Under Armour: Data of 72 Million Customers Breached in Massive Ransomware Attack

In today’s increasingly interconnected world, even sporting apparel giants can become targets of sophisticated cyber attacks. This is what happened to Under Armour, the famous fitness clothing and accessories brand, victim of a significant data breach that occurred in November 2025 and was only made public in the early months of 2026.

The company was hit by a ransomware attack orchestrated by the criminal group Everest, which compromised an enormous amount of customers’ personal information. According to official sources, as many as 72.7 million customer accounts were involved in the breach. The stolen data includes email addresses, names, dates of birth, gender, postal codes, purchase information, and employee email addresses. The Everest group also claimed to have acquired phone numbers, physical addresses, loyalty program details, and information about customers’ preferred stores, although these additional claims have not been confirmed by the company.

The impact of this breach is particularly concerning due to the volume of compromised data and the nature of the information. Although there is no evidence that passwords or financial data were stolen, the information taken is sufficient to conduct targeted phishing attacks or attempt identity theft. The Everest group had threatened to publish the data unless Under Armour paid a ransom within seven days of the demand made in November 2025. In the end, the data was actually published on a hacking forum in January 2026, suggesting that the company refused to give in to the extortion demands.

For the consumers involved, it is now essential to pay particular attention to suspicious emails that might try to exploit the stolen data. Experts recommend changing passwords for Under Armour accounts and any other service where the same combination of credentials is used. The service “Have I Been Pwned,” which monitors data breaches, notified 72 million individuals on January 21, 2026, allowing them to verify if their data had been compromised.

  • Key points to remember:
  • The breach affected 72.7 million Under Armour customer accounts, with personal data exposed but no evidence of compromised passwords or financial information.
  • The Everest ransomware group attempted to extort money by threatening to publish the data, which was then actually released in January 2026.
  • It is essential for Under Armour customers to remain vigilant against phishing attempts and consider changing their passwords across all services they use.

Sources:
ABC News, WTOP, TechCrunch, The Register, Have I Been Pwned

Source: SecurityWeek