
Under Armour suffers massive data breach exposing millions of emails
Under Armour suffers massive data breach exposing millions of emails
- Cybersecurity researchers discovered a data breach affecting 72 million Under Armour customer email addresses.
- The breach is linked to a ransomware attack by the Everest ransomware group that occurred in November 2025.
- Customers are advised to take proactive steps to secure their accounts and be cautious of potential phishing attacks.
Story
In a significant cybersecurity incident, Under Armour, the well-known sports apparel and accessories company, reported a data breach that exposed personal information linked to approximately 72 million customers. The breach was initially discovered by cybersecurity researchers who uncovered the leaked data being traded on various hacker forums. An investigation into the breach is ongoing, revealing that the exposed data potentially includes customer details connected to their purchases made through the retailer's platforms. The incident appears to be tied to a ransomware attack conducted by the Everest ransomware group in November 2025, indicating a broader trend of increasing attacks on corporate entities aimed at financial gain. However, there is currently no evidence suggesting that Under Armour's official website, UA.com, or its payment processing systems were compromised during this event, meaning payment information and passwords were not leaked. This critical information provides some level of reassurance for customers who may be concerned about the security of their financial details. Nevertheless, the exposure of email addresses remains troubling as it creates a potential avenue for follow-up phishing campaigns targeting affected individuals. In response to the breach, customers are encouraged to take proactive steps to secure their accounts and personal information. Recommendations include checking if their email addresses appeared in past breaches using the Have I Been Pwned website, monitoring for unusual account activity, and enabling multi-factor authentication on all email accounts. The incident underscores the evolving nature of cybersecurity threats facing consumers and organizations alike, highlighting the importance of vigilance and preventive measures to safeguard personal data against cybercriminals.