The ASOS hack investigation concerns third-party customer messaging platforms after some shoppers received an unauthorized app notification on October 6. In its customer notice, ASOS says someone may have accessed names and contact details. However, it does not currently believe the incident affected payment-card information or account passwords.
The retailer restricted access to the notification platforms and brought in specialist advisers and relevant authorities. Meanwhile, its October 6 regulatory announcement says the website and app are operating normally, with no current disruption to operations.
ASOS says to ignore the notification’s link
ASOS tells customers to disregard the unauthorized notification and avoid clicking or engaging with its external link. Instead, anyone with concerns can reach customer care through the company’s official website.
The company is not currently asking customers to change their ASOS password or take other action. If that advice changes, ASOS says it will contact affected customers directly.
However, the UK’s National Cyber Security Centre’s incident alert takes a broader precautionary position: all ASOS customers should consider themselves potentially affected, even without a notification. That guidance does not establish that anyone accessed every customer’s information.
Watch for follow-up scams
The NCSC warns that suspicious messages can arrive some time after a data incident. Its advice covers push notifications, emails and other messages, so a later contact deserves the same caution as the original alert.
- Avoid suspicious links, including those delivered through an app notification.
- Also review vulnerable or reused passwords. The NCSC recommends passkeys, or strong, separate passwords with two-step verification where those options are available.
- Check account activity and use the NCSC’s linked recovery guidance if there are signs of account compromise.
For related coverage, see the Framework customer-contact-data breach and how to verify Apple threat notifications. These are separate incidents, rather than evidence of how the ASOS hack occurred.
What remains unknown about the ASOS hack
Neither ASOS notice identifies the responsible party, names the affected third-party platforms or gives a customer count. Nor does either establish the technical route used to send the notification. ASOS says it will provide another update once it has confirmed more information.
