ASOS Confirms Unauthorised Push Notification, Possible Contact-Data Exposure

Stephanie Adlam
5 Min Read
An ASOS phone becomes an orange megaphone sending an unauthorised message; text ASOS ALERT and TRUST THE APP?
A familiar app notification channel can carry a message the retailer did not authorise.

ASOS has confirmed that an unauthorised notification reached customers at around 10am on October 6. The retailer is investigating activity involving third-party platforms used for customer communications and says names and contact details may have been accessed. Its current assessment is that payment-card information and account passwords were not affected.

The immediate instruction is to ignore the notification and any suspicious link. The UK’s National Cyber Security Centre (NCSC) goes further on the audience: ASOS customers should treat themselves as potentially affected even if they never received the alert.

A shopping notification became the incident

This was not simply a stranger sending an email with a copied retailer logo. ASOS acknowledged an unauthorised message through its customer-notification channel. That distinction matters: people normally associate an app’s notifications with order updates, offers and other messages authorised by the business.

The company’s regulatory statement describes unauthorised activity involving external communication platforms. ASOS restricted access to the notification platforms and brought in internal and external specialists, alongside the relevant authorities. The statement does not identify the initial access route or establish which credentials or permissions were abused.

Restricting that channel did not mean shutting down shopping. ASOS said its website and app were operating normally, with no current disruption to operations. Those statements describe different systems and can both be true: a business can contain an unauthorised communications channel while continuing to accept orders.

What the alert establishes about customer data

ASOS says basic personal information, including names and contact details, may have been accessed. That is a qualified finding during an investigation. Its statement does not provide a confirmed number of affected customers or an inventory of copied records.

The same qualification applies to passwords and cards. The company said it did not believe those were impacted; this is its assessment, not an independent guarantee that every customer account is safe. Neither the appearance of the notification nor the company’s statement proves that a customer’s phone has been infected.

The important boundary is between the ability to send a message and the ability to access other data. An unauthorised notification demonstrates misuse of the communication channel. It does not, by itself, establish control of every database behind the retailer. Conversely, a working app does not settle whether names or contact details were exposed.

No notification does not mean no exposure

The NCSC’s October 6 alert tells ASOS customers to assume they are affected even without receiving the push notification. This is precautionary guidance, rather than evidence that every account’s data was copied. An alert’s recipient list is not a reliable customer-data exposure test.

Names and contact details can make a later message more convincing. A follow-up might refer to the real incident and ask someone to verify an account or payment. That is a risk to watch for, not a follow-up campaign established by the evidence available here.

Open ASOS independently to check account information or contact support; do not use a suspicious notification as the route there. Watch for messages arriving later, and avoid suspicious links in push notifications, email or texts. The Manchester Airport breach response explains a related decision: knowledge of a genuine customer relationship does not make a new payment request legitimate.

The useful lesson from this incident is specific: a message can arrive through a service you really use and still be unauthorised. The confirmed event is the notification-channel misuse; the possible contact-data exposure and the company’s password/card assessment should stay distinct as the investigation develops.

References

  1. ASOS plc. Update regarding cyber incident. RNS 8604X, October 6, 2026.
  2. National Cyber Security Centre. Incident affecting ASOS customers. October 6, 2026; accessed October 7, 2026.
Share This Article
Follow:
Stephanie is our wordsmith, transforming technical research into engaging content that resonates with users. Her expertise in cybercrime prevention and online safety ensures that Gridinsoft's advice is accessible to everyone—whether they’re tech-savvy or not.
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?