Asos has admitted that hackers took more of your personal details than it first said, and the BBC only found out because the criminals contacted it to say the haul went well beyond “basic contact details.” Think about that. A stolen bag is usually described by the person who lost it. Here the thieves are issuing corrections, like a rival store keeping the books on your shopping.
The absurd part is what happens next. Once a shopper learns that their name, address and order history are apparently worth something to strangers, the natural question is why the company got to keep the proceeds of their information in the first place. Somewhere in a spare room, someone is already building a spreadsheet of their own old delivery addresses and pricing themselves at £4.99 a record. Asos treated your data like a stock of unsold jumpers, then lost it, and now you are the one wondering about the commission.
The reality is less funny. Selling your own data is not a side hustle. It is how you end up on a list that gets sold again and again, and it leaves you holding the risk. The useful move is dull: change the password on any account that uses the same login, be suspicious of any email or text that mentions your Asos order, and never reply to anyone offering to buy your details. Your data is not a collectible. Keep it that way, and let the retailer send the cheque when it works out how to pay for its own mistake.