Advertise with Pune MediaAdvertise with Pune MediaAdvertise with Pune MediaAdvertise with Pune Media

Top 5 This Week

Advertise with Pune MediaAdvertise with Pune MediaAdvertise with Pune MediaAdvertise with Pune Media

Related Posts

ASOS Confirms Data Breach After Rogue App Alert

Editorial Disclosure: This article is curated from reporting by the original publisher credited below. It was selected and published automatically under the Pune.Media Editorial Policy and is not original Pune.Media reporting.

Original Coverage & Source Attribution: quasa.io

On October 8, 2026, BleepingComputer reported that ASOS had traced a breach of customer information to an intruder who impersonated a trusted contact, stole an employee’s login credentials and used them to enter third-party platforms. The fuller disclosure followed an unauthorized push notification sent through the fashion retailer’s app.

In its customer update, ASOS says the intruder could access names, contact details and some non-personal account-related information; its investigation found no access to customer account passwords or payment-card information, and it tells shoppers, “There is no action you need to take on your account.” Its website and app remained safe to use throughout the incident. For customers, the immediate concern is an unexpected approach that uses a genuine detail to appear credible.

How the employee account exposed customer data

The credentials taken in the impersonation belonged to an ASOS employee, not to a shopper signing in to buy clothes. They provided a route into certain third-party platforms used by the retailer, where the intruder could reach customer information. The absence of accessed customer passwords does not erase the exposure of contact records held outside the customer sign-in system.

After discovering the intrusion, ASOS restricted access to the affected platforms and began an investigation with internal and external cyber specialists. The app alert was the public sign that an unauthorized party had gained control of a customer communication route. It was also a demand directed at the company, delivered in a channel shoppers would normally associate with ASOS. The notification itself cannot establish the breach’s full scope.

What information was accessible?

An ITV News report identifies email addresses and customer search queries among the details involved. The available account separates the categories of data the intruder could reach from information that investigators found was outside that access:

  • Names — accessible: Customer names were among the personal information available through the affected platforms.
  • Contact details — accessible: Email addresses are specifically identified in reporting. A name paired with a working contact route could help an unsolicited message seem familiar.
  • Account-related information — accessible in part: This category includes certain non-personal account-related information; customer search queries have also been identified. There is no public field-by-field inventory for individual customers.
  • Customer account passwords — no access found: These are separate from the employee credentials used in the intrusion. The finding does not mean a customer should enter a password into a later message about the breach.
  • Payment-card information — no access found: The investigation has not identified access to card details through these platforms.

Those categories describe what was accessible, not a confirmed record for every ASOS customer. The number of affected customers has not been disclosed. Receiving the rogue alert shows that a device received a message; it does not identify what data, if any, about its owner sat on the affected platforms.

What the rogue alert does and does not establish

The notification made a larger claim than the confirmed findings. In TechCrunch’s account, the attackers claimed to have fully compromised ASOS data hosted on Snowflake and threatened to leak it unless the company engaged with them. That is an attacker assertion; the public investigation describes access to certain third-party platforms and has not established the claimed breadth of a Snowflake compromise.

The full set of customer fields and the exact relationship between platform access and the ability to send the push alert remain unresolved publicly. Neither a notification on a phone nor the absence of one is a reliable test of whether a particular customer’s contact details were accessible. The more practical distinction is between a confirmed opportunity to obtain contact information and an unverified claim about a wider dataset.

What ASOS customers should do

The UK National Cyber Security Centre’s incident advice tells ASOS customers to assume they may be affected even if they did not receive the notification, to watch for suspicious messages and to avoid links in unexpected push alerts, emails or texts. Suspicious messages can arrive some time after a breach. That advice addresses the risk created by contact details becoming accessible, without implying that passwords or cards were taken.

  1. Ignore links and contact instructions in the rogue alert or any unexpected follow-up message. Open the ASOS site or app yourself if you want to check your account.
  2. Do not provide a password, security code or payment detail to someone who contacts you about the incident. A correct name or email address is not proof that the sender represents ASOS.
  3. Review account and payment activity for anything unfamiliar, and contact the relevant provider through a channel you found independently if something needs checking.
  4. Change a password if you entered it after following a suspicious link, notice account misuse or reused it on another service. A new password can secure a login, but cannot retract contact details already available to the intruder.

The next substantive development will be the results of the continuing investigation, including direct notices to customers identified as needing further information, support or action. Until the affected records are mapped more precisely, an unsolicited message that knows a shopper’s name or email address deserves careful scrutiny.

Popular Articles