Skip to content
What ASOS shoppers must do right now after phone hack alert

What ASOS shoppers must do right now after phone hack alert

Surreycomet • October 7, 2026

The warning comes after millions of ASOS customers received an alarming push alert on Tuesday, October 6.

App users across the UK woke to a notification headed "ASOS HACKED" demanding that the fashion giant an extortion group on Telegram.

The online fashion retailer issued an official statement through the London Stock Exchange confirming an urgent investigation into unauthorised activity.

ASOS confirmed that basic personal records including names and details may have been accessed, but stressed payment-card information and account passwords were not compromised.

Were you one of the ASOS customers who was rather alarmed yesterday when you received a notification which appeared to a hack? The message claimed customer data had been breached and personal information was obtained. Cybersecurity expert Jake Moore explains what to do if you're worried what's happened to your data #asos #asoshack #hack #tech — Good Morning Britain (@GMB) October 7, 2026

Were you one of the ASOS customers who was rather alarmed yesterday when you received a notification which appeared to a hack? The message claimed customer data had been breached and personal information was obtained. Cybersecurity expert Jake Moore explains what to do if you're worried what's happened to your data #asos #asoshack #hack #tech

— Good Morning Britain (@GMB) October 7, 2026

The retail platform added that both its website and shopping app remain fully operational while technicians work to restrict third-party access.

Speaking on ITV's Good Morning Britain on Wednesday, October 7, cybersecurity expert Jake Moore urged shoppers to take immediate protective measures.

Mr Moore, global cybersecurity advisor at ESET, cautioned that customers should under no circumstances click any links contained in the rogue notifications.

Shoppers must also refuse to join the Telegram channel by the hackers, as interacting with criminal groups exposes personal devices to malicious software.

Security specialists warn that secondary phishing attacks represent the single biggest danger to consumers following high-profile data leaks.

Fraudsters routinely exploit headlines surrounding corporate breaches by sending convincing fake emails and text messages pretending to represent ASOS, banks or cybersecurity investigators.

These deceptive messages typically claim that an account is at immediate risk and urge shoppers to confirm payment details or follow bogus verification links.

Consumers should treat any unexpected communication requesting personal or financial information with extreme caution and never directly.

Although the fashion retailer stated that customer passwords remain secure, industry analysts recommend updating login credentials as an extra safety measure.

Anyone who reuses their shopping password on other digital services should change those accounts immediately to prevent automated credential-stuffing attacks.

Shoppers are encouraged to use a reputable password manager to generate and store distinct, complex credentials for every online account.

Customers who access their profiles using third-party login buttons such as Apple ID, Google or should also review those connected account settings.

Enabling multi-factor authentication across all primary email and connected login providers delivers a vital additional layer of defence against fraud.

Nearly six million UK drivers risk £50 fines over common roundabout mistake

Expert reveals the exact date UK households should turn on their heating this month

What speed triggers UK speed cameras? Car expert explains

In a statement released through the London Stock Exchange, ASOS said: “ASOS can confirm that, at around 10am today, an unauthorised customer notification was sent to ASOS customers.

“We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers. We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities.

“Basic personal information including name and details may have been accessed. We do not believe that payment-card information or account passwords, were impacted.

“Our website and app are operating as normal, with no current disruption to any aspects of our operations. Customer trust is incredibly important to us, and if the situation changes an update will be provided as appropriate.

“The Company has cyber security insurance with a large global provider, including business continuity insurance. It is too early to quantify any potential impact on trading.”

Extracted Entities

Attack Types (2)

Companies (2)

Industries (1)

Platforms (2)