SecurityWeek reported on October 7, 2026 that ASOS confirmed a cyber incident after customers received an unauthorized notification through the retailer's app. ASOS said it was investigating unauthorized activity involving third-party platforms used to communicate with customers, and the company's customer notice told users to disregard the unauthorized notification and avoid the external link it contained.
The business lesson is bigger than one retailer. Many New Jersey businesses use customer messaging platforms for appointment reminders, billing alerts, app notifications, marketing campaigns, patient reminders, support updates, and account notices. If a vendor account can send a trusted message to customers, that tool belongs in the security and incident response plan.
The Risk Is the Trusted Channel
A push notification, email campaign, text alert, or customer portal message feels official because it arrives through a familiar channel. That is exactly why vendor access to customer notifications deserves attention. A third party communication platform breach can create confusion even if the main website, payment processor, or internal network is not the first system involved.
ASOS has said customers should ignore the unauthorized message and not interact with the third-party link. Reporting also noted that basic personal information such as names and contact details may have been accessed, while payment-card information and passwords were not identified as impacted in the cited coverage. That distinction matters, but it does not make the communication problem small. A trusted alert channel can move from helpful to harmful very quickly.
The Owner Decision
The owner decision is whether customer notification platform security is treated as a marketing setting or as a business-critical control. If the tool can reach customers at scale, it should have the same management discipline as other sensitive systems: named owners, multifactor authentication, role limits, vendor oversight, audit logs, and a way to pause outbound messages during an incident.
For smaller organizations, this may include tools used by the website vendor, CRM provider, appointment system, patient communication platform, school messaging tool, or e-commerce plugin. The risky part is often not the tool itself. It is the assumption that someone else is watching it.
Questions to Ask Your IT Provider or Vendor
- Which systems can message customers directly? Include email marketing tools, SMS platforms, app notifications, website chat, CRM workflows, billing alerts, and appointment reminders.
- Who has administrator access? Ask for named roles, not a general answer that the vendor manages it.
- Is multifactor authentication required? Customer-facing communication tools should not depend only on a password or shared account.
- What audit logs are retained? The business should be able to see who created a message, changed a template, added a link, exported contacts, or connected an integration.
- How fast can outbound messaging be paused? During a push notification cyber incident, speed matters. The business needs to know who can stop campaigns and revoke vendor sessions.
- What customer data is stored in the platform? Names, email addresses, phone numbers, order history, appointment details, and support notes each change the response plan.
- What does the vendor owe you after an incident? Ask about notification timing, log access, investigation support, subcontractors, and evidence that access was contained.
A Practical Next Step
Pick one customer-facing channel this week and trace it from message creation to delivery. Who can send a message? Who approves it? Which vendor hosts it? What customer data does it store? What logs are available? Who can disable it after hours?
That review does not need to become a giant policy project. Start with a simple list of customer communication tools and mark each one with an owner, admin users, MFA status, stored data, vendor contact, and emergency shutoff path.
Customer notifications are useful because people trust them. That trust is also the risk. When a communication platform becomes part of an incident, the business needs more than a login. It needs evidence, authority, and a plan for what happens before the next message goes out.
Sources and further reading