Wednesday, 7 October 2026
GoCardless
ColumnCybersecurity

ASOS shows why customer messaging tools are a board-level risk

A rogue alert reached ASOS app users on 6 October and the shares fell as much as 10%. But the platforms involved were customer-messaging tools, which mid-market boards should govern like their finance systems

An ASOS Face + Body event space with a branded reception desk
Image: ASOS
In brief
  • The ASOS share price fell as much as 10% before the company had said what data, if any, was affected.
  • Every tool that can message customers or holds their contact details needs a named owner, regular access reviews and single sign-on with multi-factor authentication for admins.
  • Directors should confirm their cyber policy responds to incidents on third-party platforms and to business interruption when operations keep running.

At around 10am on 6 October, ASOS customers received a notification the company had not authorized. In a stock exchange announcement that afternoon, the online fashion retailer said it was investigating “unauthorised activity involving third-party platforms that we use to communicate with customers” and had taken immediate action to restrict access to its notification platforms.

According to City AM and The Record, the message was addressed to the company’s data protection officer and IT team, claimed access to a cloud data store and threatened a leak unless ASOS engaged. Snowflake, the data platform it named, said it had found no compromise of its platform, Infosecurity Magazine reported.

ASOS said basic personal information, including names and contact details, may have been accessed. It did not believe payment-card information or account passwords were affected, and its website and app were operating as normal. By then the shares had already fallen. City AM reported that morning that they were down as much as 10%, at 439p.

ASOS has not said that any customer data was taken, and its investigation continues. Whatever it finds, mid-market boards should treat the software a business uses to talk to its customers – push notifications, email and SMS platforms, customer relationship management (CRM) and marketing automation, and the data stores behind them – as part of the cyber perimeter. Whoever controls that software speaks for the company.

Bring marketing tools inside the perimeter

In many mid-sized firms, customer-messaging tools are bought by the marketing or ecommerce team, administered by whoever set them up and linked to the customer list through integrations that may not have been reviewed since launch. They rarely sit on the risk register next to the finance system, the network and backups. Yet they hold every customer’s contact details and can reach all of them in minutes.

Anastasia Tikhonova, global head of threat research at Group-IB, told Infosecurity Magazine that her team had seen no sample or dump supporting the claims about ASOS customer data, and that sending a notification shows someone can use a messaging channel, not that they hold a customer database. Customers reading the alert on their phones had no way of knowing that. Charlotte Wilson, an executive at Check Point, said in comments reported by The Record that, if confirmed, the attackers appeared to have “turned ASOS’s own app into their ransom note”.

The ASOS Android app has been downloaded more than 10 million times on Google Play, BBC cyber correspondent Joe Tidy said in comments carried by Help Net Security. A mid-market retailer, wholesaler or software firm has a fraction of that audience, but one compromised admin login on its messaging tool could still reach every customer on its list.

Give every customer tool an owner

Boards should ask for a list of every supplier platform that can message customers or holds their contact data, with a named owner for each. Then they should check the basics:

  • single sign-on and multi-factor authentication on every admin account, with no shared logins
  • regular access reviews that remove leavers, agencies and former contractors
  • application programming interface (API) keys and integrations recorded, scoped to what they need and rotated
  • alerts on unusual activity, such as a broadcast sent outside a scheduled campaign

Most of these controls are settings in tools the business already pays for. What tends to be missing is a named person responsible for switching them on, and a board that asks to see proof.

Plan for a message you did not send

Incident plans are usually written for an attacker who stays out of sight. Many ASOS customers learned of this incident from the rogue message itself, hours before the company’s statement. Plans should name who can cut access to each messaging platform within minutes, including out of hours, who writes the correction and which channel the business will use to reach customers when its usual one cannot be trusted.

The ASOS announcement shows what a first statement can cover. By that afternoon it had set out what happened, what the company had done, what data may have been accessed, what it believed was unaffected and that the website and app were running normally. It also disclosed that it holds cybersecurity insurance with a large global provider, including business continuity cover, and said it was too early to quantify any impact on trading.

Read the policy before you need it

Directors should read their own policy with that disclosure in mind. Does it respond to an incident on a third-party platform the business does not run? Does business interruption cover apply when systems keep working but sales or reputation suffer? Which advisers and notification deadlines does the insurer require?

Customer channels are part of the security perimeter, whoever signed the contract. A board that cannot say who controls each one, and how quickly that access can be cut, is leaving its brand’s voice to whoever holds the password.

AdvertisementZoomInfo

Get The VETTDD BriefingThe week in B2B technology, every week.

Subscribe free
Sources
  1. ASOS plc, “Update regarding cyber incident”, RNS announcement, 6 October 2026. https://www.investegate.co.uk/announcement/rns/asos--asc/update-regarding-cyber-incident-/9809595
  2. Help Net Security, “ASOS confirms data breach after ‘hacked’ app alert reaches shoppers”, news article, 7 October 2026. https://www.helpnetsecurity.com/2026/10/07/asos-data-breach-app-notification/
  3. The Record, “Shares in British clothing company ASOS dive after hackers apparently send push notification”, news article, 6 October 2026. https://therecord.media/asos-push-notification-apparently-sent-by-hackers
  4. City AM, “Asos shares crater after ‘hackers’ threaten data leak”, news article, 6 October 2026. https://www.cityam.com/asos-shares-crater-after-hackers-threaten-data-leak/
  5. Infosecurity Magazine, “ASOS customers receive bizarre ‘hacked’ message amid suspected Snowflake compromise”, news article, 6 October 2026. https://www.infosecurity-magazine.com/news/asos-customers-message-suspected/
  6. Infosecurity Magazine, “Telegram account behind ASOS rogue notification tied to gaming trading”, news article, 7 October 2026. https://www.infosecurity-magazine.com/news/telegram-accoun-asos-tied-gaming/
Editor
About the author

Editor

The VETTDD editorial desk. Interviews, analysis, columns and news on the decisions shaping UK B2B technology.

More from Editor