UK-based fashion e-commerce giant Asos has revealed that it suffered a customer data security breach. The incident came to light after attackers exploited the company's official mobile app to send unauthorized push notifications to users.
This incident involves the abuse of a legitimate application notification platform. Attackers leveraged the company's system to transmit push notifications directly to users' devices, delivering malicious links and messages. Asos is currently working with a dedicated security team to conduct a detailed investigation into how the attackers hijacked the notification system and to determine the scope of any potential customer data leakage.
Taking the situation very seriously, Asos is prioritizing the identification and remediation of potentially affected systems and vulnerabilities. The company has urged users to ignore and not interact with any suspicious notifications. While push notification features on digital platforms are essential for enhancing user experience, this incident demonstrates how they can also serve as an attack vector. Consequently, it serves as an important lesson for companies moving forward to strengthen the security of their API management infrastructure, including notification systems.