Digital Transformation · 9 October 2026
Asos Confirms Data Breach After Hackers Hijack App Alerts
Asos confirmed hackers accessed customer data after attackers used its own mobile app to send a rogue push notification claiming its cloud storage was compromised, seizing control of disclosure before Asos could respond.
What happened
Asos has confirmed that hackers accessed customer data after attackers used the fashion retailer's own mobile app to send a push notification claiming they had "fully compromised" its cloud storage. The unauthorised notification alerted customers directly, effectively forcing the company's hand on disclosure before it could manage the announcement through its own channels.
According to TechCrunch, Asos has acknowledged the breach but has not yet detailed the scope of the data accessed, how the intrusion occurred, or how many customers are affected. The incident is notable less for its technical specifics, which remain under investigation, and more for the unusual method of disclosure: the attackers chose to notify Asos customers themselves, via a channel customers would ordinarily trust.
Why it matters
For a retailer, the app push notification is a core trust touchpoint — used for order updates, promotions and account alerts. Hijacking that channel to announce a breach turns a routine piece of customer infrastructure into a vector for shock and confusion, undermining confidence in every future notification the brand sends. It also strips the company of control over the narrative at the most sensitive moment of incident response.
The episode is a reminder that breach response is now a customer experience discipline as much as a security one. How, when and through which channel a company communicates a compromise shapes customer trust as much as the breach itself — and attackers are increasingly aware that disrupting a brand's own communication tools amplifies reputational damage.
The Renascence take
Most coverage of incidents like this focuses on the technical breach. The more instructive story is the communications failure it exposes.
When attackers can out-communicate a brand to its own customers, the real vulnerability isn't just technical — it's an absence of a rehearsed, channel-agnostic crisis communication protocol. Customers forgive breaches more readily than they forgive silence or confusion in the aftermath. Service-design teams should treat "who tells the customer, and how fast, and through which trusted channel" as seriously as the security patch itself — because in the time it takes legal and PR to agree a statement, an attacker can already be inside the inbox or the app customers check first.
Sources
This briefing was written by our Newsdesk, synthesising reporting from the outlets below. Follow the links for the original coverage.
FAQ
Questions we get on this topic
More in Digital Transformation
Stay ahead of CX
Get the signal, not the noise.
The stories shaping customer experience — plus the Journal and Experience Loom — in your inbox.
