What happened?
British fashion retailer Asos confirmed that customer data was compromised in a cyberattack. The company learned of the breach not through a standard security notice, but through a push notification sent by the attackers via its own app.
How did the attackers announce it?
Hackers sent a notification to customers through the Asos app, claiming they had "fully compromised" the company's cloud storage infrastructure. This method suggests the attack went beyond data alone, indicating that access to the notification system may also have been compromised.
Why it matters
Asos is a global e-commerce platform with millions of customers. The theft of customer data increases the risk of phishing and fraud. The incident shows that indirect access points such as cloud infrastructure and notification systems can also serve as attack surfaces for e-commerce companies.
What's next
Asos has not yet shared details on the scope of the breach or the number of affected customers. The company's investigation and possible regulatory notifications are expected to become clearer in the coming days.



