Drooid Logo
Back to story perspectives

Full Breakdown

Under Armour Investigates Major Data Breach Affecting 72 Million Customers

1/23/2026, 6:01:06 AM

Overview of the Data Breach

Under Armour, the Baltimore-based clothing and fitness data company, is currently investigating a significant data breach that reportedly compromised the personal information of approximately 72 million customers. The breach is believed to have occurred in November 2025, with the Everest ransomware group claiming responsibility for the incident. The stolen data, which has surfaced on a hacker forum, includes email addresses, names, genders, dates of birth, ZIP codes, and purchase history.

Under Armour's Response

In response to the breach, Under Armour has stated that there is currently no evidence to suggest that its website (UA.com) or systems used for processing payments and storing customer passwords were affected. The company emphasized that any implication that sensitive personal information of tens of millions of customers has been compromised is unfounded. Under Armour spokesperson Matt Dornic confirmed that the investigation is ongoing and is being conducted with the assistance of external cybersecurity experts.

Data Details and Security Concerns

The dataset reportedly includes not only customer information but also email addresses belonging to Under Armour employees. Cybersecurity website Have I Been Pwned has been instrumental in notifying affected individuals about the breach. Troy Hunt, CEO of Have I Been Pwned, has expressed surprise at the lack of an official disclosure from Under Armour, given the scale of the breach and the time elapsed since the incident.

Despite Under Armour's assurances, concerns remain regarding the potential for identity theft and phishing scams, as the leaked data could be exploited by malicious actors. Affected customers have been advised to update passwords used on other sites and enable two-factor authentication to enhance their security.

Criticism and Legal Action

The company has faced criticism for its handling of the situation, particularly regarding the delay in public acknowledgment and the lack of transparency about the breach's details. Some customers have already initiated legal action, with at least one class-action lawsuit filed in Maryland by an affected customer who received a breach alert from a credit monitoring service.

Conflicting Reports and Ongoing Investigation

While Under Armour maintains that only a small percentage of affected customers had sensitive information compromised, it has not specified what constitutes "sensitive" data or provided an exact number of impacted individuals. Additionally, there are questions about whether the company will notify customers whose information was compromised and if any ransom demands were made by the hackers.

What's Next

As the investigation continues, Under Armour has not disclosed a timeline for concluding its inquiry or whether it plans to implement additional security measures. The incident highlights the ongoing risks associated with data breaches and the importance of robust cybersecurity practices for companies handling sensitive customer information.