ASOS Hacked? What Customers Should Do to Secure Their Accounts
ASOS says names and contact details may have been accessed, but passwords and card data are not believed affected. Learn what customers should do after the unauthorized alert.
ASOS has confirmed an unauthorized customer notification and suspicious activity involving third-party platforms it uses to communicate with shoppers. As of October 7, 2026, the company says basic information such as names and contact details may have been accessed, but it does not believe account passwords or payment-card information were affected. ASOS says customers should ignore the notification and must not click or engage with its external link. The company is not currently asking customers to change their ASOS password or take other action. If your password was reused, you see account changes you did not make, or you shared information through the link, take the targeted steps below.
The word “hacked” in the alert is not a complete description of what has been verified. ASOS says it is investigating unauthorized activity involving communication platforms; it has not confirmed the sender’s specific claim about a data system or the full scope of any data access. The incident notice was posted October 6 and may change as investigators learn more.
| What is confirmed or stated | What remains uncertain | Useful response |
|---|---|---|
| Some customers received an unauthorized push notification. ASOS says it restricted access to the notification platforms and is working with specialist advisers and relevant authorities. | The company has not publicly confirmed the attacker’s full access, the precise data set involved, or whether any individual customer’s information was actually viewed or copied. | Use the official ASOS incident update for new instructions, reached by typing the web address yourself or using a saved bookmark. |
| ASOS says names and contact details may have been accessed. It does not believe account passwords or payment-card details were affected. | “May have been accessed” does not prove that every ASOS customer’s details were exposed. The statement is also preliminary, not a final forensic report. | Be alert for messages that use your name or email address to sound convincing, but do not assume that your identity or card has been stolen. |
| ASOS says its website and app remain available, and customers can continue shopping. It is not currently asking customers to change passwords. | Normal app availability does not explain the full incident, and company guidance may change as the investigation continues. | Follow the current company notice. Change passwords now if you reused one, supplied it to someone, or see signs of unauthorized account access. |
These points come from ASOS’s customer-care notice, checked October 7, 2026. That notice is the best source for what the retailer is asking customers to do today. It does not verify every claim in the unauthorized message.
Do not open the Telegram or other external link included in the unauthorized notification. Do not reply to its sender, share a verification code, or provide a password, card number, or identity document. The fact that a message appeared as an app push does not make its contents trustworthy: ASOS says the notification itself was unauthorized. Open a browser and type asos.com, or open the app from your device’s normal app list, then look for the retailer’s Customer Care notice. ASOS also warns that it will not ask for sensitive details such as a password or card information through social-media direct messages.

ASOS explicitly says it is not currently asking customers to change their passwords. If your ASOS password is unique, you did not enter it on the external link, and you have no unexpected sign-in, password-reset, or account-change alerts, you can follow ASOS’s current notice and watch for an update. This is different from saying password changes are never useful: if you reused the same password on other sites, change it on ASOS and anywhere else it was reused. If you see an unfamiliar order or an email or phone-number change you did not request, use ASOS’s official password-reset process rather than a link in a message.
ASOS’s account help says that a signed-in customer can select “Change password,” enter the current password, and create a new one between 10 and 100 characters that differs from the last password. If you cannot sign in, use “Forgotten password?” on the sign-in page; the reset link is sent to the email address registered to the account. The retailer warns that three incorrect email or password entries can lock an account for 30 minutes. See ASOS account help for the current steps.

Your email account is important because it receives password-reset links and order messages. Use a strong password that you do not use anywhere else. If your email provider offers two-step verification or multifactor authentication, enable it; this requires another proof of identity in addition to your password. Check the account’s recovery phone number, recovery email, and recent sign-in activity. These are general protections for your email account, not a claim that ASOS offers two-step verification for its own shopping accounts. The UK National Cyber Security Centre explains why a separate email password matters and recommends two-step verification where available; see its email security advice. The U.S. Federal Trade Commission also advises using two-factor authentication where available.
If you registered with ASOS using Apple, Google, or Facebook, protect that sign-in account as well. A password reset on the retailer may not secure an email or social sign-in account that is itself at risk.

Open your ASOS account through the official website or app and review “My Details,” “Address book,” “Payment Methods,” and recent orders. Look for an unfamiliar delivery address, changed contact details, a new order, or a saved payment method you do not recognize. ASOS’s current statement does not say that payment information was compromised, so there is no reason to cancel a card solely because of the headline. Still, checking your bank or card activity is a sensible precaution. If you find a transaction you did not make, contact the card issuer using the number on the back of the card or its official app; ask about freezing or replacing the card and disputing the transaction.
ASOS’s online safety guidance recommends checking statements and reporting transactions you do not recognize. For U.S. consumers, the FTC explains the steps for disputing a credit-card billing error. Deadlines and protections can depend on the card and type of account, so contact the issuer promptly instead of waiting for an investigation update.

Clicking a link alone does not prove that your phone or account was compromised. The risk depends on what happened next. If you entered your ASOS password, change it from the official site and replace it anywhere else you reused it. If you entered your email password, secure that account first, then reset other accounts that depend on it. If you provided card details, contact the card issuer immediately. If you supplied a verification code, tell the affected service through its official support channel and review active sessions or recent activity if those controls are available.
If you downloaded a file or installed an app after following the link, remove anything you do not recognize, update your device, and use its built-in or trusted security scan. Do not call a phone number or install remote-access software offered by a person claiming to “clean” your account. If you see signs that someone took over an account, follow the official recovery steps from that provider. The FTC’s account recovery advice includes changing a compromised password, signing out other sessions where possible, enabling two-factor authentication where offered, and checking recovery details.
Check ASOS Customer Care through a known route rather than through links in unsolicited texts, emails, or push alerts. ASOS says it will provide a further update when it has confirmed more information and will contact affected customers directly if its advice changes. A genuine-looking logo, your name, or an accurate order detail is not enough to authenticate a message. ASOS’s cybersecurity guidance recommends avoiding unknown links and keeping the app updated; its account support explains how to change or reset a password if your circumstances call for it.
For most customers who only received the unauthorized notification, the practical response today is straightforward: do not click its link, do not send anyone credentials or codes, and follow ASOS’s official update. Add a password reset and bank contact only when your own account activity or what you disclosed gives you a reason to do so. This article reflects information available October 7, 2026; the incident remains under investigation, so the company’s notice may be updated.
ASOS says names and contact details may have been accessed, but passwords and card data are not believed affected. Learn what customers should do after the unauthorized alert.
Find the best Amazon UK tech deals during Prime Big Deal Days, October 6–7, 2026. Compare product specs, price history, sellers, delivery, and returns.
Learn how to use a hurricane tracker for live storm updates, read forecast cones, watches, wind probabilities, arrival times, and local alerts safely.
Learn what red-dyed diesel is used for, when federal tax exemptions apply, why road use can trigger penalties, and what to verify under your state’s rules.
Compare UK Prime Big Deal Days tech offers by exact model, total checkout price, seller, condition, and warranty—so you can spot value beyond the discount badge.
Check the 2026 Gatorade recall by flavor, 28-ounce size, best-taste date, and production code. Learn what to do with a matching bottle and when to seek help.
BT has acquired TalkTalk, but existing customers are told their service, price, and contract remain unchanged for now. Here’s what to monitor as the CMA reviews the deal.
RuneScape 4 is real as a working title, but it is not a RuneScape 3 replacement. Here is what Jagex confirmed, what remains unknown, and what players should watch next.
Learn why phones and computers usually change clocks automatically, when smart devices may not, and how to check time zones, calendars, alarms, and schedules.
USPS lists October 12, 2026 as Columbus Day. Check retail counter hours, regular mail, Priority Mail Express, kiosks and shipping alternatives before you go.