How the ASOS cyberattack happened, why impersonation attacks keep working, and how businesses and consumers can protect themselves.
The short answer
ASOS says an attacker got into an employee account by impersonating a trusted contact to obtain login credentials. There was no sign of an AI deepfake. A real person convinced a real employee they were someone else. Businesses can stop this by verifying who is asking and what they are asking for and not relying on how convincing the request sounds. Consumers can protect themselves by treating unexpected messages with suspicion, even ones that arrive through a trusted app.
What happened in the ASOS hack?
What happened in the ASOS hack?
On 6 October 2026, ASOS app users received a notification through the app claiming the company had been hacked. It was not a quiet breach found weeks later. It played out in front of customers on their own phones. ASOS confirmed it was investigating unauthorised activity involving third-party platforms it uses to communicate with customers, and later said basic personal information, such as names and contact details, may have been accessed. It does not believe payment card details or account passwords were affected.
How did the attacker get in?
How did the attacker get in?
Two days later, ASOS explained how it began. In its update to customers, under the heading “What’s happened”, it said:
“We discovered that an unauthorized party gained access to an ASOS employee account by impersonating a trusted contact to obtain log in credentials.”
Those credentials were then used to reach information on third-party platforms.
The attacker didn’t need to break encryption or compromise cloud infrastructure, and there is no sign they needed a deepfake. They persuaded a person that they were somebody that person trusted.
Why do impersonation attacks keep working?
They work because trust is easy to exploit and hard to verify. For years the industry has said humans are the weakest link. We say it in every awareness training and conference talk, and then we leave employees to make high-stakes identity decisions on instinct alone. That is how these attacks happen, and we are seeing them increasingly often: an employee, deceived by a legitimate sounding request, from someone with authority and a sense of urgency, with the right answers to the KYC questions.
ASOS is one of the biggest online retailers in the world. Whatever checks it had, they didn’t stop one convincing impersonation. That is not a verdict on the employee. Nobody can reliably tell a real colleague from a skilled impostor by gut feel. The question for every enterprise is what sits behind that moment of trust.
Can deepfake detection stop an attack like this?
No, it cannot. Deepfake detection tells you whether a voice is synthetic. It doesn’t tell you whether the person speaking is who they claim to be.
The industry is understandably focused on deepfakes: cloned voices, synthetic identities, real-time impersonation. These threats are serious and growing. But what if, as in the ASOS case, the attacker is a real human, using their own real voice, claiming to be an employee, a senior executive, an IT administrator or a trusted third party? A deepfake detection system may correctly decide the voice is genuine, and the person speaking may still be a criminal. It has established that the caller is human. It has not established that the caller is the human they claim to be.
That is the difference between spotting a threat and letting it walk straight through your perimeter.
Why is the corporate helpdesk such a common target?
Because a helpdesk is an identity gateway disguised as a support function. Someone has forgotten their password. Someone needs an MFA reset. A senior executive is locked out and in a hurry. An administrator asks for elevated privileges. These requests happen thousands of times a day in a large organisation, and each is a chance to undermine its identity and access management.
An attacker doesn’t have to break into the IAM platform. They can persuade someone with legitimate authority to reset the credentials that protect it. A well-prepared attacker may already know the employee’s name, department, manager, phone number and recent activity, which is enough to build a very plausible identity. They can sound calm, credible, frustrated or urgent, and lean on the helpdesk agent’s natural wish to solve the problem. AI can make this easier, but it isn’t required. A real person impersonating another real person is an extremely dangerous attack.
If identity can be established through persuasion rather than independent verification, the trust model is vulnerable.
How can businesses stop impersonation attacks?
By checking three things independently on every voice interaction that involves identity, access or authority: that the voice is real, that the person is the right person, and that the requested action is authorised. At ValidSoft, we call these three questions, and no single one is enough alone.
- REAL HUMAN? Is the voice genuine?
The first question is whether you’re dealing with an authentic human voice or an artificial, manipulated or replayed one. That means detecting:
- AI-generated and cloned speech
- Synthetic and manipulated audio
- Replay attacks
- Voice mimicry and impersonation techniques
- Other suspicious or automated telephony activity
This matters a great deal, but it’s only the first boundary. A real-human check doesn’t establish identity. A criminal can be 100% human and 100% unauthorised.
- RIGHT HUMAN? Is this the person they claim to be?
This is the control that changes the outcome. The question is no longer whether the voice is real, but whether the live speaker matches the verified identity of the person they say they are.
With passive voice biometric authentication, an enterprise can check a caller against their enrolled voice identity instead of relying on passwords, personal details, phone numbers or a convincing conversation. The person claiming to be the CFO has to be the CFO. The person asking for an MFA reset has to be the account holder. The administrator asking for privileged access has to be the verified administrator.
If the live caller is an impostor using their own genuine voice, a properly implemented voice biometric control can detect the mismatch. Real voice. Wrong identity. Access denied. Deepfake detection alone cannot deliver that capability, which is why the two must work together.
- RIGHT OUTCOME? Is the requested action authorised, protected and provable?
Even authenticating the right person isn’t the end of the job. A legitimate employee can be manipulated into requesting something they shouldn’t, a caller may be acting under pressure, and an authorised AI agent may try to go beyond its authority. A verified identity doesn’t mean unlimited permission. That takes:
- Transaction-specific, step-up authentication
- Verification of the requested action or intent
- Role-based permissions and delegated authority
- Cryptographic binding of verified identity to approved intent
- Tamper-evident records for auditability, accountability and non-repudiation
The goal is to be able to show who acted, under whose authority, what they were allowed to do, and what was approved.
Would a voice-verified helpdesk have stopped an attack like ASOS’s?
The answer is “Yes”, in a comparable helpdesk attack, it should have blocked it at the second check, before any credentials were issued. Picture someone contacting IT support and impersonating an employee, speaking naturally in their own voice.
REAL HUMAN? Pass. There’s no synthetic audio to detect, and a deepfake-only solution has no reason to turn the interaction away.
RIGHT HUMAN? The caller claims to be an enrolled employee, but the live voice doesn’t match that employee’s verified biometric identity. Fail. The claim can’t be substantiated, so the credential reset or access recovery is blocked or escalated for independent verification.
RIGHT OUTCOME? Even a correctly authenticated caller must meet the authorisation requirements for the change they’re asking for. A password reset, privileged-access change or MFA recovery shouldn’t go ahead just because someone asked convincingly.
Is deepfake detection enough on it’s own?
No. What have you secured if you can spot a synthetic voice but can’t identify an unauthorised human? Deploying deepfake detection without identity verification leaves a huge category of social engineering unprotected. And when an attack surface is unprotected it will be compromised.
It isn’t only a helpdesk problem. It reaches contact centres, financial services, healthcare, insurance, enterprise communications, privileged-access workflows and, increasingly, AI-agent interactions. The challenge is always the same. A voice is presented. An identity is claimed. An action is requested. Unless all three are independently checked, trust is incomplete.
But the enterprise help desk is the easiest problem to solve because the enterprise can mandate voice biometrics for all its staff, consultants or third-party access. That is the solution and is the only way to protect this critical vulnerability.
What does this mean as AI agents start acting for businesses?
It means the question changes from “is this a human?” to “is this the right actor, with the right authority?” Before long, the voice requesting access, approving a transaction or starting a workflow may legitimately belong to an AI system. Knowing a voice is synthetic won’t tell you whether it’s malicious, because it could belong to a perfectly legitimate, authorised enterprise agent. A genuine human voice could belong to an attacker.
Enterprises need to tell authentic humans, human impostors, malicious synthetic identities and authorised AI agents apart, then decide whether the requested action falls within that actor’s authority. That gives us an expanded model of trust: Real Human? Right Human? Right Agent? Right Outcome?
How does ValidSoft help prevent impersonation attacks?
ValidSoft’s voice security platform combines complementary capabilities for authenticity, identity and transaction-level assurance:
- Voice Verity® detects synthetic and manipulated voice threats and other suspicious audio characteristics in real time.
- ValidSoft’s VoiceID™ passive voice biometrics independently authenticates the claimed speaker, so an enterprise can tell the right human from an impostor using a perfectly genuine voice.
- VoiceMFA/See-Say® adds cryptographically secured, transaction-specific authentication and intent verification, giving stronger assurance and evidence for sensitive actions.
Together, they form a layered voice trust architecture that goes beyond deepfake detection. It’s designed for real-world enterprise telephony, including narrowband 8 kHz audio and above, and it answers the question that matters most to the business: can we trust the identity and authority behind the voice, and the action that follows?
What should consumers do after an attack like this?
Treat any unexpected message about your account with suspicion, even one that appears inside an app you trust. ASOS has told customers to disregard the unauthorised notification and not to click its link, and to watch for phishing messages claiming to be from ASOS that ask for password resets, payment details, refunds or order verification. More generally:
- Don’t click links in unexpected messages. Open the company’s app or website directly instead.
- If someone calls claiming to be from a company, hang up and call back on the official number.
- Be wary of urgency. Pressure to act quickly is the most common tool of a scam.
- Use a unique password for every account and turn on multi-factor authentication where it’s offered.
What should CEOs and CISOs ask their teams today?
Start with the helpdesk, one of the most overlooked attack surfaces in corporate security. Ask three simple questions.
Can we detect a deepfake? That’s the first check. If the answer is no, you have a significant vulnerability.
Can we independently verify that a genuine human caller is the employee they claim to be? If the answer is no, you have a material identity security gap, a critical vulnerability.
Can we make sure that even an authenticated caller can’t start an unauthorised credential reset, access change or sensitive transaction? If the answer is also no, you’re still exposed to attacks that can compromise enterprises.
Every enterprise must move to layered voice authentication across its workforce and helpdesk interactions, combining real-time deepfake detection, passive voice biometrics and strong authorisation controls.
The bottom line
The most effective attack on an enterprise can start with a simple act of impersonation: no elaborate malware, no sophisticated deepfake, just someone convincing an employee they are somebody else. And it lands on real people, including the customers who watched it appear on their phones.
A real human isn’t necessarily the right human.
A genuine voice isn’t proof of a genuine identity.
And an authenticated identity doesn’t automatically authorise an action.
Until enterprises consistently enforce those distinctions, the helpdesk will remain a critical vulnerability in any enterprise’s security defenses.
Real Human? Right Human? Right Agent? Right Outcome? ValidSoft knows.