Loading Gee Radio...

OFF AIR Gee Radio
Published On: October 6, 2026 Categories: Technology

ASOS Investigates Cyber Incident After Customers Receive “ASOS HACKED” Notification

British fashion retailer says unauthorised activity involving third-party platforms may have exposed basic customer information

ASOS Investigates Cyber Incident After Customers Receive “ASOS HACKED” Notification

0 likes

LONDON, UK — British online fashion retailer ASOS is investigating an apparent cyber incident after customers received an unauthorised notification through its mobile application on Tuesday.

Dozens of customers reported receiving a message reading “ASOS HACKED”, prompting concern among users and raising questions about the security of third-party platforms used by the company.

ASOS later acknowledged that an unauthorised customer notification had been sent and said some basic personal information may have been accessed.

ASOS Investigates Unauthorised Activity

In a statement to customers, ASOS said it was investigating unauthorised activity involving third-party platforms used by the company.

The retailer apologised for the notification and advised customers not to engage with it.

ASOS said its website and application remained operational and that customers could continue using its services while the investigation continued.

The company has not publicly established the full scope of the incident or confirmed how many customers received the message.

Notification Raises Cybersecurity Concerns

The unusual message reportedly appeared to have been directed towards ASOS's data protection and information technology teams.

Cybersecurity specialists described the incident as an unusual form of digital extortion because the apparent attackers appeared to use the company's own customer-facing application to communicate their message.

Charlotte Wilson, head of enterprise at cybersecurity company Check Point, described the incident as a serious and unusually public attack.

She said the apparent use of the ASOS app as a communication channel demonstrated how a compromised third-party service could potentially be turned against the organisation operating it.

However, Wilson advised customers not to panic.

She recommended changing passwords, avoiding links contained in suspicious notifications and remaining alert for potential phishing emails or text messages that could exploit concerns surrounding the incident.

Customers Across Several Countries Affected

The exact number of customers who received the notification remains unclear.

Reports indicated that users in countries including Australia, France, Sweden and the Republic of Ireland had also received the message.

ASOS has a substantial international customer base, serving approximately 17 million customers annually across more than 150 markets.

The company's Android application has also recorded more than 10 million downloads on Google's Play Store, highlighting the potential scale of its digital user base.

ICO Notification Remains Unclear

ASOS had not, at the time of reporting, publicly confirmed that it had notified the UK's Information Commissioner's Office (ICO) about a personal-data breach.

Under UK data-protection rules, organisations are required to assess personal-data incidents and, where a breach presents a risk to individuals' rights and freedoms, report qualifying breaches to the regulator within the applicable timeframe.

ASOS's investigation is expected to establish whether customer data was actually compromised, what information may have been accessed and how the unauthorised notification was sent.

Financial Impact

The incident also affected investor sentiment, with ASOS shares falling by around 10% during Tuesday's trading as the company dealt with the developing cybersecurity concerns.

The immediate financial impact remains uncertain, particularly because the extent of any data exposure and the cause of the unauthorised activity have yet to be fully established.

What ASOS Customers Should Do

ASOS has urged customers not to interact with the unauthorised notification.

Cybersecurity experts have advised users to take basic precautions, including:

  1. Avoid clicking suspicious links received through the app, email or text messages.
  2. Change an ASOS password if there is concern that account credentials may have been exposed.
  3. Avoid reusing the same password across multiple services.
  4. Be cautious of unexpected messages claiming to come from ASOS.
  5. Monitor accounts for unusual activity.

For now, ASOS says its website and app are operating normally as its investigation continues.

The incident highlights the growing cybersecurity risks facing major digital retailers, particularly where businesses depend on networks of third-party technology providers and platforms to communicate with millions of customers.

Share

Share this story

Choose a platform or copy the link