Online retailer ASOS has urged customers to disregard an unauthorized push notification that appeared on smartphones this Tuesday, which claimed the company’s servers had been compromised. The message, which originated from the ASOS app, featured a link to a Telegram channel and threatened data leakage if the company did not engage with the sender.
ASOS confirmed it took immediate action to block the attackers’ access and is collaborating with security advisers and authorities. The retailer apologized for the incident and stated that the message was not genuine. Data storage provider Snowflake also told the BBC its investigations found no evidence of compromise to its platform.
While the full extent of any potential data exposure remains unclear, ASOS notified affected customers that basic personal information, such as names and contact details, may have been accessed. The company emphasized that there is no indication that payment card information or account passwords were impacted, and it stressed that receiving the notification did not mean individual phones were hacked.
Cybersecurity experts are advising consumers to take several protective measures. Users are strongly cautioned against clicking any links contained in the suspicious notification. It is also recommended to change passwords immediately, ensuring they are updated across any other accounts that may share the same credentials.
The National Cyber Security Centre (NCSC) recommends enabling two-step verification for critical accounts, such as banking and email, describing it as one of the most effective defenses against cybercrime. Additionally, customers should monitor their financial transactions for any unusual activity.
Charlotte Wilson, head of enterprise at Check Point, warned that the immediate risk lies in follow-up scams. She anticipates that criminals will attempt to exploit public confusion by sending phishing emails or texts that mimic official communications from ASOS. Consumers are advised to remain suspicious of any unsolicited messages offering refunds or requesting password resets.
Kat Cereda, a spokesperson for the consumer rights group Which?, added that individuals should hang up immediately if they receive phone calls from someone claiming to be from ASOS or another organization. Instead, they should contact the company directly through official channels. As of Tuesday evening, ASOS stated its website and app were operating normally, and it committed to providing further updates as more information becomes available.
I just changed all my passwords out of an abundance of caution. Better safe than sorry when it comes to personal data.
Has anyone else received those follow-up phishing texts yet? The experts are warning about them, so stay vigilant everyone.
Telegram links in official app notifications? That’s a pretty sloppy move by the attackers. Glad ASOS responded quickly though.
Thank goodness they clarified that payment info wasn’t touched. That’s the scary part I was worried about!