ASOS says an unauthorised notification went to its customers at about 10am on Oct. 6 and that basic personal information, including names and contact details, may have been accessed. The UK retailer links the activity to third-party platforms it uses to communicate with customers.

In a stock exchange announcement the same day, ASOS said it is investigating unauthorised activity involving those platforms and restricted access to the notification platforms immediately. It is working with specialist advisers and the relevant authorities. The company said it does not believe payment-card information or account passwords were affected, that its website and app are operating normally, and that it is too early to quantify any effect on trading.

The UK’s National Cyber Security Centre published an alert the same day. Its guidance tells customers to assume they are affected even if they never received the notification, and warns that suspicious messages “can arrive some time after a data breach incident.” It advises against clicking links in suspicious messages, including those in push notifications, and recommends passkeys, or strong separate passwords with two-step verification.

Our read: customers trust a push notification because it comes from an app they installed, so a fake one is hard to spot, and the NCSC names push notifications among the places to avoid suspicious links. Teams that send customer messages through third-party platforms should confirm who holds sending rights, how those credentials are stored, and whether the platform flags unusual sends. The same questions apply to email and SMS providers. Other recent personal-data disclosures are covered in Denmark’s CPR register incident and the ANSSI report on a French tax breach.

Source: NCSC, Incident affecting ASOS customers