If an email, text, social message, or notification claims to be from ASOS, don’t use its links or contact details to check whether it’s genuine. Open the ASOS website or app yourself and verify the order, account issue, or offer there. ASOS says it contacts customers through an ASOS-branded email address or a verified social media account; a familiar logo or convincing message is not proof.
How to check whether an ASOS message is genuine
- Check the channel. ASOS says it will contact customers through an ASOS-branded email address or a verified social media account. A display name can be copied, and scammers may use fake Gmail accounts, WhatsApp, social media, or websites that imitate ASOS. Check the actual sender or account, but don’t treat that check alone as proof. ASOS Customer Care explains its official contact channels.
- Go to ASOS independently. Type asos.com into your browser, use a saved bookmark, or open the official app. Check your order or account from there. ASOS says purchases should be made only on its official website; don’t sign in through a link in an unexpected message.
- Look for pressure or unusual requests. Unexpected demands for personal information, urgent warnings, emotional appeals, scarcity claims, and offers that seem implausibly good are reasons to pause. These are clues, not a definitive test: phishing messages can be polished and free of spelling mistakes. The UK National Cyber Security Centre (NCSC) notes that scams have become more convincing. NCSC phishing guidance
- Be wary of requests for sensitive details. ASOS says it will never ask for card details or a password in social direct messages. Don’t share passwords or payment information in a DM, email reply, or form reached through a suspicious link.
- Treat logos and QR codes cautiously. ASOS says its logo may appear beside genuine email in inboxes that support BIMI, a system for displaying verified brand logos. An absent logo is a reason for caution, but its presence is not a substitute for checking the sender and opening ASOS independently; inbox support varies. A QR code can also lead to a scam site, so don’t scan an unexpected one.
If anything still seems uncertain, stop responding and contact ASOS through Customer Care reached from its official website or app. Don’t call a number or use an address supplied in the suspicious message. As the NCSC advises: “If you have any doubts about a message, contact the organisation directly.”
What to do about the October 6, 2026 ASOS notification incident
On October 6, 2026, ASOS said an unauthorized push notification containing an external link had been sent to some customers. ASOS said basic personal information, including names and contact details, may have been accessed. At the time of its notice, ASOS said it did not believe payment-card information or account passwords had been affected, and that its investigation was ongoing. These are the company’s reported findings at that time, not confirmation that every affected data field is known.
The NCSC’s alert, also published October 6, advised ASOS customers to assume they may be affected, even if they did not receive the notification, and to watch for later suspicious messages. Don’t click or engage with the notification’s external link. Scammers may use news of an incident to make follow-up messages seem credible, so verify any related request through ASOS’s official website or app. Check the ASOS Customer Care updates and NCSC alert for current information.
#1 Best Overall
- PHISHING-RESISTANT 2FA: Cryptographically binds to real domains, making phishing attacks impossible unlike SMS codes or authenticator apps.
- 3-SIDE CAPACITIVE TOUCH: Tap the end, left, or right side to authenticate, so it works in any orientation or crowded USB port.
- MULTI-COLOR LED INDICATOR: Blue means ready, blinking blue means tap now, green means success, and red means error for instant status feedback.
- IP68 WATERPROOF & BATTERY-FREE: Crush-resistant one-piece construction survives daily carry on a keychain or in a bag for years without any batteries.
- UNIVERSAL COMPATIBILITY: Works with Google, Microsoft, Apple, GitHub, AWS, and any FIDO2 / U2F / WebAuthn service, storing up to 100 passkeys.
If you already clicked a link or shared information
- Opened a link but entered nothing: Close the page. Don’t download files, approve prompts, or enter information. If you downloaded something or granted access, seek help through your device maker’s or local cyber-safety authority’s official guidance.
- Entered a password: Change it through the real service, reached independently. If you reused it elsewhere, change it on those accounts too. Prioritize your email account and ASOS account, and use unique passwords and two-step verification or passkeys where available.
- Shared payment details or see an unfamiliar charge: Contact your bank or card issuer promptly using its official app or the number on your card. Don’t use contact details from the suspicious message.
- Lost money or believe an account was taken over: Report it through the appropriate official route for your location; UK routes are listed below.
ASOS’s incident notice said it was not currently asking customers to change their ASOS password because of that incident. That specific advice does not change the need to reset a password you personally disclosed, or one reused on other services. Follow the latest ASOS guidance for incident updates.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to report a suspicious ASOS message in the UK
- Email: Forward suspicious emails to [email protected].
- Text message: Forward suspicious texts to 7726.
- Money lost or account compromised: Use the official fraud-reporting route for your part of the UK. GOV.UK lists the routes for England and Wales, Scotland, and other locations. If you’re outside the UK, use your country’s official reporting guidance.
For general phishing guidance, the NCSC recommends reporting suspicious messages and avoiding links or attachments you cannot verify. Read the NCSC guidance.
Quick Recap
Best Value
- ENTERPRISE ROLLOUT: 25 White PVC cards in one SKU sized for bulk procurement, one card per employee for both web authentication and building access
- HARDWARE 2FA AND MFA: FIDO Alliance Certified FIDO2 v2.1 with CTAP Level 1 for phishing-resistant login and passwordless sign-in where the service supports it
- BUILDING ACCESS: MIFARE DESFire EV2 applet with 4K AES storage adds door and facility access to the same card employees use for account security
- CERTIFIED SECURE ELEMENT: NXP JCOP 4 chip rated Common Criteria EAL 6+ augmented
- DUAL INTERFACE: Tap over NFC (ISO 14443) or use a contact reader (ISO 7816), backed by a 2-year warranty from Swiss company Cryptnox
Rank #4
- HARDWARE 2FA AND MFA: FIDO Alliance Certified FIDO2 v2.1 with CTAP2 plus legacy U2F and CTAP1 for strong two-factor login and passwordless sign-in on services that support security keys
- BUILDING ACCESS ON ONE CARD: MIFARE DESFire EV2 4K applet with AES encryption adds office door and physical access control alongside digital authentication
- CERTIFIED SECURE ELEMENT: An NXP Common Criteria EAL6+ certified secure controller and Java Card platform protects your keys on a tamper-resistant chip
- DUAL INTERFACE SMART CARD: Contactless NFC ISO 14443 plus ISO 7816 contact reader support in an ISO 7810 ID-1 format that is passive and needs no battery
- SWISS ENGINEERED DESIGN: Built by Cryptnox as a single card for authentication and access control and backed by a 2 year warranty
Rank #3
- Phishing-Resistant Security: Guard against cyber threats like phishing and credential theft with bank-grade security from OneSpan, trusted by over 60% of the world’s largest financial institutions.
- Effortless, Password-Free Authentication: Experience easy, one-touch security with this FIDO2-certified device. Say goodbye to passwords and hello to secure, passwordless access in seconds.
- Portable and User-Friendly: Compact and easy to use, DIGIPASS FX7 ensures secure access anytime. Simply plug into a USB-C port on a laptop, desktop, tablet, or phone, and tap to authenticate. For added security, a PIN entry option is also available.
- Broad Compatibility: This single security key grants access to over 1,000 FIDO2-enabled services, compatible with Microsoft 365, Google Workspace, AWS, Salesforce, Okta, OneLogin, Ping Identity, and more.
- Plug-and-Play Activation: With a zero-footprint design, DIGIPASS FX7 requires no software installation or complex configuration. Just plug it in, and it’s ready to go.
Rank #2
- SECURITY KEY FOR ENTERPRISE ACCESS: Supports FIDO2 passkeys and U2F for secure authentication across enterprise IT systems.
- PHISHING-RESISTANT AUTHENTICATION: Enables passwordless login with secure on-device credential storage and PIN-based user verification.
- COMPATIBLE WITH ENTERPRISE SYSTEMS: Works with FIDO2, WebAuthn, and U2F across enterprise, cloud, and modern IT environments.
- DRIVERLESS FIDO2 AUTHENTICATION: FIDO2 works natively with modern browsers and platforms. No drivers required.
- USB AND NFC CONNECTIVITY: Supports authentication via USB-C and NFC. No batteries required.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




