Don’t use a link, phone number, or contact details in a suspicious message. Open ASOS.com or the ASOS app yourself and check your account, order, or promotion there. ASOS says it contacts customers through an ASOS-branded email address or a verified social media account; a familiar logo, display name, or convincing order detail alone does not prove a message is genuine.
How to check whether an ASOS message is real
- Check the sender and channel. ASOS says it will only contact customers through an ASOS-branded email address or a verified social media account. A sender’s display name can be misleading, so inspect the address or account itself. ASOS warns about impersonators using fake Gmail addresses, social media, WhatsApp, and fake websites. Read ASOS Customer Care’s channel guidance.
- Go to ASOS independently. Type ASOS.com into your browser, use a saved bookmark, or open the official app. Check your order, account, or offer there instead of following the message’s link. ASOS says purchases should be made only on its official website.
- Contact Customer Care through the official site. If you are still unsure, find Customer Care after opening ASOS yourself. Do not use a phone number, email address, or other contact details supplied in the suspicious message. The UK National Cyber Security Centre (NCSC) gives the same advice: “If you have any doubts about a message, contact the organisation directly.” See the NCSC’s phishing guidance.
Clues that a message may be a scam
- It asks for sensitive information. Treat requests for passwords, card details, or other personal information with caution, especially in a social-media direct message. ASOS says it will never ask for card details or a password in social DMs.
- It creates pressure or plays on emotion. Urgency, scarcity, threats, emotional appeals, and references to current events are common phishing tactics. An implausibly generous offer is another reason to stop and verify.
- It contains a link, attachment, or QR code you were not expecting. Do not click the link, open the attachment, or scan the code. QR codes can lead to scam sites just like ordinary links.
- It looks polished—or has mistakes. Neither good design nor poor spelling settles the question. Scams can be convincing, and a logo, order detail, or familiar wording is not proof that the sender is ASOS.
ASOS says its logo may appear next to genuine email in inboxes that support BIMI, a standard for displaying verified brand logos. An absent logo is a reason for caution, but an icon should not replace checking the sender and visiting ASOS independently. Inbox support varies. ASOS explains its email and social-media guidance.
Does ASOS contact customers on WhatsApp?
ASOS warns that impersonators use WhatsApp, so treat an unexpected WhatsApp message claiming to be from ASOS as suspicious. Do not reply with personal information or use its links. Verify the issue through the ASOS app, website, or Customer Care reached independently. ASOS’s stated contact channels are an ASOS-branded email address and verified social media account.
Be alert to follow-up scams about the October 2026 incident
On 6 October 2026, ASOS reported that an unauthorized push notification containing an external link had been sent to some customers. ASOS said basic personal information, including names and contact details, may have been accessed. At the time of its notice, it said it did not believe payment-card information or account passwords were affected, and that its investigation was ongoing. These statements are not confirmation that no payment or password data could be affected.
#1 Best Overall
- PHISHING-RESISTANT 2FA: Cryptographically binds to real domains, making phishing attacks impossible unlike SMS codes or authenticator apps.
- 3-SIDE CAPACITIVE TOUCH: Tap the end, left, or right side to authenticate, so it works in any orientation or crowded USB port.
- MULTI-COLOR LED INDICATOR: Blue means ready, blinking blue means tap now, green means success, and red means error for instant status feedback.
- IP68 WATERPROOF & BATTERY-FREE: Crush-resistant one-piece construction survives daily carry on a keychain or in a bag for years without any batteries.
- UNIVERSAL COMPATIBILITY: Works with Google, Microsoft, Apple, GitHub, AWS, and any FIDO2 / U2F / WebAuthn service, storing up to 100 passkeys.
The NCSC’s alert, also published on 6 October 2026, said ASOS customers should assume they may be affected, even if they did not receive the notification, and watch for later suspicious messages. Criminals may use incident-related messages to make a fake link seem credible. Do not click a message’s link to check what happened; visit ASOS’s official updates and the NCSC alert directly. ASOS incident and customer-care information; NCSC alert for ASOS customers.
What to do if you clicked or shared information
If you only opened the link
Close the page. Do not enter information, download files, or continue interacting with it. Verify any claimed order or account issue by opening ASOS independently.
Rank #2
- SECURITY KEY FOR ENTERPRISE ACCESS: Supports FIDO2 passkeys and U2F for secure authentication across enterprise IT systems.
- PHISHING-RESISTANT AUTHENTICATION: Enables passwordless login with secure on-device credential storage and PIN-based user verification.
- COMPATIBLE WITH ENTERPRISE SYSTEMS: Works with FIDO2, WebAuthn, and U2F across enterprise, cloud, and modern IT environments.
- DRIVERLESS FIDO2 AUTHENTICATION: FIDO2 works natively with modern browsers and platforms. No drivers required.
- USB AND NFC CONNECTIVITY: Supports authentication via USB-C and NFC. No batteries required.
If you entered a password
Change that password through the real service, reached independently. Change it anywhere else you reused it, starting with your email account and ASOS account. Use unique passwords and turn on two-step verification or passkeys where available. ASOS’s notice about the October 2026 incident says it is not currently asking customers to change their ASOS password because of that incident; that is separate from changing a password you personally disclosed or reused.
If you shared card details or lost money
Contact your bank or card issuer promptly using its official app or the number on your card. Check for unfamiliar transactions and follow the bank’s advice.
Rank #3
- Phishing-Resistant Security: Guard against cyber threats like phishing and credential theft with bank-grade security from OneSpan, trusted by over 60% of the world’s largest financial institutions.
- Effortless, Password-Free Authentication: Experience easy, one-touch security with this FIDO2-certified device. Say goodbye to passwords and hello to secure, passwordless access in seconds.
- Portable and User-Friendly: Compact and easy to use, DIGIPASS FX7 ensures secure access anytime. Simply plug into a USB-C port on a laptop, desktop, tablet, or phone, and tap to authenticate. For added security, a PIN entry option is also available.
- Broad Compatibility: This single security key grants access to over 1,000 FIDO2-enabled services, compatible with Microsoft 365, Google Workspace, AWS, Salesforce, Okta, OneLogin, Ping Identity, and more.
- Plug-and-Play Activation: With a zero-footprint design, DIGIPASS FX7 requires no software installation or complex configuration. Just plug it in, and it’s ready to go.
If you opened an attachment or downloaded something
Do not open it or enter credentials into it. If you installed an app or program, use your device’s established security and support guidance to assess and remove it. Change any credentials you entered, using the steps above.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to report an ASOS phishing message in the UK
- Email: Forward suspicious emails to report@phishing.gov.uk.
- Text message: Forward suspicious texts to 7726.
- Money lost or account hacked: Follow the official reporting route for your location. In England and Wales, report fraud to Action Fraud; in Scotland, contact Police Scotland. GOV.UK explains how to report suspicious messages and fraud.
If you are outside the UK, use your country’s official cybercrime or consumer-protection reporting service and your mobile carrier’s reporting process.
Quick Recap
Best Value
- ENTERPRISE ROLLOUT: 25 White PVC cards in one SKU sized for bulk procurement, one card per employee for both web authentication and building access
- HARDWARE 2FA AND MFA: FIDO Alliance Certified FIDO2 v2.1 with CTAP Level 1 for phishing-resistant login and passwordless sign-in where the service supports it
- BUILDING ACCESS: MIFARE DESFire EV2 applet with 4K AES storage adds door and facility access to the same card employees use for account security
- CERTIFIED SECURE ELEMENT: NXP JCOP 4 chip rated Common Criteria EAL 6+ augmented
- DUAL INTERFACE: Tap over NFC (ISO 14443) or use a contact reader (ISO 7816), backed by a 2-year warranty from Swiss company Cryptnox
Rank #4
- HARDWARE 2FA AND MFA: FIDO Alliance Certified FIDO2 v2.1 with CTAP2 plus legacy U2F and CTAP1 for strong two-factor login and passwordless sign-in on services that support security keys
- BUILDING ACCESS ON ONE CARD: MIFARE DESFire EV2 4K applet with AES encryption adds office door and physical access control alongside digital authentication
- CERTIFIED SECURE ELEMENT: An NXP Common Criteria EAL6+ certified secure controller and Java Card platform protects your keys on a tamper-resistant chip
- DUAL INTERFACE SMART CARD: Contactless NFC ISO 14443 plus ISO 7816 contact reader support in an ISO 7810 ID-1 format that is passive and needs no battery
- SWISS ENGINEERED DESIGN: Built by Cryptnox as a single card for authentication and access control and backed by a 2 year warranty
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

