Breach report
RetailUnder Armour
Under Armour says it's 'aware' of data breach claims after 72M customer records were posted online
A dataset of about 72 million Under Armour customer records, claimed by the Everest ransomware gang, circulated online in early 2026, while the sportswear maker said it was investigating and disputed that most customers had sensitive data exposed.
Reported by TechCrunch
Records exposed
72M
About 72 million customer records
Scale vs. largest on file
- When
- 2025 (disclosed 2026)
- How they got in
- Ransomware group data theft (Everest)
- Sector
- Retail
In November 2025, the Everest ransomware group listed Under Armour on its dark web leak site, claiming to have stolen a large cache of the sportswear company's data. In January 2026, a dataset attributed to the theft began circulating more widely, and breach notification service Have I Been Pwned obtained a copy and began alerting affected people. TechCrunch reported on January 22 that the data contained about 72 million customer records, and after reviewing a sample, confirmed that the records appeared authentic.
The exposed information included customer names, email addresses, dates of birth, approximate locations derived from ZIP or postal codes, gender and purchase details. Employee email addresses were also present. Under Armour said its investigation, carried out with outside cybersecurity experts, was ongoing and that it had found no evidence the incident affected its main website or the systems used to process payments or store customer passwords.
The company also pushed back on the scale of the harm, saying that only a very small percentage of affected customers had any information that could be considered sensitive, and disputing that tens of millions had sensitive data compromised. It did not say how the attackers got in, whether it had received a ransom demand or when it would notify customers directly. Everest, which has operated since around 2020, is known for stealing data and extorting victims with the threat of publication.
The episode fits a pattern seen in other recent retail breaches, in which customers first learn of an incident through a hacker's leak or a third-party notification service rather than from the company itself. Under Armour had faced security scrutiny before: in 2018, its then-owned MyFitnessPal app disclosed a breach affecting about 150 million users.
Although the stolen records did not include payment information, the combination of names, birthdates, locations and purchase histories is valuable for tailored phishing and identity fraud. The case also highlights a gap between what companies consider sensitive under breach notification laws and what consumers might reasonably expect to be told. For shoppers, the practical steps were to watch for convincing emails referencing recent orders and to check exposure through services like Have I Been Pwned.