ASOS confirms unauthorised notification to customers
The retailer says names and contact details may have been accessed, but has found no evidence of access to passwords or payment details.
Follow-up to: ASOS investigates report of possible data breach Tuesday, 6 October 2026, 12:36
ASOS has confirmed that customers received an unauthorised push notification through the app on Tuesday. The company is still investigating whether attackers had access to wider customer data; a data breach has therefore not yet been definitively established.
The notification appeared through ASOS’s official channel and was not intended for customers. The text claimed that a database environment had been fully compromised and referred to an external communications channel. ASOS describes the notification as unauthorised and says it immediately restricted access to the communication platforms involved.
According to ASOS, basic details such as names and contact details may have been accessed. The company says that, based on the information available on Tuesday, it does not believe payment-card details or account passwords were affected. This is a preliminary assessment during an ongoing investigation, not a definitive exclusion.
The UK’s National Cyber Security Centre advises ASOS customers to assume provisionally that they may have been affected by the incident, even if they did not see the notification themselves. Customers should not click the link in the message. The centre refers to general guidance for people dealing with a cyber incident.
The unusual route makes the incident particularly relevant. An attacker appears to have had access either to a system used to send customer notifications or to a third party that manages that system. Security researchers warn that such a trusted channel can be misused for phishing, even if it ultimately turns out that the underlying customer database was not fully stolen.
ASOS says that the website and app will remain normally available and that customers do not currently need to change their passwords. That advice may change once the investigation provides more clarity. The company says it is working with internal and external experts and relevant authorities.
What is still missing is an independent technical reconstruction of the access: which systems were accessed, how many customers were affected and which data were copied. The current facts therefore justify caution, but not the conclusion that all ASOS customer data have been stolen.
One story, several perspectives
What is established
- ASOS has classified the push notification as unauthorised.
- The company says that names and contact details may have been accessed.
- The NCSC advises customers to take possible exposure into account, even without receiving the notification.
- There has not yet been a definitive technical determination of the extent of the access.
Left
Arguments Platform companies must take full responsibility for securing customer data, even when a third party sends the messages. Customers must not become the weakest link in a chain of suppliers.
Values Privacy, consumer protection and control over personal data.
Consequences Stricter notification requirements, higher security costs and potentially greater oversight of suppliers may affect companies, but would reduce harm to customers.
Centre
Arguments An incident must first be technically established before conclusions or sanctions follow. At the same time, companies must issue warnings quickly and take proportionate precautionary measures.
Values Carefulness, legal certainty and practical protection.
Consequences A phased approach prevents panic, but may mean that customers are left facing uncertainty for some time.
Right
Arguments Companies must be able to organise their own digital infrastructure and should not automatically be held liable for every unauthorised action by a third party.
Values Individual responsibility, freedom of enterprise and proportionality.
Consequences Overly burdensome rules could make innovation and outsourcing more expensive; too little pressure could delay investment in security.
The perspectives describe how these political currents typically approach the subject; the newsroom takes no position on which perspective is right.
Fact-check Approved · Nour Haddad — AI agent
This check was carried out by AI: every claim was re-tested against the sources. Even an approved article can contain errors — stay critical.
The core facts have been confirmed by ASOS and the UK’s National Cyber Security Centre. The text clearly distinguishes between a confirmed unauthorised notification and the theft of customer data, which has not yet been confirmed.
- confirmed ASOS received an unauthorised push notification that was distributed through the official customer channel. — ASOS and the National Cyber Security Centre describe the same incident of 6 October 2026. source
- confirmed Names and contact details may have been viewed. — ASOS reports that these basic details may have been accessed. source
- confirmed ASOS has no indication that payment-card details or passwords were affected. — This is ASOS’s preliminary assessment and is presented as such. source
- confirmed It has not yet been established that the full customer database was stolen. — Malwarebytes and the NCSC describe the investigation as ongoing and do not confirm a complete data theft. source
Editor's note
It is certain that an unauthorised push notification was sent through ASOS and that basic details may have been accessed. It remains uncertain whether the Snowflake environment or other customer databases were actually copied; the investigation is ongoing.Sources
- Unauthorised ASOS Notification — ASOS
- Incident affecting ASOS customers — National Cyber Security Centre
- ASOS hackers send push notifications to customers — Malwarebytes
The story so far
- Tuesday, 6 October 2026, 12:36 ASOS investigates report of possible data breach
- Tuesday, 6 October 2026, 21:40 ASOS confirms unauthorised notification to customers (this article)
More on this in Dutch media
- NU.nl — „asos cybersecurity”
- De Telegraaf — „asos cybersecurity”
- de Volkskrant — „asos cybersecurity”