ASOS confirmed unauthorised activity involving third-party customer-communications platforms after an attacker-controlled push notification reached customers and basic personal information may have been accessed.
What changed
An attacker-controlled notification reached ASOS customers through an official channel. ASOS confirmed unauthorised activity involving unnamed third-party communications platforms and possible access to names and contact details, while saying passwords and payment cards were not believed affected.
Public record through 2026-10-07. Source references count citations across published briefings, including repeated sources. Explore the record and its limits →
What We Publish / What We Sell
D
Free · Public
The Daily
Five evidence-backed selections for security leaders, every weekday.
Scores are Security.io editorial judgements from 0–100. Exposure considers reachable organisations and privileged placement; urgency considers remediation and containment windows; business consequence considers disruption, data, trust and governance impact. They are not vendor severity scores. Exposure: 84. Urgency: 93. Business consequence: 88. Focus the chart and use the up and down arrow keys for detail. Source: Security.io editorial assessment based on the five selected stories and their cited evidence.