ASOS has confirmed a breach involving customer data after hackers sent a push notification through the fashion retailer’s app. The message claimed that the attackers had “fully compromised” the company’s cloud storage, according to a report by TechCrunch.
The use of an official app notification gave the claim an unusually direct route to customers. Instead of relying on an external leak site or social-media post, the attackers used a communications channel associated with the company itself.
The available information does not establish how the hackers gained the ability to send the notification, or whether that access was connected to the claimed cloud-storage compromise. ASOS’s confirmation means the incident extends beyond an unverified attacker assertion, but the scope of the affected data has not been detailed in the reported information.
For technology teams, the episode underlines the importance of treating notification services, mobile-app administration and cloud access as connected parts of the security perimeter. A compromised customer-facing channel can amplify a breach quickly, while also making incident communication more difficult for the affected company.
