Full Breakdown
Under Armour Investigates Major Data Breach Affecting 72 Million Customers
1/26/2026, 11:09:33 AM
Overview of the Data Breach Incident
Under Armour, the Baltimore-based sportswear retailer, is currently investigating a significant data breach that has reportedly compromised the email addresses and personal details of approximately 72 million customers. The breach is believed to have occurred in November 2025, when the Everest ransomware group claimed responsibility for the attack, alleging they had accessed 343 gigabytes of sensitive data. The stolen information includes email addresses, names, genders, birthdates, geographic locations, and purchase history.
Company Response and Investigation
In response to the breach, Under Armour has stated that there is currently no evidence to suggest that its website, payment systems, or customer passwords were compromised. Company spokesperson Matt Dornic emphasized that the investigation is ongoing, with the assistance of external cybersecurity experts. Under Armour has also asserted that any implication that sensitive personal information of tens of millions of customers has been compromised is unfounded.
Criticism and Legal Actions
Despite Under Armour's reassurances, the company faces criticism for its handling of the situation. Cybersecurity expert Troy Hunt, CEO of Have I Been Pwned, noted the unusual lack of an official disclosure statement from Under Armour, given the scale of the breach. Furthermore, several class-action lawsuits have been filed against Under Armour, alleging negligence in protecting customer data and failing to notify affected individuals in a timely manner. One lawsuit was initiated by a customer who received a breach alert from Capital One’s CreditWise monitoring service, indicating that their email address was exposed.
Broader Implications and Security Concerns
The breach raises significant concerns about the potential for identity theft and phishing scams targeting affected customers. Cybersecurity advisor Jake Moore warned that once personal data is stolen, it can be exploited for follow-up attacks, urging individuals to remain vigilant against suspicious communications. The incident underscores the ongoing risks associated with data security breaches in the retail industry, which continues to be a lucrative target for cybercriminals.
Conflicting Reports and Gaps
While Under Armour maintains that only a small percentage of affected customers may have had sensitive information exposed, there are discrepancies regarding the extent of the data compromised. The Everest ransomware group has claimed to possess a vast amount of data, including additional information not verified by breach trackers, such as phone numbers and home addresses. The lack of clarity on what constitutes "sensitive" information further complicates the situation.
What's Next for Under Armour?
As the investigation continues, Under Armour has not disclosed whether it will notify customers about the breach or if it has received any ransom demands from the hackers. The company’s response to the incident and the outcomes of the ongoing lawsuits will be closely monitored as it navigates the fallout from this significant data breach.
Verbatim Quotes
- “We have no evidence to suggest this issue has affected UA.com or systems used to process payments or store customer passwords. Any implication that sensitive personal information of tens of millions of customers has been compromised is unfounded.” — Matt Dornic, Under Armour Spokesperson
- “That’s unusual, especially given the size of the organisation, the scale of the breach and the amount of time that has passed since the incident,” — Troy Hunt, CEO of Have I Been Pwned
This incident serves as a reminder of the critical importance of data security and the need for companies to implement robust measures to protect customer information.
