Summary
- ASOS says an unauthorised customer notification was sent at around 10am on 6 October.
- The retailer is investigating activity involving third-party platforms used to communicate with customers.
- Names and contact details may have been accessed, but ASOS does not currently believe card data or account passwords were affected.
ASOS is investigating unauthorised activity involving third-party platforms used to communicate with customers after an unauthorised notification was sent through its customer channels on 6 October.
In a regulatory announcement issued later that day, ASOS said the notification was sent at around 10am and that access to the affected notification platforms was restricted after the activity was identified.
The retailer is working with internal and external specialists and relevant authorities while it investigates what happened and what information may have been accessible.
ASOS said: “Basic personal information including name and contact details may have been accessed. We do not believe that payment-card information or account passwords, were impacted.”
The company has not said how many customers may be affected, identified an attacker or disclosed how access to the third-party communications platforms was obtained.
Its website and app remained operational, and ASOS said it was not experiencing wider disruption to current operations. The retailer also disclosed that it holds cybersecurity insurance, including business continuity cover, while saying it was too early to quantify any potential impact on trading.
Communications platforms carry their own customer risk
A service used to send notifications can sit outside payment and account authentication systems while still holding customer information and controlling a communication channel associated with the retailer.
Unauthorised access can therefore create two different problems. Personal information accessible through the service may be exposed, while control of the notification channel can allow messages to arrive through a route customers recognise as legitimate.
The National Cyber Security Centre issued its own notice after the incident and advised ASOS customers to assume they may be affected even if they did not receive the unauthorised notification.
The NCSC repeated ASOS’s current assessment that payment card information and account passwords are not believed to have been affected. It also warned that exposed contact information could be used to make later fraudulent messages more convincing.
That warning does not mean fraud using the information has already occurred. It reflects the secondary risk created when names and contact details become available to an unauthorised party.
ASOS has so far confined its disclosure to the third-party communications platforms under investigation. It has provided no evidence that its main website, app, payment processing environment or password systems were compromised.
The company has also not identified the providers involved. Without that information, it is not possible to establish whether the incident began with stolen credentials, misuse of a supplier account, a weakness in the platform or another route.
Restricting access to the affected platforms was the containment action ASOS disclosed. The company has not described the technical steps behind that action.
The investigation still has to establish how many people were affected and whether any information beyond the categories already disclosed was accessed. The confirmed position remains that names and contact details may have been exposed, while ASOS does not currently believe payment card information or account passwords were affected.





