UK Cyber Agency Tells Every ASOS Customer to Assume They Are Affected

The UK's National Cyber Security Centre published an alert on Oct. 6, 2026, telling anyone who shops with ASOS to assume they are affected by a cyber incident at the online retailer, even if nothing unusual reached their phone.
The alert is consumer guidance: the NCSC addressed it to individuals and families rather than to organizations, and the advice in it is short. Watch for suspicious messages, which can arrive some time after an incident like this. Do not click suspicious links, whether they arrive in a push notification, an email or a message. The alert's own list of actions runs from confirming you are affected to watching for scams, updating passwords that may be at risk, reviewing account activity and checking for wider exposure.
It also points customers to its own data breach guidance and to the UK's Stop! Think Fraud service for reporting fraud. Its standing advice is to use passkeys, a password-free sign-in or strong separate passwords with two-step verification.
On Oct. 6, 2026, some ASOS customers received a push notification from the ASOS app that the company says was unauthorized. ASOS has said it is investigating the activity and that some customer personal information may have been accessed.
The company has said the information involved is basic, covering names and contact details, and that it does not believe payment card information or account passwords were affected. Those are ASOS's own statements, relayed by the NCSC, and the company describes the access as possible rather than confirmed.
Neither the NCSC nor ASOS has published a figure for how many customers are involved. The alert names no attacker and does not say how the notification was sent.
