For many business leaders, this is the cyber-security equivalent of a nightmare phone call. Reports suggest attackers were able to send unauthorised messages directly through the ASOS app, using a trusted customer channel to claim the retailer had been compromised.

While the investigation is ongoing and the full facts are still emerging, the incident serves as a powerful reminder that cyber security is not only about protecting systems. It's about protecting customer trust.
 

What matters now is understanding what has been confirmed, what remains unclear, and what organisations can learn from the situation.

QUICK SUMMARY

  • ASOS app users reportedly received unauthorised push notifications
  • The messages claimed the retailer had been hacked and threatened the release of data
  • This does not, by itself, confirm data was accessed or stolen
  • The incident highlights the risk surrounding trusted customer communication channels
  • Organisations should review access controls, monitoring and incident response arrangements

Stay alert to opportunistic scams

High-profile incidents can create opportunities for phishing and scam campaigns. The National Cyber Security Centre (NCSC) has advised consumers to be cautious of unsolicited emails, texts or calls claiming to be linked to the ASOS incident.

Always verify requests through official channels before clicking links, sharing information or resetting passwords.

 

 

What appears to have happened?

Reports indicate that unauthorised messages were delivered directly to ASOS app users. The messages claimed that attackers had compromised the retailer and threatened to release information.
 
However, a malicious claim should not be treated as proof of a data breach. Until ASOS or an investigating authority confirms what systems were accessed and whether information was taken, it is important to distinguish between a compromised communication channel and confirmed data theft.
 
Even a limited compromise can have a significant impact. Sending messages through an official app allows an attacker to communicate using a channel that customers already trust.

 

Image (46)
edited-photo

This is where organisations get caught out

Cybersecurity strategies often focus on networks, endpoints and email. Customer-facing systems can receive less attention, despite being highly visible and closely connected to brand trust.
 
The question is not only:
“Could an attacker enter our corporate network?”
 
IT and security leaders should also ask:
“Could an attacker impersonate us through a channel our customers trust?”
 
That broader attack surface can include mobile apps, push-notification tools, social media accounts, customer portals and third-party marketing platforms.
 
For well-known brands, the immediate challenge is often not the technical investigation itself. It's maintaining customer trust while establishing the facts and communicating clearly during a fast-moving situation. Even a relatively limited compromise can quickly become a reputational issue when customer-facing systems are involved.

 

A timely reminder during Cyber Security Awareness Month

As organisations mark Cyber Security Awareness Month, incidents like this provide a useful opportunity to reflect on whether security controls, awareness efforts and response plans remain aligned to today's threats.
 
Awareness should extend beyond employee training. Organisations need to ensure that the systems used to communicate with customers have appropriate access controls, monitoring and response processes.
 
Publicity around a recognised brand may also be exploited by opportunistic scammers. The National Cyber Security Centre (NCSC) has advised consumers to remain cautious of unexpected communications relating to the incident. Customers and employees should be cautious of unexpected password-reset messages, compensation offers and requests to verify account information. This is a precaution, not evidence that these scams are connected to the reported incident.

 

Five questions every organisation should ask

1. Who has access to customer communication platforms?

Push notifications, social media and customer portals can all influence trust. Make sure you know exactly who can access and manage them.

2. Are permissions and access controls up to date?

 People change roles and suppliers change over time. Regular reviews help ensure users only have access to what they genuinely need.

3. Is multi-factor authentication (MFA) enabled?

A password alone is rarely enough. MFA adds an extra layer of protection to customer-facing systems and administration tools.

4. Would you spot unauthorised activity quickly?

The faster unusual activity is identified, the quicker it can be contained before it affects customers or damages confidence.

5. Do you have a response plan for communication channels?

 
An incident can quickly become public. Have a clear process for managing systems, stakeholders and customer communications.

 

What should businesses do next?

Use Cyber Security Awareness Month to review whether your current cybersecurity strategy covers the full range of systems through which customers interact with your organisation.
 
Start with a focused assessment of mobile apps, notification services, customer portals and third-party communication platforms. Confirm who has access, how activity is monitored and what would happen if a trusted channel were compromised.
 
The goal is simple: understand where your organisation is exposed, who is responsible for managing risk, and how you would respond if a trusted communication channel was compromised.
 
The ASOS incident also serves as a reminder that effective cyber security is not just about preventing attacks. It's about helping employees and customers recognise suspicious activity when incidents become public. Awareness remains one of the most important layers of defence.
 
 
 

forum_300dp_2640FF_FILL0_wght400_GRAD0_opsz48F5 DISCUSSION POINT

Cyber Security Awareness Month is an opportunity to take stock of your organisation's security posture. Are your current controls, processes and awareness efforts keeping pace with the way people, customers and attackers interact with your business today?