ASOS says names and contact details may have been accessed after a rogue app alert
ASOS app users, including in Australia, got an 'ASOS HACKED' push alert. What ASOS says was accessed, what wasn't, and the scam messages to watch for.

If you shop with ASOS, expect scam messages that look like they come from the retailer. On Tuesday 6 October some ASOS customers received an unauthorised push notification from the ASOS app, and ASOS says customers’ names and contact details may have been accessed.
Customers reported receiving the alert on Tuesday evening, Australian time, Information Age reports. ASOS runs an Australian store and has posted a notice for Australian customers on its /au/ site.
What ASOS says was accessed
ASOS says it is investigating unauthorised activity. According to the UK National Cyber Security Centre’s alert, the company has said that basic personal information, including name and contact details, may have been accessed. ASOS has also said it does not believe payment card information or account passwords were affected.
ASOS said it had “taken immediate action to restrict access”, the ABC reports. It apologised for the notification and told customers not to click or engage with the link it contained.
Several things are still unconfirmed. ASOS hasn’t said how many customers were affected, in Australia or anywhere else, or exactly which data each customer had exposed. The notification itself claimed the senders had broken into an ASOS data system and threatened to leak data. Treat those claims as unverified. ASOS hasn’t confirmed them, and the senders aren’t a reliable source on what they took or what they’ll do with it.
Assume you’re affected
The NCSC’s advice is blunt: if you’re an ASOS customer, assume you’re affected, even if you didn’t get the notification. A push alert only reaches people with the app installed and notifications switched on. A breach of customer details isn’t limited to them.
The UK Information Commissioner’s Office, the UK privacy regulator, published a statement on 7 October. It advises people to be cautious of links and attachments, and, if you change a password, to do it by logging in directly through the official website or app. It also says to watch bank accounts and online services for unusual activity, and never to share personal or financial information in response to unexpected contact.
We found no statement on the incident from Australia’s privacy regulator, the OAIC, as of 9 October.
The real risk: messages that use your details
Names, email addresses and phone numbers are what scammers need to make a message look genuine. The NCSC warns that suspicious messages can arrive some time after a breach. Expect emails and texts about refunds, “account verification”, delivery problems or compensation, each using your name and the ASOS brand.
The OAIC’s guidance on responding to a data breach notification covers this. Secure your email account with a strong password and multi-factor authentication, and watch for scams that use your name or personal details. If someone calls claiming to be from a company, hang up and call back on a number you’ve found yourself.
ASOS says it doesn’t believe passwords were affected and, according to Information Age, says customers don’t need to change their ASOS password. But if you’ve reused your ASOS password on other accounts, especially your email, change those accounts now. Our passkeys explainer covers the stronger option where a service offers it.
For businesses that buy from ASOS
Some small businesses use a work email or a shared account for retail orders. If so, warn whoever reads that inbox: a convincing “ASOS refund” or “verify your account” email is the obvious next move for a scammer.
For your own business’s obligations if customer data is ever exposed, see our guide to the Notifiable Data Breaches scheme.
Checklist
- Ignore the ASOS HACKED notification. Don’t tap its link or reply to the senders; ASOS has asked customers not to click or engage with it.
- Open ASOS yourself. If a message about your ASOS account or order arrives, close it and check by opening the app or typing the website address.
- Change reused passwords. If your ASOS password is also used on another account, especially your email, change that account’s password today.
- Turn on multi-factor authentication for your email. Your email account is the key to resetting every other password, so protect it first.
- Hang up and call back on unexpected calls. If a caller says they’re from ASOS or your bank about this incident, call back on a number you’ve looked up yourself.
- Watch your bank and card statements. ASOS doesn’t believe card details were affected, but keep checking for unfamiliar transactions, because scams can follow a breach some time later.
- Warn the shared inbox. If your business orders from ASOS on a work account, tell whoever reads that inbox to expect fake ASOS emails.
Tick items as you go. Your ticks stay in this browser.




