ASOS hack: what customers should do now to avoid follow-up scams
ASOS says names and contact details may have been accessed after hackers sent app users an alert. Here's how to protect yourself from the scams that often follow.

What's happened
ASOS has confirmed that hackers got into systems it uses to contact customers, after many app users were sent an alarming push notification on the morning of Tuesday 6 October. The message, headed "ASOS HACKED", was addressed to the company's data protection and IT teams and read: "we have fully compromised the Snowflake instance. Engage with us, or we will leak it." It linked to a Telegram channel run by a group calling itself Xuanye.
In a statement that afternoon, ASOS said it was "investigating unauthorised activity involving third-party platforms that we use to communicate with customers" and that "basic personal information including name and contact details may have been accessed". It added: "We do not believe that payment-card information or account passwords, were impacted." Its website and app are working as normal. Snowflake, the data storage firm named in the message, told the BBC it had "found no compromise" of its platform.
The National Cyber Security Centre (NCSC) has published advice for shoppers, and the Information Commissioner's Office (ICO) issued a statement on 7 October. ASOS shares fell by as much as 10% to 439p on the day of the hack.
Who's affected
ASOS hasn't said how many customers were affected, and it isn't yet clear exactly what data, if any, was taken. The NCSC's advice is blunt: "If you are an ASOS customer, you should assume you are affected by this incident, even if you did not receive the unauthorised notification."
Getting the pop-up doesn't mean your phone has been hacked, the BBC points out. The bigger worry is what comes next. Names and contact details are exactly what fraudsters need to make a fake email, text or phone call look genuine. The NCSC warns that scam messages often arrive "some time after a data breach" and may talk about "resetting passwords", "receiving compensation", "scanning devices" or "missed deliveries".
What a scam could cost: a worked example
Say you get a call from someone claiming to be from ASOS's refunds team. They know your name and email address, say your account has been misused, and talk you into moving £1,200 by bank transfer to a "safe account". It's a scam.
Under reimbursement rules that came in on 7 October 2024, overseen by the Payment Systems Regulator, your bank should refund victims of this kind of authorised push payment (APP) fraud up to £85,000. Banks can apply an optional excess of up to £100, though not for vulnerable customers. So, at worst:
- Money lost to the scammer: £1,200
- Maximum excess your bank could keep: £100
- Minimum you should get back: £1,100
You should normally be repaid within five business days of claiming, although your bank can extend that to 35 business days if it needs more information. You need to report it within 13 months. These rules only cover UK bank transfers made by Faster Payments or CHAPS, so a card payment on a fake website is handled differently.
What to do now
- Ignore the notification. ASOS has told customers to disregard the alert and not to click its link. If you tapped it and entered a password, change it from another device straight away.
- Only go to ASOS directly. ASOS's own Q&A says it isn't currently asking customers to change their password or take any other action, and that it will contact affected customers directly if that changes. If you want to change your password anyway, the ICO says to log in "directly through the official website or app" and do it the usual way, not through a link in a message.
- Fix reused passwords. If your ASOS password is the same as on other accounts, especially your email, change those too. A password manager such as NordPass makes unique passwords easier to keep track of.
- Turn on two-step verification or passkeys wherever you can, starting with your email and banking apps. The NCSC says this keeps accounts secure even if your data is breached.
- Hang up on unexpected calls. Which? advises putting the phone down on anyone who says they're from ASOS or another firm, then contacting the company yourself using details you've found independently.
- Check your bank and card statements over the coming weeks for anything you don't recognise.
Your questions answered
Were my card details stolen?
ASOS says it doesn't believe payment card information or account passwords were affected. It says names and contact details may have been accessed. Watch the ASOS website or app for official updates.
Is it safe to keep shopping with ASOS?
ASOS says its website and app are operating as normal and customers can continue to shop. Just make sure you go to the site or app yourself rather than following links in messages.
Where do I report fraud?
In England, Wales and Northern Ireland, report it to Report Fraud online or on 0300 123 2040. In Scotland, call Police Scotland on 101. Tell your bank first if you've lost money.
Ways to save
Two-step verification is free on most phones and email services. For extra protection, a security suite such as Kaspersky can scan for malware and flag dodgy websites. Check our codes page before you buy.
Sources: National Cyber Security Centre, ICO, BBC News, The Independent, City AM, Metro, Payment Systems Regulator, Stop! Think Fraud
Ad: affiliate links. The codes and deals below link to the stores, and we may earn a commission if you buy, at no cost to you. How we make money.
Codes & deals for this story
Buy a discounted ASOS Shopping Card through Blue Light Card and spend it on asos.com. Blue Light Card membership (£4.99 for two years) required.
Unlimited passwords, sync across devices, autosave and autofill at no cost.
Applies to Kaspersky home subscriptions bought from the site.
daysfree
7-day free trial as advertised on NordVPN's risk-free page; check the page for eligible devices.
Free to join with an ASOS account; tiered benefits based on 12-month spend, including a tier-specific birthday discount code.
Discount on Premium for eligible students via the NordPass student-discount page.
Keep reading
Scam ads from firms on the FCA warning list still running on Meta, Google and TikTok
Which? found nine firms kept advertising after the FCA warned about them, including a fake SpaceX investment and a clone insurer. Here's how to check a firm first.
Voucher Magpie team
Clubtab: a new app to collect subs and match fees for grassroots clubs
Clubtab lets parents pay subs from a link and matches every payment to the right player. Here's how it works, what it costs and what Stripe's fees mean for your team.
Voucher Magpie team
Car finance compensation on hold: court dates, deadlines and what to do now
Payouts from the FCA's car finance scheme are paused while lenders' challenges go to a hearing in December or February. Here's how to complain for free in the meantime.
Voucher Magpie team
ASOS
NordPass
NordVPN