Quick Answer
ASOS says an unauthorized customer notification sent around 10 a.m. on October 6, 2026, may have exposed names and contact details through third-party communication platforms. ASOS says passwords and payment-card data were not affected, and its website and app remain operational. Treat unexpected ASOS messages as suspicious, avoid their links, and verify account activity directly through the official app or website.
Key Takeaways
- ASOS says basic personal information, including names and contact details, may have been accessed.
- ASOS says it does not believe customer passwords or payment-card information were affected.
- The incident involved third-party platforms ASOS uses to communicate with customers.
- The ASOS website and app were operating normally as of October 6, 2026.
- The NCSC advises affected shoppers not to click suspicious links, including links in push notifications.
What happened in the ASOS data breach alert?
The ASOS data breach alert concerns an unauthorized customer notification that ASOS says was sent at about 10 a.m. on October 6, 2026. The retailer said it is investigating unauthorized activity involving third-party platforms used to communicate with customers and has restricted access to those notification platforms.
ASOS has not described the exact method used to send the unauthorized notification. The company also did not name Snowflake or confirm a claim that a Snowflake instance was compromised. ASOS’s October 6 market announcement is the primary source for the company’s current description of the incident.
The most important point for customers is that a legitimate-looking app alert or message can now be used as a starting point for follow-on scams. Criminals often rely on public awareness of a real incident to make fake password-reset, refund, delivery, or account-verification messages appear more credible. The practical response is to avoid acting through links in unexpected communications.
What customer information may have been exposed?
ASOS says basic personal information may have been accessed, including customer names and contact details. Contact details can include information used to reach customers, which makes the exposure important even when financial data and account credentials are not believed to be involved.
Names and contact details can help scammers create more convincing phishing messages because a message can appear personalized or refer to a known retailer. A fraud attempt does not need access to a password to ask a customer to enter one on a fake website. Customers who receive an unexpected ASOS notification should treat the message as unverified until they confirm it through an official ASOS channel.
Security incidents involving customer communications can also affect the usefulness of routine alerts. A customer may reasonably expect an order update, promotion, or account notice from a retailer, so an attacker can imitate familiar message formats. Readers who have seen similar tactics in other retail incidents can review how customer information exposure affects phishing risk after a reported breach.
Were ASOS passwords or payment cards affected?
ASOS says it does not believe payment-card information or account passwords were affected by the unauthorized activity. That statement reduces the immediate evidence that customers need to replace cards or reset passwords solely because of this incident.
ASOS’s wording is still important because the investigation remains ongoing. A company’s initial assessment reflects the information available when it publishes the update, rather than a permanent guarantee that no additional findings will emerge. Customers should watch for direct updates from ASOS and use the company’s official website or app instead of links supplied in messages.
| Information or service | ASOS’s October 6 assessment | Practical customer response |
|---|---|---|
| Names and contact details | May have been accessed | Expect possible phishing or impersonation attempts. |
| Account passwords | ASOS does not believe they were affected | Do not reset a password through an unexpected message link. |
| Payment-card information | ASOS does not believe it was affected | Monitor normal account activity and use official support for concerns. |
| ASOS website and app | Operating normally | Access ASOS by opening the app or typing the address yourself. |
The safest approach is to separate the reported exposure from the scams that may follow. The ASOS announcement does not tell customers to provide new information in response to an alert. A legitimate company can contact customers about an incident, but a message that pressures you to act immediately or asks for credentials deserves added scrutiny.
How did the unauthorized ASOS notification reach customers?
The unauthorized ASOS notification involved third-party platforms that ASOS uses to communicate with customers. ASOS says it restricted access to those notification platforms while it investigates the unauthorized activity.
Third-party communication platforms can send customer-facing messages such as notifications or other service communications. Access to a notification channel matters because customers often view messages from a familiar brand as trustworthy, especially when the message arrives inside an app or resembles an expected service alert.
The available information does not establish that ASOS’s core website, app systems, customer accounts, or payment infrastructure were compromised. ASOS said its website and app continued to operate normally, with no current disruption to operations. Customers should avoid assuming that every ASOS message is fraudulent, but they should independently verify unexpected requests before responding.
What phishing risks should ASOS customers watch for?
ASOS customers should watch for phishing messages that use the incident as a reason to request a password, payment details, verification code, or personal information. The UK National Cyber Security Center advises affected shoppers not to click suspicious links, including links in push notifications, and to watch for follow-on phishing messages.
Phishing works by redirecting a customer to a fraudulent website or persuading the customer to disclose information that was not exposed in the original incident. A fake message may claim that an account is locked, a refund is waiting, a delivery needs confirmation, or security details must be updated. The message can appear convincing when it uses the customer’s name or references ASOS.
The NCSC’s consumer alert for affected ASOS customers specifically warns against suspicious links in push notifications. The practical response is to open ASOS directly through the official app or a manually entered web address, then check whether the claimed issue appears in the account itself.
Customers should also be cautious about messages that request one-time passcodes. A verification code can allow someone else to access an account if the customer provides it during a fraudulent login attempt. Password managers and official app logins are generally safer than following a link from an unexpected notification.
What should ASOS customers do now?
ASOS customers should avoid links in unexpected notifications and use official ASOS channels to check orders, account details, and any security notices. The reported incident creates a higher risk of social engineering, which means messages that appear routine deserve more careful review.
- Open the ASOS app yourself or type the ASOS web address into your browser instead of using a link from a notification.
- Check recent orders, saved contact details, and account activity for information you do not recognize.
- Ignore messages that ask for a password, payment details, or one-time verification code through a link or reply.
- Use a unique password for ASOS if you decide to change it, especially if the existing password is reused on other services.
- Contact ASOS through its official support options if an account notice appears suspicious or an unfamiliar account change is visible.
Changing an ASOS password is a reasonable precaution for customers who reuse that password elsewhere, but ASOS does not currently believe passwords were affected. The stronger immediate protection is to avoid giving away credentials in response to a fake alert. Customers concerned about message-based fraud can also review the warning signs used in fake technical-support alerts, including pressure tactics and deceptive links.
Is the ASOS website and app safe to use?
The ASOS website and app were operating normally as of the company’s October 6 announcement, and ASOS said there was no current disruption to operations. That means customers can access ASOS directly to review their accounts, orders, and official communications.
Normal operation does not remove the need for caution around incoming notifications. The reported issue concerns a customer communication channel, so the safer method is to begin from the official app already installed on your device or by entering the retailer’s web address yourself. This avoids relying on a link that may redirect to an impersonation page.
ASOS shares fell 10% after the retailer warned that customer information may have been accessed, according to Reuters reporting on the market reaction. The share-price movement reflects investor concern, but it does not change the practical customer advice: monitor official updates, remain alert to phishing, and avoid unexpected links.
What should customers avoid after the ASOS notification incident?
ASOS customers should avoid clicking notification links that arrive unexpectedly, sharing verification codes, or entering account credentials after a message creates urgency. The NCSC warning matters because attackers can use a real incident to make an unrelated fraudulent message look credible.
Customers should also avoid calling phone numbers supplied only in suspicious messages. Use contact information found inside the official ASOS app or website instead. A fraudulent message can imitate a retailer’s tone, colors, and wording, but it cannot make an independently opened official account page show a legitimate security request.
The most sensible approach is to pause before responding to any alert that asks you to secure an account, claim money, confirm a delivery, or update payment information. Customers who entered credentials after following a suspicious link should change the ASOS password through the official service and change the same password anywhere else it was reused.
FAQ
Did ASOS confirm a data breach?
ASOS confirmed unauthorized activity involving third-party customer communication platforms and said names and contact details may have been accessed. ASOS has not publicly described the incident as a confirmed compromise of its core website, app, payment systems, or customer passwords.
Did the ASOS incident expose payment-card details?
ASOS says it does not believe payment-card information was affected. Customers should still avoid entering card details through links in unexpected notifications because phishing scams can seek information that was not exposed in the incident.
Should ASOS customers change their passwords?
ASOS customers do not need to reset a password solely because of the company’s current assessment, since ASOS says it does not believe passwords were affected. Customers who reuse an ASOS password on other services may still choose to replace it with a unique password as a precaution.
Can an ASOS push notification be a phishing scam?
Yes, an ASOS-related push notification can be used in a phishing attempt if it directs customers to a suspicious link or requests sensitive information. The NCSC advises affected shoppers not to click suspicious links, including links in push notifications.
Is the ASOS app still working after the incident?
ASOS says its website and app were operating normally, with no current disruption to operations, as of October 6, 2026. Customers should open the official app directly rather than using links delivered in unexpected messages.
