ASOS customers are being advised by the UK’s National Cyber Security Centre (NCSC) to assume they are affected by the retailer’s cyber incident, even if they did not receive the unauthorised push notification sent on Tuesday 6 October.
That does not mean ASOS has confirmed that every customer’s personal information was accessed.

ASOS says basic personal information including names and contact details may have been accessed. However, it does not currently believe payment-card information or account passwords were affected.
The retailer is not currently asking customers to change their ASOS password or take any other specific action, beyond ignoring the unauthorised notification and not clicking the external link it contained.
What happened at ASOS?
ASOS says an unauthorised customer notification was sent at around 10am on Tuesday 6 October.
The company is investigating unauthorised activity involving third-party platforms it uses to communicate with customers.
It says it restricted access to the notification platforms and is working with specialist advisers and relevant authorities.
Its website and app continue to operate normally.
ASOS published a regulatory announcement about the cyber incident on Tuesday afternoon and has also published customer advice about the unauthorised notification.
Who should assume they are affected?
ASOS says customers may have been affected if they received the unauthorised push notification.
The NCSC is taking a wider precautionary approach.
It says:
“If you are an ASOS customer, you should assume you are affected by this incident, even if you did not receive the unauthorised notification.”
This does not confirm that every ASOS customer had personal information accessed.
It means the NCSC wants all customers to follow its safety advice while the investigation continues.
What information may have been accessed?
ASOS has said, “basic personal information including name and contact details may have been accessed”.
It has not publicly explained exactly what “contact details” includes.
That means we should not assume it includes an email address, phone number, postal address or any other specific detail unless ASOS confirms this.
Skint Dad contacted the ASOS press office at 9:30pm on Tuesday 6 October asking for more detail.
The press office replied seven minutes later and directed us to the company’s published statement.
We then asked ASOS specifically what “contact details” includes and whether customers who did not receive the unauthorised notification could still have had personal information affected.
ASOS responded again on Wednesday morning, directing us to the same published statement.
It has not provided further clarification on either of those questions.
Do ASOS customers need to change their password?
ASOS is not currently asking customers to change their ASOS account password.
The company says it does not believe account passwords were affected.
However, the NCSC recommends using passkeys where available, or strong, separate passwords plus two-step verification.
If you reuse your ASOS password on other websites, use a different password for each important account.
There is one situation where the NCSC says you should act quickly.
If a suspicious message includes a password you still use, change it as soon as possible and change it anywhere else you have reused it.
You can read the NCSC’s full guidance for people affected by data breaches.
This is general cyber-security advice. It is not evidence that ASOS passwords have been exposed.
Should you turn on two-step verification?
The NCSC recommends two-step verification for accounts where it is available.
It adds another check when someone tries to sign in, making it harder for someone to access an account with a password alone.
ASOS has not told customers to switch on an ASOS-specific two-step verification setting, and we have not been able to verify from its public customer guidance that such an option is currently available.
So this is wider account-security advice rather than evidence that ASOS accounts themselves have been compromised.
What scams should ASOS customers watch for?
The NCSC warns that suspicious messages can arrive some time after a data incident becomes public.
Criminals can also use a high-profile cyber incident as bait even if they did not obtain your personal information in the incident.
Watch for unexpected emails, texts, calls or notifications claiming you need to:
- reset a password
- claim compensation
- carry out a security check
- deal with a missed delivery
- act urgently to protect an account
Be wary of any unexpected message asking for a password, bank details or other personal information.
Rather than clicking a link, open the ASOS app yourself or visit the official ASOS website directly.
Also check your online accounts for activity you do not recognise, including changes to security settings, messages you did not send, or login attempts from unusual places or at unusual times.
We recently reported on a separate warning showing how criminals can take over genuine email and social media accounts and use them to target other people.
Do you need to cancel your bank card?
There is no official advice telling ASOS customers to cancel their payment cards simply because of this incident.
ASOS says it does not believe payment-card information was affected.
You should still check bank and card statements for anything you do not recognise.
The Information Commissioner’s Office recommends contacting your bank, building society or card provider if you spot unusual transactions or activity.
If you have entered card or bank details into a suspicious website, or given them to someone you do not trust, contact your bank straight away using its official app, website or the number on the back of your card.
You can also call 159 if your bank supports the service.
What if you have already been targeted?
What you need to do depends on what information you have shared.
If you entered a password into a suspicious site, change it straight away and change it anywhere else you use the same password.
If you shared bank or card information, or think a fraudster may have access to your bank account, contact your bank as soon as possible.
Suspicious emails can be forwarded to report@phishing.gov.uk and suspicious text messages can be forwarded free to 7726.
If you have lost money or believe you have been the victim of fraud, contact your bank and report it to Report Fraud if you are in England, Wales or Northern Ireland.
In Scotland, fraud and cyber crime should be reported to Police Scotland on 101.
What is still unclear?
There are still important questions ASOS has not publicly answered.
It has not said exactly which contact details may have been accessed, how many customers may be involved, or whether information was actually copied or taken.
ASOS has also not publicly identified which authorities it is working with.
As of Wednesday 7 October, the ICO has not published an ASOS-specific statement.
Not every personal data breach has to be reported to the ICO.
Where a breach meets the legal reporting threshold, the ICO says organisations should report it without unnecessary delay and no later than 72 hours after becoming aware of it.
ASOS says it will provide a further update once it has confirmed more information.
Skint Dad will update this article if further verified information affecting customers is released.
Add Skint Dad as one of your preferred sources.
- Aldi vs Lidl wooden toys compared: where your Christmas budget goes furthest - 7 October 2026
- NCSC tells ASOS customers to assume they are affected – what to do now - 7 October 2026
- Primark recalls two Halloween gonks over potential asbestos risk - 6 October 2026
Saved a few quid with our tips?
If Skint Dad has helped you spend less or feel more in control of your money,
you can support the site with a small contribution.
