ASOS is investigating unauthorised activity involving third-party platforms used to communicate with customers after an unauthorised notification was sent through its systems.
The online fashion retailer said the notification was issued to customers at around 10am on 6 October.
Basic personal information, including names and contact details, may have been accessed. ASOS said it does not believe payment-card information or account passwords were affected.
The company has restricted access to the relevant notification platforms and is working with internal and external specialists and the relevant authorities.
Its website and app remain operational, with no current disruption to trading. ASOS said it is too early to quantify any potential impact and noted that it holds cyber-security and business-continuity insurance.
The incident highlights the importance of including customer-communication tools within retailers’ wider security controls, even when their core ecommerce platforms remain available.








Share