Source: Agence France-Presse
On October 6, 2026, millions of ASOS customers received a push notification that no retailer ever wants to send. The message was titled “Asos hacked” and pointed to a Telegram account, and the retailer did not send it. Attackers had gained access to the notification platforms ASOS uses to communicate with its 17 million active customers and pushed an extortion note straight into their pockets.
What actually happened
According to a statement from ASOS, the company is investigating unauthorized activity involving the third-party platforms it uses for customer communications. It took immediate action to restrict access to those platforms and is working with internal and external specialist advisers and all relevant authorities. The company said personal information such as names and contact details may have been accessed, but it does not believe payment card information or account passwords were impacted, and its website and app continued operating normally. The attacker message claimed a full compromise of a Snowflake instance, but Snowflake told reporters it has found no compromise of its platform so far.
Why the notification channel is the real story
The most uncomfortable detail for every engineering and security leader is the delivery mechanism. The attackers did not need to breach the ASOS application itself to cause a public crisis. By compromising a third-party messaging platform they reached every customer instantly, with a message the company could not recall. The market reaction was immediate, with ASOS shares slumping almost 15 percent in London before partially recovering, still down nearly 10 percent by the afternoon. Britain’s NCSC has offered assistance, and the ICO said it had not received a report on the matter at that stage, which puts the focus squarely on the 72-hour GDPR notification window.
The UK and European context
This is not an isolated event. UK businesses have faced a sustained wave of attacks, including M&S, Harrods, the Co-op and Jaguar Land Rover last year, and the Manchester Airports Group breach in August. Each incident reinforces the same lesson: your incident response plan is only as good as its coverage of third-party channels, and regulatory deadlines do not wait for perfect information. ASOS told shareholders it has cyber insurance but that it is too early to quantify the impact.
If your organization relies on third-party platforms for customer communication, now is the time to audit who can send messages, rotate those credentials, and rehearse the scenario where the channel itself is weaponized. Contact Excello Digital at https://excello.digital/contact/ and we will help you harden your notification and messaging stack, tighten third-party access, and build an incident response plan that satisfies GDPR timelines before the clock starts.
