SecurityOctober 8, 20268 min read

What to Do After the ASOS Data Breach (October 2026)

PT

By PrivacyOn Team

Privacy Research & Removal Operations

SharePostFacebookEmail
What to Do After the ASOS Data Breach (October 2026)

Worried you're exposed? Find out in 60 seconds with a free exposure scan.

ASOS confirmed a data breach on October 7, 2026 after attackers hijacked its mobile app to push "HACKED" notifications to shoppers. ASOS says names and contact details were exposed, but no payment card details or account passwords were accessed. Change your ASOS password now, switch on two-factor authentication, and treat every ASOS message as suspect.

What ASOS Has Confirmed

Reported as exposed: customer names and contact details (names, delivery and email addresses, phone numbers) plus some account-related information such as recent search history. Reported as not accessed: payment card details and account passwords. How: ASOS says an unauthorised party impersonated a trusted contact to obtain an employee account's login credentials, then used them to reach information held on certain third-party platforms ASOS uses. Scale: ASOS has not published a victim count; for context it reports roughly 17 million customers across about 150 countries.

What Actually Happened

On October 6, 2026, ASOS customers began receiving push notifications through the ASOS app claiming their data had been stolen. The messages came from a group calling itself "Xuanye Group," which used its access to broadcast the alert directly into shoppers' phones — an unusually public form of extortion pressure. ASOS confirmed the incident the following day and said its investigation pointed to social engineering: someone talked an employee out of their credentials, then reused that access against third-party platforms holding ASOS customer data.

The attackers have separately claimed they compromised an ASOS cloud data environment and hold millions of records. ASOS has not confirmed that claim, and no verified record count exists yet. Treat any number you see circulating — including figures in the millions — as an attacker claim until ASOS or a regulator publishes one.

Note that this is a different incident from the ASOS US breach disclosed in August 2026, which affected roughly 138,800 individuals and did involve financial information. If you received a notice earlier in 2026, it was almost certainly about that earlier event.

Why a "Names and Emails Only" Breach Still Matters

No card numbers were taken, so the immediate fraud risk is low. The real risk is targeted phishing. An attacker holding your name, email, phone number, delivery address and your recent ASOS searches can write a scam message that reads like a genuine order update: the right items, the right address, the right tone. That is how "your parcel is held, pay a £1.99 redelivery fee" texts convert. The hijacked in-app notifications prove these attackers are willing to use ASOS's own channels, so a message looking official is not evidence that it is.

Step 1: Change Your ASOS Password — and Anywhere You Reused It

Sign in through the ASOS app or by typing asos.com into your browser directly — never through a link in an email or text. Change your password to something unique. If you used that same password anywhere else (email, PayPal, another retailer), change it there too; credential reuse is what turned ASOS's earlier 2026 US incident into account takeovers. A password manager makes unique passwords practical.

Step 2: Turn On Two-Factor Authentication

Enable two-factor authentication or a passkey on your ASOS account and, more importantly, on the email address attached to it. Your inbox is the reset path for every other account you own, so it deserves the strongest protection you can give it. Prefer an authenticator app or passkey over SMS codes where you have the choice.

Is your data already out there?

Leaked data ends up on broker sites and in scammers' hands. Run a free 60-second scan to see your exposure — then let us remove it.

Run a free scan

★★★★★ 4.8/5 · Trusted by thousands of families

Step 3: Treat Every ASOS Message as Unverified for the Next Few Months

Expect a wave of phishing emails, texts and even app-style notifications referencing real orders. Rules that hold up:

  • Never click a tracking or payment link in an unexpected message — open the ASOS app and check your orders there.
  • No legitimate retailer asks for your password, full card number, or a small "redelivery" or "customs" fee by text.
  • Check the sender domain, not the display name. Lookalike domains (asos-delivery.com, asos.support) are the giveaway.
  • Be suspicious of urgency. "Your account will be closed in 24 hours" is pressure, not policy.

Step 4: Watch Your Statements Anyway

ASOS says cards were not taken, but a saved card plus an account takeover is still a fraud route. Review your card and bank statements for the next three statement cycles and turn on transaction alerts in your banking app. In the US, check all three credit bureaus for accounts you did not open; freezing your credit at Experian, Equifax and TransUnion is free and blocks most new-account fraud.

Step 5: Delete the Data ASOS No Longer Needs

You can reduce the blast radius of the next breach by shrinking what is stored about you. Remove saved cards and old delivery addresses from your ASOS account, and if you no longer shop there, submit a deletion request: UK and EU customers have erasure rights under UK GDPR and the GDPR, and residents of California and a dozen other US states have deletion rights under their own privacy laws. ASOS handles these through its privacy contact in its privacy policy.

Step 6: Get Your Address and Phone Number Off Data Broker Sites

Breach data does not sit still. Names, emails, phone numbers and addresses from incidents like this get cross-referenced against people-search sites, which already publish your address, relatives and phone history for anyone who searches your name. That combination is what makes the follow-up scams believable — and the brokers are the one part of this you can actually clean up.

PrivacyOn removes your personal information from 100+ data brokers and people-search sites, re-removes you when they re-list, submits Google and Bing delisting requests, and monitors the dark web and breach dumps for your email, phone and SSN so you hear about the next ASOS-style incident from us rather than from a push notification. Plans cover up to 5 household members and start at $8.33/month.

Start With a Free Exposure Scan

PrivacyOn's free scan shows exactly which broker sites currently publish your name, address and phone number — the raw material for the phishing wave that follows every retail breach. Removal plans run from $8.33/month and include dark web and breach alerts for your whole household.

Frequently Asked Questions

Was my ASOS password stolen in the October 2026 breach?

ASOS says account passwords were not accessed, and neither were payment card details. Change your password anyway: the investigation is ongoing, attacker claims go beyond what ASOS has confirmed, and a unique password costs you two minutes. If you reused that password on another site, change it there first.

How many ASOS customers were affected?

ASOS has not published a figure. The attackers claim millions of records, but that claim is unverified and ASOS has not confirmed how many customers had data accessed. ASOS serves roughly 17 million customers in about 150 countries, which is the size of the customer base, not a victim count.

Is the "HACKED" notification I got in the ASOS app real?

The October 6 notification was genuinely sent through ASOS's app by the attackers, not by ASOS. That is exactly why you should not act on instructions in any message now. Do not click links or pay fees from notifications, texts or emails — open the ASOS app yourself, or type asos.com, and check your account directly.

Should I close my ASOS account?

Closing it does not delete the data already taken, so it is not an emergency fix. If you do not plan to shop there again, remove saved cards and addresses and submit a formal deletion request under UK GDPR, the GDPR, or your US state privacy law. If you will keep shopping, a unique password plus two-factor authentication matters more than deleting the account.

Do I need identity theft protection after an ASOS breach?

Credit monitoring is less useful here, because no Social Security numbers or card numbers were reported taken. What helps is cutting off the contact data that makes follow-up scams work and watching for your details in future breach dumps. PrivacyOn covers both — broker removal across 100+ sites plus dark web and breach alerts — from $8.33/month for up to 5 people, and the exposure scan is free.

How will I know if my data shows up in the dump?

Check your email address against a breach-notification service, and set up continuous monitoring so you are not relying on a one-off check. PrivacyOn monitors breach databases and dark web marketplaces for your email, phone number and SSN and alerts you when something new surfaces, which is far more reliable than waiting for a company notification letter.

SharePostFacebookEmail
PT
PrivacyOn Team

Privacy Research & Removal Operations

Operates removal across 100+ data broker sitesGuides verified against live opt-out processesContent reviewed and updated continuously

The team that operates PrivacyOn's data-removal service — publishing opt-out guides and privacy research based on handling real removal requests every day.

Find out what's already exposed

A free 60-second scan shows your breaches and broker exposure. PrivacyOn removes it and monitors 24/7 so it stays gone.

★★★★★ 4.8/5 · Trusted by thousands of families