eDiscovery

How to work out what happened, which people may be affected, and what you can reasonably say while an investigation is still under way.
By Jonathan Krause | Founder and Managing Director, Forensic Control | 9th October 2026
On 6 October, ASOS confirmed that an unauthorised notification had been sent to its customers and that names and contact details may have been accessed. For anyone responsible for customer data, the immediate question is familiar: how do you find out what actually happened?
You need evidence to establish what information was exposed and where the gaps are before deciding what to tell customers and the regulator.
ASOS’s statement said it was investigating unauthorised activity involving third-party platforms used to communicate with customers. It had restricted access to the notification platforms and was working with specialist advisers and the relevant authorities. The company said it did not believe payment card information or account passwords had been affected.
That is the extent of the company’s initial public account. It doesn’t establish how the incident happened or how many people’s details were accessed. I wouldn’t draw conclusions about either from a notification or an attacker’s claim.
Before founding Forensic Control, I investigated cybercrime at New Scotland Yard. One principle from that work applies here: you need to be able to explain where your evidence came from and what has happened to it since it was collected.
During a live incident, you also need to stop further access. Preserve evidence alongside containment wherever possible. If an account needs to be disabled or its credentials changed urgently, do that and record the action. Waiting for a perfect evidence collection while an attacker still has access can make the situation worse.
Rebuilding a system or deleting an account can destroy useful evidence, depending on how the platform stores it. Logs can also expire while teams are busy restoring services. I’d include these steps in the initial response:
1. Ask the suppliers involved to preserve relevant logs and records. Identify the affected accounts and a time window, including activity before the incident was discovered. Ask what records exist, how long they are retained and how to obtain them.
2. Collect the records available to you. These may include sign-ins, administrative changes, queries, exports and downloads. Keep the original exports securely, record their source and collection time, and analyse copies.
3. Keep a response log. Record who changed what, when and why, including password resets, session revocations and changes made by suppliers. This helps separate the response team’s activity from the suspected intrusion.
Start by building a timeline. Which account was used? What access did it have at the time? Which actions were recorded? Then compare that activity with the data held in the affected systems.
Be careful with the conclusions. An account having permission to read a database doesn’t prove that every record was read. Equally, finding no export event doesn’t prove that nothing was taken. The available records may be incomplete or may not capture every way data can leave a system.
A useful investigation report distinguishes confirmed access from possible exposure and explains any limits in the evidence. If the records support a precise list of affected people, produce it. If they don’t, say what remains uncertain and how that affects your assessment.
If you have an exported dataset or a copy of material allegedly taken, eDiscovery methods can help with the review. That means organising the material, making it searchable, identifying personal information and matching it to the people concerned.
The content needs checking too. Does it match your records? What dates does it cover? Are there duplicates? Does it contain information that creates a particular risk for someone, such as identity documents or financial details?
A published sample may help establish that someone has obtained particular records. It won’t necessarily show everything they hold. The review needs to be considered alongside the technical evidence, with any differences investigated.
If leaked material needs collecting, arrange authorised collection and secure handling. Don’t circulate it around the business or upload it to an unapproved tool for a quick summary. You could expose the same people’s information again.
Under UK GDPR, a controller must report a personal data breach to the ICO unless it is unlikely to risk people’s rights and freedoms. For a notifiable breach, report without undue delay and within 72 hours of awareness where feasible. You can supply details in stages; an incomplete investigation is no reason to wait.
Affected individuals must be informed without undue delay where the breach is likely to create a high risk to them. Record all personal data breaches and your reporting decisions. The ICO’s breach reporting guidance explains the requirements.
Use the facts available at the time and update your assessment as the evidence develops. Someone whose records were accessed without permission may be affected even if you cannot prove that a copy was downloaded.
Customers may ask what information you hold about them or make subject access requests. Complaints, insurer enquiries and legal proceedings may also follow. Keep the evidence and your decisions organised so you can answer consistently as the investigation progresses.
If you hold customer data in cloud services, check your audit logs now. Find out what is recorded, how far back it goes and who can export it. Ask your suppliers the same questions. That is a manageable job before an incident, and a much harder one during it.
It starts when the controller becomes aware of a personal data breach, rather than when the investigation finishes. For a notifiable breach, report without undue delay and within 72 hours where feasible. Further information can follow in stages.
Assess the likely harm in context. Consider targeted phishing or fraud, other information exposed and the people affected. Direct notification is required where the likely risk is high. Document the assessment and revisit it as facts change.
Sometimes they support a detailed answer. In other cases, they show access to an account or dataset without identifying every record read or copied. Check what each log records and its coverage before drawing conclusions. A missing event can reflect a logging gap.
Preserve relevant authentication, administrative, query, export and download records, together with supplier records and your own response log. Record where each item came from and when it was collected. Coordinate collection with urgent containment.
Yes, if you have the authority, skills and secure systems to handle it. Large datasets can be difficult to search and match to individuals. Restrict access, keep the original material and document the review. Get specialist support where the scale or sensitivity warrants it.
Safeguard your business with our expert cyber security solutions. Whether you require digital forensics, penetration testing or proactive security assessments, our team is ready to assist. Contact us today to discuss your security needs and take the first step towards a more secure future.