ASOS Confirms New Cyber Incident After Attackers Hijack Customer Notifications

ASOS confirmed a new cyber incident involving third-party communication platforms after attackers hijacked customer notifications and potentially accessed names and contact details.
ASOS logo over abstract blue cyber background.

ASOS is investigating a new cyber incident after an unauthorized party gained access to third-party platforms used by the retailer to communicate with customers, allowing attackers to send a threatening push notification through ASOS’s own customer channels.

The British online fashion retailer confirmed on Oct. 6 that an unauthorized customer notification was sent at approximately 10 a.m. ASOS said basic personal information, including customer names and contact details, may have been accessed during the incident.

The company does not currently believe payment-card information or account passwords were affected. ASOS restricted access to the affected notification platforms and is working with internal and external security specialists and relevant authorities.

The incident is separate from an ASOS breach disclosed in August, when attackers used credentials obtained outside the company to access individual customer accounts. BreachNews previously reported that ASOS blocked affected accounts and forced password resets after detecting the credential-based attacks in July.

Attackers turned ASOS notifications into an extortion channel

The Oct. 6 incident became public after ASOS customers received an unauthorized push notification through the retailer’s app claiming the company had been hacked.

The notification alleged that attackers had compromised an ASOS Snowflake environment and threatened to leak data unless the company engaged with them. It also directed recipients to an external communication channel.

BreachNews is not reproducing or linking to the contact information included in the unauthorized notification.

The ability to distribute a message through an official ASOS customer channel demonstrates that an unauthorized party obtained access to at least part of the infrastructure used to communicate with customers. It does not, however, independently establish the attacker’s broader claim of compromising ASOS’s Snowflake environment.

ASOS has not confirmed that its Snowflake environment was compromised. In its public statement, the company instead described the incident as unauthorized activity involving third-party platforms used to communicate with customers.

The identity of the party responsible also remains unclear. The notification was associated with a previously little-known group identity, but there is currently insufficient independently verified information about the operation or its history to establish a broader attribution.

Names and contact details may have been accessed

ASOS acknowledged that the intrusion may extend beyond the unauthorized notification itself.

According to the company, basic personal information including names and contact details may have been accessed. ASOS said it does not currently believe payment-card information or account passwords were affected.

The company has not disclosed how many customers may have had information accessed or identified the specific third-party platforms involved.

ASOS said its website and app continue to operate normally and that the incident has not caused any current disruption to its operations. The company also confirmed that it carries cybersecurity insurance, including business continuity coverage, but said it is too early to determine the potential financial impact of the incident.

ASOS has published customer guidance addressing the unauthorized notification, telling customers not to click or interact with the external link contained in the message. The retailer is not currently asking customers to change their ASOS passwords.

UK cyber agency warns all ASOS customers

The UK’s National Cyber Security Centre has also issued an alert concerning the ASOS incident.

The NCSC advised ASOS customers to assume they may be affected even if they did not receive the unauthorized push notification. It warned customers to watch for suspicious messages that could arrive after the incident and to avoid clicking links in unexpected push notifications, emails or messages.

The potential exposure of names and contact information creates a particular risk of follow-on phishing and impersonation attempts. Attackers could potentially use legitimate customer information to make fraudulent communications appear more convincing.

ASOS’s official guidance similarly tells customers to disregard the unauthorized notification and avoid interacting with its external link.

Second ASOS security incident in months

The latest incident comes less than 3 months after ASOS detected a separate campaign targeting customer accounts.

In that earlier incident, first detected on July 28, attackers logged into ASOS accounts using credentials obtained from a source outside the retailer. Potentially exposed information varied by account and included names, email addresses, delivery and billing addresses, telephone numbers, dates of birth and limited payment-card information.

ASOS blocked access to the affected accounts, required password resets and said it had not observed further unauthorized activity after implementing those measures.

There is currently no evidence connecting the July credential attacks to the Oct. 6 compromise of ASOS’s customer communication platforms. The intrusion methods also appear materially different based on what the company has disclosed so far.

The earlier attack relied on credentials obtained outside ASOS to access individual accounts. The new incident instead involves unauthorized activity affecting third-party platforms integrated with the retailer’s customer communication infrastructure.

Snowflake claim remains unconfirmed

The most significant unanswered question is whether the attackers actually obtained the Snowflake access claimed in their notification.

ASOS has confirmed possible exposure of names and contact details but has not publicly connected that exposure to Snowflake. The company has also not disclosed how the attackers gained access, which third-party communication platforms were compromised or whether credentials, tokens or another authentication mechanism were involved.

Until those details are established, the confirmed scope remains unauthorized access involving ASOS’s third-party customer communication platforms, the ability to send an unauthorized notification, and the potential exposure of basic customer information.

ASOS said it will provide another update if the situation changes as its investigation continues.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site →