What is confirmed
On October 6, some ASOS app users received an unauthorised push notification containing an external link. ASOS asked customers not to engage with it.
The company restricted access to affected third-party platforms. Its initial guidance said names and contact details may have been accessed, but it did not believe passwords or payment-card data were affected.
What it means
A notification delivered by a legitimate app is not necessarily trustworthy: a compromised messaging platform can carry an attacker's message.
Attackers’ claims about the extent of the theft must be separated from confirmed findings and the company's investigation.
What this incident reveals
A notification delivered by a legitimate app is not necessarily trustworthy: a compromised messaging platform can carry an attacker's message.
Practical steps to take
Do not follow links in the unauthorised push; consult ASOS support directly.
Be cautious of emails or texts using your name or purchase history to request a payment or login.
What to do
Do not follow links in the unauthorised push; consult ASOS support directly.
Be cautious of emails or texts using your name or purchase history to request a payment or login.
Protect your email account with multifactor authentication and independently verify unusual requests.
Use the related SecurCheck tool, then confirm important decisions with an official source.