ASOS Hacked: Rogue Push Notification Claims Full Cloud Storage Compromise

TL;DR
- ASOS confirmed hackers hijacked its mobile app push notification system to send a rogue alert falsely claiming its cloud storage was fully compromised.
- The retailer says no payment details or passwords were exposed, but names, emails, and order histories may be at risk while investigations continue.
- Shoppers should reset passwords, enable two-factor authentication, and be on high alert for phishing texts and emails impersonating ASOS.
What Happened: Panic From a Push
Shoppers woke up to a shock this week when ASOS app users received an alarming push notification claiming the fashion giant had been completely hacked and all of its cloud storage had been stolen. The message, laced with hacker bravado, urged users to take immediate action and spread the word online.
Within hours, screenshots of the rogue alert went viral on X, TikTok, and Reddit, with thousands of customers questioning whether ASOS had suffered a catastrophic ransomware-style breach. ASOS quickly pulled the notification system offline and confirmed that its app messaging service had indeed been hijacked by an unauthorized third party.
The company stressed that the claim of a full cloud storage compromise appears to be exaggerated, calling it a scare tactic designed to cause maximum panic and damage trust.
How Did Attackers Get In
According to ASOS's initial statement, the attackers did not breach ASOS's core e-commerce platform or its main customer database directly. Instead, they gained access to a third-party push notification and engagement provider connected to the ASOS app.
This is a growing attack pattern in retail tech. By compromising API keys or admin credentials for a marketing tool, hackers can blast messages to millions of phones without ever touching the retailer's checkout servers. Security researchers say similar push-hijacking incidents have hit airlines, banks, and gaming apps in the past year.
ASOS said it immediately revoked access tokens, cut off the vendor's connection, and launched a forensic investigation with external cybersecurity experts. The UK's National Cyber Security Centre and the Information Commissioner's Office have reportedly been notified.
What Customer Data Is Actually At Risk
This is the question every shopper is asking. ASOS says its investigation is ongoing, but here is what is known so far.
ASOS has confirmed that full payment card numbers, CVV codes, and account passwords are not stored in plain text and were not exposed via the push system. The push provider would not normally have access to that level of sensitive data.
However, to send personalized notifications, the marketing system does hold names, email addresses, device identifiers, app preferences, and potentially recent order and browsing data. ASOS has warned that this limited profile information may have been viewed or scraped during the hijack.
The bigger risk, experts warn, is follow-on fraud. With a verified list of active ASOS customers, attackers could launch highly convincing phishing campaigns pretending to offer refunds, order cancellations, or account resets related to the breach.
How ASOS Responded
ASOS moved quickly to contain the fallout. The company issued an in-app banner and email to customers confirming the rogue notification was not sent by ASOS and advising users to ignore links in the fake message.
A spokesperson said no evidence has been found so far of a full compromise of its AWS and cloud storage environment, despite the hackers' claims, but the company is continuing to audit logs as a precaution. ASOS also forced a reset of internal employee credentials for marketing tools and said it is reviewing all third-party vendor access.
The retailer has not reported any disruption to ordering, payments, or deliveries, and its website and app remain operational. ASOS said it will directly notify any customers whose personal data is confirmed to have been accessed, in line with UK GDPR rules.
What Shoppers Should Do Right Now
First, do not click any links from the rogue push notification or any unexpected messages claiming to be about the ASOS hack. Delete the original alert and only use the official ASOS app or asos.com typed directly into your browser.
Second, change your ASOS password immediately and make sure you are not reusing that password anywhere else. Turn on two-factor authentication if you have not already, and check your order history for any unfamiliar purchases or address changes.
Third, be extra vigilant for the next few weeks. Expect fake delivery texts, refund emails, and Instagram ads impersonating ASOS support. ASOS will never ask you for your full card number, password, or one-time passcode by email or text. If you spot suspicious activity, report it to ASOS customer care and to Action Fraud in the UK.
A Wake-Up Call For Retail Security
The ASOS incident is the latest reminder that modern breaches rarely start with the main website. Hackers are increasingly targeting the sprawling web of vendors, plugins, and cloud integrations that power push alerts, chatbots, and personalized marketing.
For ASOS, which serves more than 20 million active customers globally, rebuilding trust will be critical ahead of the peak holiday shopping season. For shoppers, it is another signal to practice good digital hygiene and treat every unexpected notification with skepticism, even when it comes from a trusted app.
Get All The Latest Updates Delivered Straight To Your Inbox For Free!