ASOS is back in the headlines today over customer account access — and it’s a textbook example of a threat that could hit almost any of us, on almost any website we use.

Here’s the important bit, because the word “hacked” gets used loosely. ASOS’s own systems weren’t cracked open by someone forcing their way in. What happened is more subtle, and far more common: attackers took login details stolen in other companies’ data breaches and simply tried them on ASOS — betting that people reuse the same email and password across lots of sites. Where the details matched, they were straight in. It’s a technique called credential stuffing.

The confirmed incident earlier this year affected an estimated 138,000 customers. The attackers used credentials sourced from outside ASOS; the retailer blocked the affected accounts and forced password resets. Today, further — so far unverified — claims of a wider breach have circulated and ASOS’s share price fell; at the time of writing the company had not confirmed them. But whatever the final picture, the core lesson doesn’t change.

What is credential stuffing, in plain English?

Picture a burglar who’s found a bunch of keys dropped outside a different building. They don’t pick your lock — they just walk down the street trying each key in every door, because people so often use the same key everywhere. That’s credential stuffing. The stolen “keys” are email-and-password combinations leaked from one website, then tested automatically against hundreds of others — your email, your bank, Netflix, Facebook, Instagram, Spotify, Amazon, eBay, a sports membership portal, a fashion site like ASOS. If you’ve reused a password, a single old leak can unlock your whole digital life.

Two things that stop it dead

1. A different, unique password for every single account. This is the big one, and I can’t say it strongly enough. If every site has its own password, a leak at one site can’t open any other. Nobody can remember dozens of unique passwords — so let a password manager create and store them for you.

2. Multi-factor authentication (MFA) wherever it’s offered. That’s the code sent to your phone, or an app approval, on top of your password. Even if a criminal has your password, they can’t get in without that second step. It would help here — though it isn’t clear ASOS offers it to shoppers yet, which is itself a nudge to switch MFA on everywhere you can: your email first, then banking, social media and shopping.

Why this matters for your business too

This isn’t only a consumer problem. Staff reuse passwords between personal and work accounts all the time, and criminals credential-stuff business logins — Microsoft 365, your line-of-business systems, your suppliers — in exactly the same way. The defences are the same: unique passwords through a managed password tool, MFA enforced on your Microsoft 365, and the fundamentals certified through Cyber Essentials. It’s precisely the kind of gap we close for the businesses we look after.

So whatever the ASOS story turns out to be, take the free win today: use a unique password for every online account, and switch on MFA everywhere you can. One old leak should never be able to open every door you own.

Sources: ASOS US breach notification (August 2026) and reporting by CyberInsider, GBHackers, eSecurity Planet and others on the confirmed credential-stuffing incident; plus 6 October 2026 reporting of further, as-yet-unverified claims that ASOS has not confirmed. This article is general cyber-security guidance and the author’s personal opinion.