Skip to main content
Breach Signal

Breach report

Retail

Adidas

Adidas warns of data breach after customer service provider hack

Adidas disclosed in May 2025 that attackers had stolen consumer contact information by breaching one of its outside customer service providers, following earlier incidents affecting shoppers in Turkey and South Korea.

Reported by BleepingComputer

Records exposed

Undisclosed

Undisclosed

When
2025
How they got in
Compromise of third-party customer service provider
Sector
Retail

In late May 2025, German sportswear giant Adidas announced that an unauthorized external party had obtained certain consumer data through a third-party customer service provider. The company said the stolen information consisted mainly of contact details belonging to consumers who had contacted its help desk in the past. Adidas stressed that passwords, credit card numbers and other payment information were not involved.

The disclosure followed separate notices earlier in May to customers in Turkey and South Korea, where Adidas said data from customer service inquiries made in 2024 and earlier had been exposed. In those regions, the affected information included names, email addresses, phone numbers, dates of birth and home addresses. It was not immediately clear whether the incidents were connected, although all involved outside providers handling customer support.

Adidas did not name the vendor, say when the intrusion was detected or disclose how many customers were affected. It said it had immediately taken steps to contain the incident, launched an investigation with information security experts and was informing potentially affected consumers as well as data protection and law enforcement authorities. Because Adidas operates across the European Union, the incident fell under GDPR's notification requirements.

The breach came during a period of heightened attacks on major retailers and consumer brands. In the same weeks, British retailers Marks & Spencer and the Co-op were dealing with severe social engineering attacks, and luxury brands including Dior and Victoria's Secret reported security incidents. Many of these intrusions targeted customer service systems, contact centers or cloud customer relationship management platforms rather than core transaction systems, reflecting attackers' growing focus on the outsourced edges of large companies.

Although no financial data was taken, contact details combined with knowledge that a person is an Adidas customer can fuel convincing phishing campaigns, such as fake order updates or refund offers. The incident is a reminder that consumer data is only as secure as the least-protected vendor that can access it. For companies, it underscored the need for strict access controls and monitoring of support contractors; for consumers, it was a prompt to treat unsolicited messages invoking a brand relationship with caution.

More from the wire

More in Retail.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.