← Back to news
NCSC (UK)6 Oct 2026 · 2 min read

ASOS investigates customer data incident following unauthorised notification

Online fashion retailer ASOS is investigating a cyber incident after some customers received an unauthorised push notification on 6 October, according to an alert published by the UK’s National Cyber...

Online fashion retailer ASOS is investigating a cyber incident after some customers received an unauthorised push notification on 6 October, according to an alert published by the UK’s National Cyber Security Centre (NCSC).

ASOS said that customer information may have been accessed during the incident. The potentially affected data includes names and contact details, the NCSC said. The retailer has stated that it does not currently believe account passwords or payment-card information were involved.

The scale of the incident has not been disclosed. The NCSC advised all ASOS customers to regard themselves as potentially affected, including people who did not receive the unexpected notification.

Risk of follow-on scams

Exposure of contact information can enable phishing and other social-engineering attempts, particularly when criminals use a known brand or recent incident to make messages appear credible. The NCSC warned that suspicious communications may arrive after the initial breach and may be delivered through email, text messages or mobile notifications.

Customers should avoid following links or responding to unexpected messages that claim to be from ASOS, especially where they request login details, payment information or urgent action. Instead, users should access their accounts directly through the official ASOS app or website.

Steps customers can take

  • Monitor email, SMS and push notifications for messages that appear unusual or request sensitive information.
  • Use a strong, unique password for the ASOS account and other services; enable two-step verification where it is available.
  • Consider using passkeys where supported to reduce the risk associated with password theft.
  • Review account activity and delivery or order details for changes that were not made by the account holder.
  • Report suspected fraud through the appropriate UK reporting channels.

While ASOS has said payment details and passwords are not believed to be affected, customers should remain alert for fraudulent messages that cite the incident. The investigation is ongoing, and further details may emerge as ASOS assesses the unauthorised activity.

Share this article:TwitterLinkedIn