Asos just got hacked, and the hackers made sure everyone knew it.
The fashion retailer confirmed a breach of customer data after attackers sent a push notification directly to Asos app users. The message claimed the hackers had "fully compromised" the company's cloud storage. That's an unusually loud way to announce a breach. Most attackers prefer to stay quiet while they extract data; these ones used Asos's own notification system as a bullhorn, which suggests either a point to prove or leverage for extortion.
The bigger worry here isn't just stolen data, it's the access required to pull this off. Sending a push notification through a company's app typically means getting into backend systems that control customer communications, not just a database dump. That points to a deeper intrusion than a simple leak, and it raises the question of what else those attackers could touch.
Asos joins a long line of retailers learning that cloud storage is only as secure as the credentials and permissions guarding it. The company hasn't detailed what customer data was exposed, but turning its own app into a megaphone for the attackers is the kind of detail that will stick in customers' minds long after the technical postmortem is forgotten.