Back to all news
Cybersecurity 2 min read

ASOS Data Breach Highlights Mobile App Notification Risks for Fiji Businesses

UK retailer’s hacked in‑app alerts expose a vulnerability that Pacific firms must guard against

ASOS confirmed a data breach after hackers sent unauthorized push notifications through its mobile app, underscoring the need for Fiji businesses to secure notification channels and verify digital communications.

What happened

UK fashion retailer ASOS confirmed a data breach on Tuesday after hackers sent unauthorized push notifications through its mobile app. The breach was disclosed after the retailer detected the malicious in‑app alerts, which were labelled “HACKED” and warned shoppers not to click on the messages.

Why it matters

The incident shows that attackers can compromise a brand’s mobile‑app infrastructure to deliver fraudulent notifications directly to users. Unlike phishing emails, push notifications appear to come from a trusted source and can bypass many traditional email‑security controls. When users interact with a malicious notification, they may expose personal data or credentials, amplifying the impact of the breach.

What this means for Fiji businesses

For Fiji businesses, this means that any organisation that uses mobile apps to engage customers—retailers, banks, tourism operators, and utility providers—faces a similar threat vector. Even if a breach originates abroad, the tactics can be replicated locally. Key implications include:

  • Trust erosion: Customers who receive fake alerts may lose confidence in the brand’s digital channels.
  • Regulatory exposure: If personal data is accessed, businesses could face compliance issues under Fiji’s data‑protection framework.
  • Operational disruption: Responding to a notification‑based attack can divert resources from core activities.

What businesses should do now

  1. Audit notification infrastructure – Review the security of any push‑notification services, SDKs, or third‑party providers integrated with your apps.
  2. Implement multi‑factor verification – Require additional authentication for actions triggered by notifications, such as password changes or payments.
  3. Educate users – Publish clear guidance that your organisation will never ask for sensitive information via push alerts and encourage users to verify any unexpected messages through official channels.
  4. Monitor for anomalies – Deploy real‑time monitoring to detect unusual notification traffic patterns or unauthorized API calls.
  5. Establish an incident‑response plan – Ensure your team can quickly isolate compromised components, communicate with customers, and coordinate with regulators if personal data is at risk.

By taking these steps, Fiji businesses can reduce the likelihood that a breach similar to ASOS’s will affect their customers and reputation.

Independent evidence

Sources

3 sources

Aura Digital Fiji · Digital services

Need help applying this technology to your business?

Custom websites, ecommerce, business email, security, mobile apps and IT systems built for Fiji businesses.

Continue reading

Related intelligence

All news →