What is confirmed
A trusted notification channel carried an unauthorised message
ASOS says some customers received an unauthorised push notification on 6 October. It is investigating activity involving third-party platforms used to communicate with customers and has restricted access to its notification platforms. ASOS says names and contact details may have been accessed, while it does not currently believe payment-card details or account passwords were affected. Its website and app remained available.
Do not repeat the attacker's claim as a finding
People first
Watch for follow-up impersonation
The UK NCSC advises ASOS customers to assume they may be affected even if they did not receive the push notification. It recommends watching for suspicious communications, which can arrive later, and avoiding unexpected links in notifications, email or messages. Names and contact details can make a fraudulent follow-up sound plausible even without payment information.
ASOS says it is not currently asking customers to change their ASOS password. Customers should use the app or website reached independently to check any new instruction rather than following a link in an alarming message.
For defenders
Treat communications tooling as a privileged system
- 1
Map the send path. Identify who and what can compose, approve and send customer push messages, including third-party integrations and service accounts.
- 2
Preserve evidence. Retain provider audit logs, campaign history, API activity, token use and changes to audience lists before rotating access.
- 3
Constrain future sends. Review least privilege, approval requirements, token scope, emergency disablement and independent monitoring for unusually broad or out-of-pattern sends.
- 4
Keep customer guidance current. Provide one official place for updates and distinguish confirmed exposure from precautionary advice as the investigation develops.
Defender note
Availability is not the whole measure of recovery
- A working storefront can coexist with a compromised communications channel.
- Separate notification-system access, customer-data access and the attacker's extortion claims in the incident timeline.
- Plan for secondary phishing that may exploit the publicity surrounding the incident even without stolen ASOS data.