
Online fashion giant ASOS has launched an investigation into a security breach after thousands of customers received alarming unauthorized push notifications through the company's mobile application. On Tuesday morning, app users across multiple countries were startled by messages explicitly stating "ASOS HACKED." The company quickly acknowledged the incident, attributing the breach to unauthorized activity involving third-party platforms rather than a direct compromise of its core infrastructure.
While the incident caused widespread confusion and concern, ASOS has sought to reassure its global customer base. Preliminary assessments by the company suggest that while some "basic personal information" may have been accessed, critical sensitive data—including passwords and payment information—is believed to remain secure. Despite the breach, both the ASOS website and mobile app remain fully operational, and the company has encouraged customers to continue shopping while the investigation proceeds.
Cybersecurity experts have described the attack as an unusually brazen attempt at extortion. Unlike typical data breaches where hackers operate quietly to extract data for sale, this incident involved a direct and public confrontation with the company's clientele. The market reacted swiftly to the news, with ASOS shares experiencing a notable decline, falling by approximately 10% on the London Stock Exchange following the reports.
ASOS is currently working alongside specialized cybersecurity consultants and has alerted the National Cyber Security Centre (NCSC) and the London Stock Exchange. Although the company is still assessing the full extent of the breach to determine if formal notification to the Information Commissioner's Office (ICO) is required, it has advised users to remain vigilant. Security analysts recommend that users refrain from interacting with the suspicious notifications and consider updating their account passwords as a standard safety precaution.