Cybercriminals Apologise for Bypassing Proper ASOS Customer Service Channels

A hacking collective that sent an unauthorised notification to ASOS app users on Tuesday has issued a formal apology for failing to submit their data breach through the retailer's established customer service system.

The group, which accessed the fashion retailer's notification platform and messaged millions of users directly, acknowledged in a statement that they should have opened a support ticket under the "Data Access Request" category and waited the standard 28 business days for an initial response. The hackers admitted their direct notification approach violated the company's clearly stated communication protocols, which require all queries to be submitted through a dropdown menu on the website.

The collective said they had subsequently attempted to retroactively file their extortion demand through proper channels but encountered technical difficulties when the online form rejected their Telegram handle as an invalid contact method. They have since requested guidance from ASOS on whether to categorise the incident under "Account Security," "Order Problem," or "General Inquiry."

ASOS confirmed it would have processed the ransom demand through normal procedures but cannot locate any corresponding ticket in its system. A company spokesperson said the IT and data protection teams check the support queue hourly and would have escalated the matter to the appropriate department within three to five business days had proper protocol been followed. The company noted that without a reference number, it has no formal record that the hackers attempted to make contact before sending the notification.

The incident has prompted cybersecurity consultants to issue new guidance recommending that future attackers initiate contact through the live chat feature during business hours. Experts suggest that hackers mention their case reference number in all subsequent Telegram communications and avoid sending unauthorised push notifications until they have received an automated email confirming their ticket has been received.

The advisory also encourages criminal organisations to monitor their spam folders for ASOS responses and to allow up to 14 days before following up on pending extortion requests.