ASOS Cyber Attack: What IT Leaders Can Learn About Third-Party Risk
The ASOS cyber attack reported on 6 October 2026, has raised fresh questions about third-party access, SaaS security and how modern organisations manage an increasingly connected attack surface. The incident became public in an unusual way: customers received an unauthorised mobile push notification through the ASOS app claiming the retailer had been compromised. ASOS later confirmed that basic personal information, including names and contact details, may have been accessed.