ASOS Confirms Data Breach After Hackers Send Push Notification
Translated & summarized from Mako by baba
Fashion retailer ASOS confirmed a potential data breach on October 7, 2026, after hackers sent an unauthorized push notification to customers claiming system compromise. While payment details and passwords are not believed to be affected, basic personal information like names and contact details may have been exposed. The company is investigating the incident, which caused its stock to fall 12%, and advises customers to ignore the notification and await official updates.
The story in 6 lines · by baba
- ASOS confirmed a potential data breach on October 7, 2026, affecting customers globally.
- Hackers sent an unauthorized push notification to customers claiming system compromise.
- Basic personal information, including names and contact details, may have been exposed.
- Payment card details and account passwords are not believed to have been compromised.
- ASOS stock dropped 12% following the incident and reports of a breach.
- Customers are advised to ignore the notification and await official company updates.
British fashion retailer ASOS confirmed on October 7, 2026, that a cyberattack may have exposed basic personal information of customers worldwide, including those in Israel. The company issued a statement after customers received an unauthorized push notification on the ASOS app claiming the company's systems had been breached and threatening to leak data. The hackers claimed to have gained full access to ASOS's Snowflake account, a platform used by many retailers for customer data storage and analysis, and which has been linked to previous breaches at companies like Ticketmaster and AT&T.
ASOS urged customers not to click on the link in the suspicious notification and to ignore it. In a more detailed statement, the company acknowledged investigating unauthorized activity related to third-party platforms used for customer communication. While ASOS stated that payment card details and account passwords are not believed to have been compromised, basic personal information, including names and contact details, may have been exposed. The company has taken immediate action to restrict access to notification platforms and is working with internal and external experts, as well as relevant authorities.
The incident caused ASOS's stock to drop by approximately 12% following widespread social media reports. The UK's National Cyber Security Centre (NCSC) reportedly offered assistance to ASOS. Experts suggest the hackers' direct approach via push notification was intended to pressure ASOS, possibly as part of a ransomware attempt, by demonstrating the extent of their access to company systems.
Idan Abramov, CTO of Comsecure, noted that the ability to send a push notification indicates the attackers accessed at least some connected systems, though full confirmation of their claims regarding the breach's scope is pending. He advised users to avoid clicking the notification, refrain from contacting the attackers, and rely solely on official ASOS updates. ASOS has confirmed that its website and app operations continue as normal and that it holds adequate insurance coverage, including cyber and business continuity insurance.
Mentioned
The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.
Centre 2Other 1
Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.
