Asos Admits Data Leak After Hackers Use Fake App Notification to Signal Cloud Compromise
The UK‑based online fashion retailer Asos has confirmed that a security incident led to the exposure of customer information after cyber‑criminals dispatched a misleading push alert via the company’s mobile application, telling users that the retailer’s cloud storage was "fully compromised."
The notification that popped up on users’ phones was not an authentic Asos message. It was generated by the attackers, who used the alert as proof that they had infiltrated the retailer’s cloud‑based data stores. The warning sparked immediate alarm among shoppers, many of whom began checking their accounts for any irregular activity.
In a press statement, Asos said the breach is being examined by its internal security team together with external cybersecurity experts. Although the firm has not revealed exactly what data was accessed, it said it is taking measures to harden its systems, reset passwords where needed, and advise affected customers on how to safeguard their personal information.
The incident comes at a moment when online merchants face increasing scrutiny over data‑protection practices, especially after the rollout of tighter privacy laws such as the UK’s GDPR and the EU’s e‑Privacy directives. Analysts point out that leveraging push notifications as an attack vector is relatively new, underscoring the shifting tactics of threat actors who seek to abuse trusted communication channels.
Security specialists urge users to stay cautious, confirming the origin of any app notifications and refraining from clicking links or entering credentials in response to unsolicited alerts. Asos has asked its users to keep an eye on account activity, report any suspicious behavior, and consider enabling two‑factor authentication where it is offered.
The episode highlights the need for strong cloud security and ongoing monitoring for large e‑commerce sites. As investigations proceed, regulators may review whether Asos met mandatory breach‑notification deadlines and data‑protection duties, a review that could shape future industry standards for protecting shopper data.
Comments (0)
Be the first to comment.
Join the discussion