SOCLYDE logo
Current languageEN
Cybersecurity newsData breachOnline retailAccount security

Asos: unauthorised notification and customer data

ASOS is investigating after an unauthorised push notification was sent. What the company and the UK NCSC say about potentially accessed data.

Published on

By Soclyde Team

A customer checks a phone in a kitchen after receiving an unexpected notification

In summary

  • ASOS is investigating after some customers received an unauthorised push notification on 6 October.
  • The company says names and contact details may have been accessed; it does not believe account passwords or payment-card data were affected.
  • The UK NCSC advises ASOS customers to assume they are affected, even if they did not receive the notification.

Explore next

Soclyde resources

Article contents

On 6 October 2026, some customers received an unusual push notification in the ASOS app. The retailer confirmed unauthorised activity and is investigating access to customer information. The message displayed in the app is not, by itself, proof that every system or account was compromised.

What ASOS has confirmed

ASOS says names and contact details may have been accessed. The company does not believe account passwords or payment-card data were affected. These are preliminary statements made while the investigation continues, not a final incident report.

The unauthorised push message linked to an external channel and claimed that a storage environment had been compromised. That claim came from the message’s authors; ASOS has not confirmed it as the technical description of the incident. The notification itself must be distinguished from findings published by the company.

Who should assume they are affected?

The UK National Cyber Security Centre advises every ASOS customer to assume they are affected, even if they did not receive the notification. This cautious guidance does not establish that each customer was individually impacted; it means that not seeing the push is not enough to rule out risk.

The information published so far does not provide a final count of accessed accounts or a detailed list of every potentially exposed field. Do not infer that additional data was compromised based only on the allegation in the notification.

Useful checks for customers

Open ASOS by typing its address yourself or using the installed app, then check the company’s updates. Do not use links, phone numbers, or messaging accounts from the unauthorised push. Be alert to urgent requests for a code, payment, or identity confirmation that use the incident as a pretext.

If you reused your ASOS password, change it on the other services as well. Start with your email account, which can often be used to reset access elsewhere. Review contact details and recent orders in the official account, and contact ASOS through its usual channels if you spot an unexpected change.

What ecommerce teams should examine

For a service that sends mobile notifications, an investigation should cover the message content, the account or tool used to send it, and access to the messaging platform. Administrative and delivery logs can help establish whether an unauthorised session, integration, or vendor account was involved.

Teams should revoke suspicious access, review integration keys, and publish guidance through a trusted channel. A malicious notification delivered by a familiar app blurs the line between genuine communication and phishing; clear, consistent advice helps customers recognise legitimate follow-up messages.

The Soclyde connection

Soclyde does not protect ASOS infrastructure and cannot resolve this incident. An encrypted local-first vault can help a user keep unique passwords for each service and quickly find accounts where a secret was reused. App controls and the investigation remain ASOS’s responsibility.

The takeaway

ASOS is investigating after an unauthorised notification and says names and contact details may have been accessed. The company does not believe passwords or card data were affected; the NCSC nevertheless advises customers to assume they are affected. Use official channels and eliminate password reuse. To create a separate secret for each account, read our secure password generator guide.

Frequently asked questions

What ASOS customer data may have been accessed?

ASOS and the NCSC say basic personal information, including names and contact details, may have been accessed. ASOS does not believe account passwords or payment-card information were affected. The investigation is ongoing.

Should I change my ASOS password?

The NCSC advises customers to assume they are affected. If you reused your ASOS password elsewhere, replace it on every affected service with a unique secret, starting with your email account. Use only the official website or app.

Was the notification customers received an official message?

No. ASOS said an unauthorised notification had been sent through its app. Do not follow its external link or contact the alleged attackers; check updates published by ASOS and the NCSC instead.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading