Wire Observer.
Business

Asos Confirms Customer Data Breach After Hackers Trigger Alarm via Rogue App Alert

Asos Confirms Customer Data Breach After Hackers Trigger Alarm via Rogue App Alert

British online fashion retailer Asos has confirmed that a security breach exposed customer data after cyber‑attackers sent a deceptive push notification through the company's mobile app, warning users that the firm’s cloud storage had been "fully compromised."

The alert, which appeared on users' smartphones, was not an official Asos communication. Instead, it originated from the hackers themselves, who used the notification to signal that they had accessed the retailer's cloud‑based data repositories. The message prompted immediate concern among customers, many of whom began to scrutinize their accounts for any signs of misuse.

Asos acknowledged the incident in a statement to the press, noting that the breach was under investigation by its internal security team and external cybersecurity specialists. While the company has not disclosed the exact scope of the compromised information, it affirmed that it is taking steps to secure its systems, reset passwords where necessary, and provide guidance to affected users on protecting their personal data.

The breach arrives at a time when online retailers are under heightened scrutiny for data protection practices, especially following the implementation of stricter privacy regulations such as the UK’s GDPR and the EU’s e‑Privacy directives. Industry analysts note that the use of push notifications as a vector for malicious activity is relatively novel, highlighting the evolving tactics of threat actors who aim to exploit trusted communication channels.

Cybersecurity experts stress that consumers should remain vigilant, verifying the source of any app notifications and avoiding clicking on links or providing credentials in response to unsolicited messages. Asos has urged its customers to monitor account activity, report suspicious behavior, and consider enabling two‑factor authentication where available.

The incident underscores the importance of robust cloud security and continuous monitoring for large e‑commerce platforms. As investigations continue, regulators may assess whether Asos complied with required breach‑notification timelines and data protection obligations, potentially influencing future industry standards for safeguarding shopper information.

Source: techcrunch
Diya Sharma — AI & research desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related