and class-action exposure. The incident also underlines that credential theft remains the most reliable path into consumer data stores.

Third-party operators as single points of failure

A more structurally alarming incident surfaced in the same period: hackers hijacked Google domains after breaching country-code top-level domain registries, as BleepingComputer reported. The attackers obtained unauthorized HTTPS certificates for several Google domains and hijacked domains in the ccTLDs for Ghana, American Samoa, and Sierra Leone after compromising third-party operators and modifying authoritative DNS records.

This is not a story about Google being breached in the conventional sense. It is a story about the institutions that sit between domain owners and the global DNS. The ccTLD registries for smaller nations often rely on contracted third-party operators who may have weaker security postures than the global brands whose domains they manage. When those operators are compromised, authoritative DNS records can be rewritten, and traffic intended for legitimate destinations can be redirected. The issuance of unauthorized HTTPS certificates makes the hijack harder to detect because padlock indicators can still appear valid to end users.

The US technology sector depends on this DNS trust chain more than it acknowledges. American cloud providers, SaaS platforms, and e-commerce companies host services under global domain names, but the integrity of those names ultimately depends on registry operators and certificate authorities scattered across many jurisdictions. The incident is a reminder that trust in the DNS is not a property of the brand. It is a property of the weakest operator in the chain.

The security vendor as an additional risk

Perhaps the most corrosive development is the charge against the owner of ransomware remediation company MonsterCloud, as BleepingComputer reported. The owner allegedly defrauded ransomware victims by secretly paying their attackers for decryptors while claiming to use proprietary technology to recover encrypted data.

This is not a breach in the conventional sense, but it belongs on the cyberattack beat because it describes how the attack economy has expanded to include the firms that victims hire to respond. If the allegation is proven, the business model was not recovery. It was intermediation. The victim pays the recovery firm, the recovery firm pays the attacker, and the victim is told that a proprietary tool did the work. That outcome would distort the market in two ways. First, it would make victims more willing to pay ransoms because the payment is laundered through a vendor instead of made directly. Second, it would erode the credibility of legitimate incident response providers who genuinely try to avoid ransom payments.

For US companies, this is a governance problem. The incident response vendor sits inside the breach, with access to sensitive systems and sometimes to the decision-making process about whether to pay. If that vendor is secretly paying attackers, the victim's legal and regulatory position becomes far more complicated. Sanctions rules, disclosure obligations, and insurance claims can all be affected by whether a ransom was paid and to whom. The alleged conduct converts a security service into a liability.

The common thread: trust is the attack surface

Across all three stories, the attackers did not defeat the primary target. They defeated the trust relationships around it. At ASOS, the trust was in a credential holder who could be manipulated. At the ccTLD registries, the trust was in a third-party operator whose DNS records were modified. At MonsterCloud, the trust was in a remediation vendor that allegedly converted victim payments into attacker payments.

This is the pattern that should define how US technology companies think about cyberattacks in 2026. The perimeter is not a firewall. It is a network of human and organizational dependencies, each of which can be subverted. Defending the core is necessary but insufficient if the edges are porous. The attacks that matter are the ones that exploit the gap between what an organization controls and what it assumes it can trust.

What to watch

Three concrete indicators will show whether this pattern is being addressed. First, whether companies like ASOS disclose more detail about the social engineering vector, including whether credentials were reused or whether MFA was bypassed, because that determines whether the failure was procedural or architectural. Second, whether ccTLD operators and certificate authorities tighten third-party oversight, particularly for smaller jurisdictions whose registry infrastructure supports global brand domains. Third, whether US regulators or insurers take a harder line on incident response vendors that obscure ransom payments, because that would change the economics of the recovery market.

The stories above do not predict what happens next. They establish a baseline: in each case, the attack succeeded because trust was misplaced, not because a wall was breached. US technology companies that treat that as a one-off will keep relearning it.

More on this beat: Cybersecurity on TechManNews.

#cyber attacks#social engineering#DNS hijacking#ransomware#third-party risk#incident response

Newsletter

Get Tech News in Your Inbox

The latest AI, gadgets, software and startup stories from TechManNews, delivered every morning - free.