ASOS Confirms Credential Breach After Hackers Send Fake Push Notification
ASOS has confirmed that a cyber‑attack compromised an employee account, allowing hackers to dispatch a fraudulent push notification to users.
The breach came to light during an internal security review, after which the retailer engaged independent cybersecurity experts to conduct a thorough investigation.
Investigators determined that the perpetrators gained entry by exploiting the employee's login details, then leveraged the compromised account to issue a push alert that appeared to originate from ASOS itself.
According to the company, the intrusion exposed limited personal data, including names and contact information, as well as certain non‑personal account‑related details. No financial information, passwords or payment data were reported as accessed.
ASOS responded by disabling the rogue notification, resetting credentials for affected accounts, and implementing additional authentication safeguards.
Security analysts note that credential theft and social‑engineering tactics continue to be prevalent threats for online retailers, especially those with extensive mobile app ecosystems.
The incident highlights the ongoing need for robust multi‑factor authentication and continuous monitoring. ASOS said it will review its security measures and cooperate with relevant regulators as it works to prevent future breaches.
Comments (0)
Be the first to comment.
Join the discussion