Why Today's Breaches Start With Trusted Accounts

Photo: BleepingComputer

Article

Why Today's Breaches Start With Trusted Accounts

ASOS, Nikkei, and Denmark's national database show attackers are winning through trusted channels rather than perimeter walls, with real costs for US firms.

NagiOctober 11, 20264 min read

The common thread in this week's breach disclosures is not the volume of records or the novelty of the intrusion technique. It is that attackers repeatedly operated through channels their targets had already deemed trusted: an app's own push system, employees' email accounts, a national database of citizen records. The pattern is access abuse, and it carries direct consequences for US technology companies that build and rely on the same architecture.

The App Becomes the Attack Surface

UK fashion retailer ASOS confirmed a data breach on Tuesday after hackers sent unauthorized push notifications through its mobile app, as BleepingComputer reported. The messages were not a side effect; they were the visible symptom of an intrusion in which the attackers claimed to have stolen customer data from the company's Snowflake environment. That pairing matters. Push notifications are normally a marketing and service channel, treated as a low-risk utility. When an adversary can send through it, the app stops being a storefront and becomes a broadcast tool for the attacker's own claims. For US technology companies, the lesson is that notification infrastructure, API keys, and third-party data platforms are as sensitive as the customer database itself. A compromised push credential does not just enable spam; it undermines the authenticity of every future message the brand sends. and it gives an intruder a megaphone aimed at the entire installed base.

Email Remains the Silent Foothold

Over the weekend, Japanese publishing giant Nikkei disclosed that unknown attackers breached two employee email accounts and used one to send thousands of phishing emails, as BleepingComputer reported. Nothing about this is exotic. Email accounts are the keys to password resets, vendor communications, internal documents, and downstream contacts. The damage compounds because a compromised corporate mailbox is trusted by recipients in a way that a spoofed domain never is. US technology companies are especially exposed because so much business runs through email-based workflows: contract approvals, cloud billing notices, and partner onboarding. The Nikkei case illustrates a familiar sequence, where a small number of accounts produces a large downstream effect. The thousands of phishing messages are the attacker's leverage, not the endpoint. Each recipient now faces a message that genuinely originated from a legitimate corporate address, which is exactly the condition that defeats conventional filtering advice.

Government Databases Are Not Just Government Problems

Denmark's government said a breach of names, addresses, and state-issued ID numbers affects 8 million people, including people living abroad and the deceased, according to TechCrunch. Two features distinguish this from a typical corporate incident. First, the affected population exceeds the country's living resident base, which means the record set outlives the individuals in it. Second, the data elements are identity anchors rather than preferences or purchase histories. State-issued ID numbers are used to verify who someone is across banking, healthcare, and government services.

For US technology companies, that has a practical edge. Many US firms process identity data for customers, employees, and partners who hold foreign credentials. A breach of a national ID registry abroad raises the risk that a US platform's own verification checks can be defeated with authentic-looking data. It also increases the compliance surface, because data originating in one jurisdiction flows through US cloud and analytics systems. The deceased-inclusive scope is a reminder that identity data has a retention problem: records kept for legitimate administrative reasons become long-term liabilities when they are compromised.

Credentials, Not Walls, Define the Perimeter

The three cases share a structure. Attackers did not need to defeat a hardened external boundary. They needed to reach a system that already had permission to act. ASOS's push channel had permission to reach customers. Nikkei's email accounts had permission to reach internal and external contacts. Denmark's database had permission to hold identity records on an entire population. This is the recurring theme in breach disclosures, and it explains why traditional perimeter spending has limited returns. US technology companies have spent years consolidating identity into single sign-on and federating access across cloud providers. That consolidation improves operations but also concentrates risk: one set of valid credentials can reach a broad set of systems.

What This Means for US Companies and Consumers

US technology firms face three concrete pressures. The first is disclosure credibility. When an attacker can send notifications through a company's own app, customers have no reliable way to distinguish an official message from an intruder's claim. Trust in the channel degrades independently of the data loss. The second is third-party platform risk. The ASOS incident points to a Snowflake environment, and similar cloud data platforms are widely used by US companies. Contractual assurances do not transfer the operational burden; the customer still owns the configuration and the credentials. The third is identity-data exposure. Denmark's 8 million affected people show how far a single database breach can reach, and US consumers whose records sit in similar systems abroad inherit that exposure.

For US consumers, the practical effect is a rising volume of messages that look legitimate because they originate from legitimate infrastructure. That raises the value of out-of-band verification and lowers the value of channel-based trust signals. It also means breach notifications may arrive after the attacker has already used the compromised channel, which is what happened at ASOS.

What to Watch

Watch whether ASOS discloses the scope of customer data taken from its Snowflake environment and whether the unauthorized push mechanism is closed without disrupting normal notifications. Watch whether Nikkei's disclosure expands beyond the two employee accounts, and whether the phishing wave produces secondary breaches at recipient organizations. Watch whether Denmark's government revises retention or ID-number practices for deceased and overseas records, which would set a precedent other national registries may follow. Watch, more broadly, for breach reports that describe misuse of already-authorized channels rather than perimeter compromise. That framing, more than any single incident, indicates where defenders should be spending in the months ahead.

Sources: BleepingComputer (ASOS, Nikkei); TechCrunch (Danish government database).

More on this beat: Cybersecurity on TechManNews.

#data breaches#identity theft#cloud security#phishing#cybersecurity

Newsletter

Get Tech News in Your Inbox

The latest AI, gadgets, software and startup stories from TechManNews, delivered every morning - free.