Has ASOS Been Hacked? What We Know and How Customers Can Stay Safe
If you received an “ASOS Hacked” notification on your phone, you’re not alone.
You’re probably wondering whether your ASOS account is at risk. You may also be concerned about your password, personal information or bank details.
Here’s what we know so far, along with some practical steps ASOS shoppers can take to stay safe.
With October marking Cyber Security Awareness Month, the incident is also a timely reminder of how important it is to recognise suspicious messages, links and unexpected requests for personal information.

Has ASOS been hacked?
ASOS has confirmed that it is investigating a cyber incident.
At around 10am on Tuesday 6 October, customers received an unauthorised notification through ASOS communication systems.
The message claimed that attackers had compromised an ASOS Snowflake system and threatened to leak information online.
However, it is important to separate what has been claimed from what has actually been confirmed.
The wider claims made by the people behind the notification have not been confirmed, although the incident has caused significant discussion online and across social media.
Some people initially assumed the notification was part of an ASOS marketing campaign. However, this has since been confirmed not to be the case.
It is also unusual for attackers to announce an alleged compromise directly through a company’s own customer notification system.
Has my ASOS data been stolen?
ASOS currently says that basic personal information, including names and contact details, may have been accessed.
The exact number of customers affected has not yet been confirmed.
At the time of writing, ASOS says it does not believe that customer passwords or payment-card information were affected.
Do I need to change my ASOS password?
ASOS says it does not currently believe account passwords were affected.
However, this is still a good opportunity to check your password security.
If you use the same password for ASOS and other websites or services, it is sensible to change it and use a unique password for each important account.
Reusing passwords can create additional risk because if one account is ever compromised, criminals may try the same email address and password on other websites.
It is particularly important to protect your email account with a strong, unique password and multi-factor authentication where available.
Do I need to cancel my bank card?
Based on the information currently provided by ASOS, there is no indication that customers need to cancel their bank cards solely because of this incident.
ASOS says it does not currently believe payment-card information was affected.
However, it is always sensible to keep an eye on your bank and card transactions and contact your bank immediately if you notice anything you do not recognise.
I received the link. Should I click it?
No.
If you still have the original notification, do not follow the link contained within the pop-up.
The notification itself was unauthorised.
As a general rule, if you are unsure about any link you receive by email, text message, social media or push notification, do not click it.
Instead, open the company’s official app yourself or type its website address directly into your browser.
This is particularly important following a high-profile cyber incident.
Criminals can take advantage of increased public attention by sending phishing emails and text messages that appear to relate to the incident.
For example, you could receive a message claiming:
“Your ASOS account has been affected. Click here to secure your account.”
Or:
“Please confirm your payment details following the ASOS security incident.”
Messages like these can appear convincing, particularly when they arrive immediately after a genuine cyber security story.
The safest approach is to avoid clicking unexpected links and go directly to the service or company yourself.
If you want to learn more about recognising suspicious emails and messages, Network Ltd provides practical phishing awareness training for businesses.
If you have already clicked a suspicious link or entered your login details, it would be sensible to change the affected password as soon as possible.
If you have reused that password elsewhere, change it on those accounts too.
Is the ASOS site safe to use?
At the time of writing, ASOS says its website and app are operating as normal, with no current disruption to its operations.
ASOS has also said that it does not currently believe payment-card information or account passwords were affected by the incident.
Based on what ASOS has confirmed so far, there is currently no indication that customers need to stop using the official ASOS website or app.
However, because the investigation is ongoing, customers should remain cautious.
If you want to shop with ASOS or check your account, go directly to the official ASOS website or open the ASOS app yourself rather than following a link sent to you through an email, text message, social-media post or unexpected notification.
Be particularly wary of messages claiming that you need to:
- Reset your ASOS password urgently
- Confirm your bank or card details
- Pay a fee to secure your account
- Provide a security or verification code
- Click a link to find out whether your account has been affected
Following any high-profile cyber incident, phishing attempts can use the news itself to make fraudulent messages appear more believable.
So, while the ASOS website and app are currently operating normally, the safest approach is to access ASOS directly and remain cautious about unexpected messages relating to the incident.
What should ASOS customers do now?
For most customers, there is no reason to panic.
The practical steps you can take are relatively simple:
- Do not click the link contained in the unauthorised ASOS notification.
- Be cautious of emails or text messages claiming to be about the ASOS incident.
- Use a unique password for your ASOS account.
- Change your password if you currently use it on other websites.
- Protect your email account with multi-factor authentication.
- Keep an eye on your bank and card transactions.
- Never give out passwords, security codes or payment details in response to an unexpected message.
- Get updates directly from ASOS rather than relying on links shared through social media or unsolicited messages.
A timely reminder during Cyber Security Awareness Month
October is Cyber Security Awareness Month, and incidents like this are a good reminder that cyber security affects everyone, not just large businesses or IT teams.
For consumers, some of the most effective protections are also the simplest: use unique passwords, switch on multi-factor authentication and take a moment to check unexpected messages before clicking.
For businesses, the same principle applies.
Employees who can recognise phishing emails, suspicious links and unusual requests can help stop an attack before it goes any further.
Network Ltd works with businesses to improve their cyber security, including phishing awareness, email security, backups, endpoint protection and Cyber Essentials support. You can find out more about our cyber security services for businesses.
For ASOS customers, though, the main advice remains simple:
Stay cautious, access ASOS directly and think before clicking on unexpected messages.
This article reflects the information available at the time of publication and will be updated if further confirmed information becomes available.





