Security

ASOS App Users Report Suspicious Push Notifications: Was It a Hack?

By

Padlock
Photo via Wikimedia Commons

What happened: Today, on October 6, 2026, users of the popular online fashion retailer ASOS's mobile app began reporting a flurry of strange and seemingly unauthorized push notifications. These alerts, appearing on their smartphones, contained nonsensical messages or suspicious links, leading many to believe that the company's notification system had been compromised. Screenshots shared online showed varied content, from gibberish to messages that appeared to be from an external, potentially malicious actor.

Why it matters: For a major e-commerce platform like ASOS, a security incident involving push notifications is a serious concern. It directly impacts customer trust and raises questions about the integrity of the company's digital infrastructure. If hackers gained control of the notification system, there's a risk that users could be directed to phishing sites, tricked into revealing personal information, or even exposed to malware. This incident highlights the critical importance of securing every layer of a digital service, including seemingly simple communication channels.

Deep dive: Push notifications are messages sent from an app or website directly to a user's device. They are typically used for legitimate purposes like order updates or promotional offers. However, if the system responsible for sending these notifications is compromised – either through a vulnerability in ASOS's own backend, a breach of a third-party notification service provider, or an internal error – it can be misused. Attackers might exploit access to send out spam, deface the brand, or, more dangerously, distribute malicious links designed to steal user credentials or install unwanted software. Understanding the vector of attack is crucial for preventing future incidents and assessing the full scope of potential damage.

Report check: This incident gained traction after appearing on Hacker News, with a BBC News article serving as a primary source. The article reports on widespread user complaints and ASOS's initial acknowledgement of 'unusual activity' within its notification system. While ASOS has confirmed the unusual messages, it has not yet definitively confirmed a 'hack' or detailed the precise cause of the notifications. The nature of the breach (external attack vs. internal system error) and its full implications are still under investigation.

Open questions: The key questions that remain are: What was the exact cause of these unauthorized push notifications? Was it an external cyberattack, an internal system misconfiguration, or a compromise of a third-party vendor? What, if any, user data might have been accessed or exposed during this incident? What steps is ASOS taking to secure its systems and prevent similar occurrences, and how will they communicate updates to their customer base?