BlackTree Security · Infrastructure · Automation · AI

ASOS Says Contact Details May Be Affected

ASOS says some customers received an unauthorised push notification on 6 October. Basic personal information, including names and contact details, may have been accessed. The retailer does not believe payment-card information or account passwords were affected.

The National Cyber Security Centre says every ASOS customer should assume they are affected, even if they did not receive the notification. Do not use its external link. Open the ASOS website or app independently and remain alert for suspicious messages that may arrive later.

What ASOS has confirmed

ASOS restricted access to the notification platforms. Its website and app remain available. It is not currently asking customers to change their ASOS account password.

Treat follow-up messages as untrusted

The NCSC advises customers to watch for scams, review account activity and use passkeys or strong, separate passwords with two-step verification. That is general protective advice, not evidence that ASOS passwords were taken. Preserve suspicious messages and report fraud through an official channel.

BlackTree’s analysis of the Trezor and Brevo incident shows why a real communications channel can still carry a hostile message. That comparison supports independent verification, not a claim of a shared supplier, attacker or technique.

What remains unknown

Neither notice identifies the platform, technical cause, actor, total customer count or whether data was copied. No provider or common cause should be inferred.

Sources: ASOS customer notice, inspected 6 October 2026; NCSC alert, published 6 October 2026; and BlackTree’s Trezor/Brevo analysis, published 11 September 2026 and updated 21 September 2026.

Leave a Reply

Your email address will not be published. Required fields are marked *