Asos is currently investigating reports of "unauthorised activity" involving third-party platforms after customers received alarming notifications from its app, reportedly sent by hackers. On Tuesday morning, numerous users reported receiving a message titled "ASOS HACKED", which has left many feeling uneasy about the security of their personal information.

Incident Overview

The notification was directed to the company's data protection officer and IT teams, and cybersecurity experts have described it as a "brazen" extortion attempt. Asos confirmed the "unauthorised customer notification" on Tuesday afternoon, acknowledging that some "basic personal information" may have been accessed.

In an email sent to customers later that evening, Asos apologized for the incident and advised users not to engage with the notification. The company reassured customers that its website and app are "operating as usual", encouraging them to "shop with confidence" while the investigation is ongoing.

Scope of the Breach

While the exact number of affected customers remains unclear, the ASOS app has been downloaded over 10 million times on Android devices. Reports indicate that users in Australia, France, Sweden, and the Republic of Ireland also received the notification.

Shares in Asos fell by approximately 10% following the incident. Charlotte Wilson, head of enterprise at cybersecurity firm Check Point, described the attack as "deeply serious" and noted that the hackers had effectively turned Asos' own app into their ransom note.