# ASOS investigates breach exposing customer data

Published: 2026-10-06 · Severity: routine · Sectors: retail
Canonical: https://vorant.io/reports/16db732b-e17e-55b5-abae-129ba594ef57/asos-investigates-breach-exposing-customer-data

> ASOS customers may have had names and contact details accessed after an unauthorised push notification was sent, NCSC warns.

The UK's National Cyber Security Centre has issued guidance following a cyber incident affecting ASOS, the online fashion retailer. On Tuesday 6 October, some ASOS customers received an unauthorised push notification, prompting an investigation by the company. ASOS has confirmed that basic personal information - including customer names and contact details - may have been accessed by the unauthorised party, though the company states it does not believe payment card information or account passwords were compromised.

The NCSC advises that all ASOS customers should assume they are affected by this incident, even those who did not personally receive the unauthorised notification. This suggests the scope of the data access may extend beyond the subset of customers who received the push notification, indicating broader exposure of the customer database or contact information.

Defenders and affected individuals should be alert to follow-on phishing or smishing attempts, which often arrive some time after an initial data breach is disclosed, exploiting the leaked contact details. The NCSC recommends standard post-breach hygiene: avoiding suspicious links in notifications, emails, or messages purporting to be from ASOS, and strengthening account security using passkeys or strong, unique passwords combined with two-step verification, even though passwords are not believed to be affected in this instance.

Source reporting: https://www.ncsc.gov.uk/news/incident-affecting-asos-customers

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/16db732b-e17e-55b5-abae-129ba594ef57/asos-investigates-breach-exposing-customer-data.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
