Jessica Entwistle
October 8 2026
Today's stories highlight how established attack techniques are evolving alongside newer technology risks. A UK retail breach reminds us that customer data remains a primary target, whilst infrastructure-level domain hijacking shows attackers are finding creative ways to bypass trust signals. Meanwhile, the emergence of AI-targeted phishing and continued arrests of prolific threat actors demonstrate both the changing attack surface and ongoing law enforcement pressure on cybercriminal groups.
The National Cyber Security Centre has published a notice confirming that ASOS, the UK-based online fashion retailer, is investigating a cyber incident in which some customer personal information may have been accessed. The NCSC statement, published on 6 October, provides limited detail but confirms the incident is under investigation and that ASOS is working to understand the scope of data potentially affected. The retailer serves millions of UK customers and holds typical e-commerce data including names, addresses, payment card details and order histories. ASOS has not yet confirmed the nature of the attack, the volume of records involved, or whether payment information was compromised.
For UK businesses, particularly those in retail, this incident is a reminder that customer-facing platforms remain high-value targets. E-commerce organisations hold datasets that are operationally sensitive and commercially valuable to attackers, whether for fraud, identity theft or onward sale. The NCSC's public acknowledgement suggests the incident meets a threshold of significance, and organisations in similar sectors should treat this as a prompt to review their own detection, containment and customer notification processes. Breaches of this kind often result in regulatory scrutiny, reputational impact and operational disruption during investigation and remediation.
For UK businesses handling customer data, this is a prompt to review incident response readiness, particularly the speed and clarity of internal escalation, external reporting to the ICO, and customer communication. Ensure you have a tested process for identifying what data has been accessed, how quickly you can contain further exposure, and who owns the decision to notify customers and regulators.
Source: NCSC UK
The Register reports that attackers compromised three country-code top-level domain (ccTLD) registries and obtained unauthorised HTTPS certificates for several Google domains. The affected domains were .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa). Google confirmed on 6 October that its own systems were not breached, but the registry-level compromise allowed attackers to manipulate DNS records and request valid certificates from trusted certificate authorities. This means an attacker could potentially impersonate legitimate Google services over encrypted connections without triggering the usual browser certificate warnings that users rely on to verify authenticity.
This incident matters because it undermines one of the foundational trust mechanisms of the internet. HTTPS certificates are intended to prove that a website is genuinely operated by the organisation it claims to represent. By compromising the domain registries themselves, attackers bypassed the usual certificate issuance controls and obtained certificates that would appear legitimate to browsers and users. For UK organisations, this highlights the risk that trust infrastructure can be subverted at levels outside your direct control. It also reinforces the importance of defence in depth, including monitoring for unexpected certificate issuance, implementing certificate transparency logging, and ensuring that authentication and access controls do not rely solely on the presence of a valid certificate.
For many organisations, this is a reminder that certificate-based trust alone is not sufficient. Review whether you monitor certificate transparency logs for your own domains, whether your security controls would detect an unexpected certificate being issued in your name, and whether your users are trained to recognise other indicators of phishing beyond the presence of a padlock icon.
Source: The Register
Infosecurity Magazine reports that Barracuda has identified phishing emails specifically designed to manipulate both human users and AI assistants. The emails contain hidden prompt injection attacks, which are instructions embedded in the message content intended to influence the behaviour of AI tools that process or summarise the email. For example, an AI assistant reading the email on behalf of a user might be instructed to ignore security warnings, approve a transaction, or extract and forward sensitive information. This represents a new variation on phishing that exploits the growing use of AI-powered email filtering, summarisation and response tools in enterprise environments.
For UK businesses, this development is significant because many organisations are now deploying or evaluating AI assistants to help manage email workflows, summarise messages, draft responses or automate routine tasks. These tools are designed to save time and improve productivity, but they also introduce a new attack surface. If an AI assistant can be manipulated by carefully crafted input, it may take actions that a human user would not, or it may present information in a way that makes malicious content appear legitimate. This is particularly concerning in environments where AI tools have access to sensitive data, can initiate transactions, or are trusted to make decisions on behalf of users.
For UK businesses deploying AI assistants, this is a prompt to review what permissions and access these tools have, how they handle untrusted input, and whether your security controls account for the possibility that AI-generated summaries or recommendations may themselves be influenced by attacker-controlled content. Ensure there is clear ownership of AI tool governance and that users understand the limitations of automated decision-making.
Source: Infosecurity Magazine
Krebs on Security reports that a teenager from Amman, Jordan, suspected of leading the prolific data theft and extortion group ShinyHunters, has been detained and is reportedly cooperating with the FBI to identify other members of the hacking gang. The suspect, who uses the handle "Rey", was detained as ShinyHunters was in the process of extorting a business unit recently divested by Boeing. ShinyHunters has been linked to numerous high-profile data breaches over recent years, targeting organisations across multiple sectors and geographies. The group is known for stealing large volumes of customer and corporate data, then attempting to extort the victim organisation or selling the data on criminal forums.
For UK businesses, this development is a reminder that law enforcement pressure on cybercriminal groups is increasing, but also that these groups remain active and capable of targeting large, well-resourced organisations. ShinyHunters has demonstrated a consistent pattern of targeting customer databases, cloud storage and third-party services, often exploiting misconfigurations, weak credentials or unpatched vulnerabilities. The fact that the suspect was detained during an active extortion attempt suggests that investigations are becoming more coordinated and responsive, but it also highlights that organisations may find themselves in the middle of an ongoing law enforcement operation during an incident.
For UK businesses, this is a prompt to review your approach to extortion and ransomware incidents, including whether you have a clear process for engaging with law enforcement, how you handle communications with attackers, and whether your incident response plan accounts for the possibility that an attacker may be under investigation or surveillance. Ensure your legal, communications and technical teams understand their respective roles during an extortion event.
Source: Krebs on Security
Today's stories illustrate that effective security comes from understanding both the fundamentals and the emerging edges of risk. Whether it's protecting customer data, monitoring trust infrastructure, governing new AI capabilities or preparing for extortion scenarios, the organisations that respond well are those that have already established clear ownership, tested their processes, and built the habits of review and escalation before an incident occurs. Good security is not about predicting every possible attack, but about having the discipline and clarity to respond effectively when something does go wrong.