ASOS Hacked: What Customers Should Do After the Data Incident
Updated October 6, 2026: ASOS is investigating a cyber incident after customers received an unauthorized push notification. The UK National Cyber Security Centre (NCSC) says customer names and contact details may have been accessed, while ASOS has said it does not believe payment card information or account passwords were affected.
The NCSC advises ASOS customers to assume they may be affected, even if they did not receive the suspicious notification. That does not mean every account has been taken over. It means customers should be alert for fraudulent messages and impersonation attempts that could exploit exposed contact information.
What happened to ASOS?
On Tuesday, October 6, some ASOS customers received an unauthorized push notification. ASOS said it was investigating unauthorized activity, and the NCSC subsequently published a customer alert about the incident.
At this stage, public information points to possible exposure of basic personal information such as names and contact details. ASOS has said it does not believe card details or account passwords were affected. Because the investigation is ongoing, customers should treat those statements as the best current information rather than a guarantee that no further details will emerge.
What customer data may have been exposed?
According to the NCSC alert, the information that may have been accessed includes customer names and contact details. Contact data can still be valuable to scammers because it can make fraudulent emails, texts or phone calls look more convincing.
For example, a scammer who knows that someone shops at ASOS could send a message claiming that an order failed, a refund is waiting, a delivery address needs to be confirmed or an account needs attention. The safest response is to avoid message links and open the official app or website directly.
Do you need to change your ASOS password?
If your ASOS password is unique and you have no sign of unauthorized access, there is no public indication that passwords themselves were exposed. Changing it is still a reasonable precaution if you reused it elsewhere, if it is weak, or if you received an unexpected password-reset message.
Use a long, unique password or a passkey where available, and enable two-step verification on important accounts that support it.
What ASOS customers should do now
- Treat unexpected ASOS messages cautiously. Open the official app or website directly instead of following an unfamiliar link.
- Watch for impersonation. Be suspicious of urgent messages about refunds, failed payments, deliveries or account suspension.
- Review your ASOS account. Look for unfamiliar profile changes, saved addresses or orders.
- Replace reused passwords. If your ASOS password is also used elsewhere, switch each account to a unique password.
- Protect your email account. Email is often the recovery route for shopping accounts, so strong authentication matters.
- Monitor financial activity. Although ASOS says card data is not believed to be affected, checking statements is a sensible precaution.
- Use official reporting channels. UK customers can follow NCSC and Stop! Think Fraud guidance if they suspect fraud.
Should you remove saved payment methods?
There is no official recommendation that every customer must remove saved payment methods, and ASOS has said card data is not believed to be affected. Removing saved cards is optional. It should not replace the more useful steps of watching for fraudulent messages, using unique passwords and reviewing account activity.
Can scammers use only a name and contact details?
Yes. A criminal does not need a password or card number to begin an impersonation attempt. A name, email address or phone number can make a message appear more believable than a generic scam.
If a message claims there is a problem with your ASOS account, verify it independently through the official app, website or customer support.
What if you interacted with the unauthorized notification?
If you opened a suspicious notification but did not submit information, close the page and avoid further interaction. If you entered account credentials on an unfamiliar page, secure the affected account and any other account where those credentials were reused. If you disclosed payment information, contact the payment provider using its official app or published support channel.
How to recognize suspicious ASOS messages
No single clue proves that a message is genuine. Unexpected urgency, unfamiliar domains, unusual requests for verification, or demands to confirm account information should all raise caution.
Even a familiar sender name can be misleading. The safest verification method is to navigate independently to the official service rather than relying on a message link.
Is ASOS still safe to use?
The reported incident does not automatically mean customers must stop using ASOS. The NCSC alert focuses on practical steps customers can take while the company investigates. Whether you continue shopping is a personal decision, but standard account-security habits reduce risk across all online retailers.
Why the unauthorized push notification matters
Push notifications are normally trusted because they arrive through an installed app. An unauthorized notification can therefore feel unusually convincing. The incident is a reminder not to assume that a message is safe simply because it appears inside a familiar app.
ASOS incident FAQ
Was ASOS definitely hacked?
The NCSC says ASOS is investigating a cyber incident and unauthorized activity. Public information indicates that customer information may have been accessed, but the investigation is continuing.
Were ASOS passwords affected?
ASOS has said it does not believe account passwords were affected.
Were ASOS card details affected?
ASOS has said it does not believe payment card information was affected.
Who should assume they are affected?
The NCSC advises ASOS customers to assume they are affected even if they did not receive the unauthorized push notification.
What is the main practical risk?
Fraudulent messages and impersonation attempts are an immediate concern because exposed contact details can make scams more convincing.
Bottom line
ASOS customers do not need to panic, but they should be more cautious than usual. Watch for suspicious messages, avoid unfamiliar links, secure reused passwords and review account activity. Official updates from ASOS and the NCSC should take priority over screenshots or unverified social posts.
For more consumer security updates, visit AVARIXO’s Alerts section.
