The BBC reports that dozens of ASOS app users received a strange push notification that appears to have come from hackers. The cause has not been confirmed. Incidents like this usually involve the alert system rather than customer accounts.
Key takeaways
- The BBC reports that dozens of people appear to have received an unusual push notification through the ASOS shopping app.
- It is not publicly known how the message was sent, who sent it, or whether any customer data was affected.
- Push notifications are normally sent through a separate system from the app itself, often run with an outside messaging provider.
- An unauthorised push alert shows that someone could send messages, but on its own it does not prove that customer accounts or payment details were accessed.
- Users who received an unexpected alert should avoid tapping any links in it and should rely on official channels for updates.
What has happened to the ASOS app?
According to the BBC, dozens of people appear to have received a strange message from the ASOS app, the mobile app of the online clothing and beauty retailer. The notifications are reported to have apparently been sent by hackers, not by the company’s own marketing team.
Several important details are not known publicly at the time of writing. These include the exact wording of every message, how many users received it in total, how the sender was able to trigger it, and whether the incident involved anything more than the notification channel. This article does not guess at those points. It explains how app notifications work, why a stray message matters, and what it can and cannot tell us.
Why is this in the news now?
Push notifications appear on a phone’s lock screen and carry the trusted name and icon of the app. When a well-known retailer’s app sends something that clearly did not come from its marketing team, people notice straight away. Many then share screenshots and ask whether anyone else received the same thing.
That visibility is the main reason the story has spread. Most security incidents happen out of sight and come to light weeks or months later through disclosures or investigations. A rogue push alert lands directly in front of customers. It is a public signal that something has gone wrong, even before the company has explained what that something is.
How do app push notifications actually work?
Some background helps explain what a hacked notification could mean. When someone installs a shopping app and allows notifications, their phone registers with the operating system’s push service. On iPhones this is Apple’s push notification service. On Android phones it is usually Google’s Firebase Cloud Messaging. The phone receives a token, which is essentially an address the app’s operator can use to reach that device.
The retailer stores these tokens, often through a customer engagement or marketing platform, and uses them to send alerts about sales, deliveries or abandoned baskets. To send a message, the sender needs valid credentials for the push service or for the platform that sits in front of it. These credentials may be keys, certificates or login details for a marketing dashboard.
This means a push notification can be sent without anyone touching the app’s code, the shop’s website or its customer database. Anyone who holds the right credentials, or who gets into an account on a connected platform, may be able to send messages to some or all registered devices.
Security researchers have described several common weak points over the years. They include credentials accidentally left in app code or public code repositories, compromised staff logins for marketing tools, and weaknesses at third-party providers that serve many brands at once. Which of these, if any, applies to ASOS is not known.
Who is affected and how?
The people directly affected are app users who received the message. The BBC describes them as dozens of people. Whether more received it, or whether it went only to a subset of devices, has not been established publicly.
For most recipients the immediate effect is confusion and possibly alarm. The bigger risk depends on what the message contained. A notification that is simply odd or offensive is mainly a reputational problem for the company. A notification that urges users to tap a link, enter details or contact someone is more serious. It can be used for phishing, because it arrives under a brand people already trust.
The retailer is also affected. Even when no data is taken, an unauthorised message suggests that some part of its communications set-up was open to misuse. The company will want to find out how that happened and to close the gap. It may also have to consider whether the incident triggers any reporting duties. That depends on facts that are not yet public.
Where do informed people disagree?
Security professionals often disagree about how much to read into incidents like this. One view is that a hijacked notification channel is a fairly contained problem. In this view, a leaked key or a single compromised marketing login lets someone send messages, but it does not necessarily give access to names, addresses, order histories or payment information, which are usually held in separate systems.
Another view urges more caution. Whoever could send push alerts may also have been able to see the list of registered devices, any customer segments stored on the same platform, or other connected services. Until an investigation has mapped exactly what the intruder could reach, some experts argue it is premature to call the incident harmless.
There is also a wider debate about the reliance on third-party marketing and messaging platforms. They let retailers run sophisticated campaigns without building everything themselves. They also add more accounts, keys and suppliers that must each be secured. Some argue that brands should treat the ability to message every customer as a high-privilege function, protected as carefully as access to payment systems. Others note that this adds friction to everyday marketing work. In this case it is not known whether a third party was involved at all.
What should app users do now?
For individuals the practical steps are modest and sensible regardless of the eventual explanation.
Anyone who received an unexpected message through a retail app should not tap links in it. If they already did, they should not enter passwords, payment details or personal information on any page that opened. Going directly to the app or website by typing the address or opening the app normally is safer than following a notification.
Changing the account password is a reasonable precaution, especially if the same password is used elsewhere. Unique passwords and a password manager limit the damage if any single service is compromised. Where a service offers two-step verification, switching it on adds another layer of protection.
Users can also review notification settings. Phones let people turn off alerts for individual apps, and doing so removes one route for this kind of message. It is also worth watching bank statements and inboxes for unusual activity. Users should be wary of follow-up emails or texts that mention the incident, because scammers often exploit news stories to make their own messages seem credible.
What should we watch for next?
The most important next step is any official explanation from the company. That would include how the message was sent, whether the cause has been fixed, and whether any customer information was exposed. Until then, reports on social media and screenshots should be treated as partial evidence rather than a full account.
It will also be worth watching whether a third-party service is named as the source of the problem. If a shared platform turns out to be involved, other brands that use it could face similar questions.
Finally, the incident may add to existing industry discussion about protecting customer messaging tools: rotating keys regularly, limiting who can send to an entire user base, and requiring strong authentication for marketing dashboards. Whether this particular case prompts any change in practice is not yet known.
Frequently asked questions
Was the ASOS app hacked?
The BBC reports that dozens of users received a strange push notification that appears to have been sent by hackers. However, the exact cause has not been publicly confirmed. A rogue notification can result from misuse of the push messaging system or a connected marketing platform. It does not necessarily mean that the app itself or its customer database was broken into.
Is my ASOS account or payment information at risk?
It is not publicly known whether any customer data was accessed. Unauthorised push notifications are often sent through messaging credentials that are separate from account and payment systems, but that has not been confirmed in this case. As a precaution, users can change their password, use a unique password for each service and keep an eye on their bank statements for anything unusual.
What should I do if I received the strange notification?
Do not tap any link in the message. If you already have, do not enter any personal or payment details on the page that opened. Open the app or website directly instead. Changing your password is a sensible precaution. You may also want to turn off notifications for the app until the company has explained what happened and confirmed the problem is fixed.
How can hackers send push notifications through someone else’s app?
Push alerts are sent through services run by phone platform providers, often via a marketing or messaging platform. Anyone who obtains the right sending credentials, such as an exposed key or a compromised staff login on a connected dashboard, may be able to send messages to registered devices without changing the app’s code or reaching its customer records.
Can a push notification itself infect my phone?
A push notification is normally a short message displayed by the operating system, and simply receiving one is generally not considered a way to install malicious software. The main risk is what the message persuades you to do, such as opening a link to a fake login page or sharing personal details. Keeping your phone’s software up to date further reduces risk.
How do I stop notifications from a shopping app?
Both iPhone and Android phones let you control notifications app by app. Open the phone’s settings, find the notifications section, select the shopping app and switch its alerts off. Many apps also have their own notification preferences inside their account or settings menu. Turning alerts off does not delete your account, and you can switch them back on later.
Sources and further reading
- BBC News technology coverage reporting that ASOS app users received a strange notification apparently sent by hackers.
- Developer documentation from mobile platform providers explaining how app push notification services and device tokens work.
- Guidance from the UK National Cyber Security Centre on recognising phishing and securing online accounts.
- Information Commissioner’s Office material on organisations’ responsibilities when personal data may be affected by a security incident.
Surfaced from the rss:bbc_tech signal “rogue retail app notifications”. AI-assisted draft, editorially reviewed.

