Hackers Compromised an ASOS Employee Account to Send a Rogue Push Notification, Exposing Limited Customer Data
ASOS disclosed that attackers impersonated a trusted contact to gain an employee’s credentials, allowing them to push a fraudulent notification to customers and view limited personal information. The incident highlights the need for robust identity controls and security‑awareness programs to meet audit and trust requirements.
ADTP Breach Watch· October 8, 2026· The Record
SeverityHigh
Type🔑 Breach
ConfidenceHigh
ReportedOct 8, 2026
Retail & E-CommerceRetail/E‑commercePhishing
What happened
Attackers impersonated a trusted contact to obtain an ASOS employee’s login credentials. Using the compromised account they sent an unauthorized push notification to customers and accessed names, contact details and some non‑personal account information.
Why it matters for trust and compliance
This breach underscores the importance of continuous identity‑access monitoring and documented security‑awareness training, which provide defensible evidence for audit readiness across frameworks.
Implement regular phishing simulations and training to demonstrate due diligence.
Maintain logs of privileged access and push‑notification actions for continuous control monitoring.
Who is affected
Retail/E‑commerce
Recommended actions
Review and tighten employee credential management, enforce MFA, and document security‑awareness activities.
Get the Breach Digest
The incidents that matter for your vendors and your data, analysed for practitioners, in one email.