Data breach
Under Armour
- Records
- 74,967,293
- Breach date
- 24 November 2025Estimated
- Added
- 11 December 2025
What was exposed
3 types of data · 2 more reported
- Email addresses1
- Names1
- Gender1
- Dates of birthReported, not counted
- Purchase historyReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
The Everest ransomware group claimed in November 2025 that it stole 343 GB of internal data from Under Armour, and months later, tens of millions of customer records surfaced publicly. According to Cybersecurity News, Everest announced the theft on its dark web leak site on November 16, 2025, and posted sample records it said came from customer and employee databases. In January 2026, customer data from the incident appeared on a public hacking forum, and The 5K Runner reported that roughly 72.7 million unique email addresses had been published. The investigation team indexes 74,967,293 rows from this listing and estimates the attack occurred on or around November 24, 2025. Under Armour has acknowledged the claims but disputes their scale, telling Fox News through a spokesperson that there is no evidence UA.com, payment processing systems, or stored customer passwords were affected.
November 16, 2025: The Everest ransomware group listed Under Armour on its dark web leak site, claiming the theft of 343 GB of internal data and demanding contact within seven days, according to Cybersecurity News.
January 2026: Customer data linked to the November attack was published on a public hacking forum; The 5K Runner reported the dataset contained about 72.7 million unique email addresses.
September 14, 2026: A federal judge in Maryland denied Under Armour's motion to dismiss a proposed class action over the breach, Law360 reported.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses, genders, and names.
Additional reporting corroborates a broader set of fields. Mozilla Monitor lists email addresses, dates of birth, genders, geographic locations, names, and purchase information in the dataset. Everest's own claims, as reported by Cybersecurity News, included phone numbers, physical addresses, transaction histories, and employee contact data, though those details have not been independently verified. Researchers cited by Fox News also found Under Armour employee email addresses in the leak. Under Armour has stated that passwords and payment card data were not affected, per its statement to Fox News.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Even without passwords or payment details, this type of data supports several kinds of fraud. Names, email addresses, birth dates, locations, and purchase histories can fuel convincing phishing emails that appear to come from a retailer the victim actually shops with. Employee addresses in the leak raise the risk of targeted scams against the company and business email compromise. Birth dates and locations are also common identity-verification answers, which can make account takeovers easier elsewhere. The Register's reporting on the class action describes plaintiffs alleging harms including identity theft.
What Is Under Armour Doing in Response?
Under Armour says it is investigating the claims with the help of external cybersecurity experts. In its statement to Fox News, a spokesperson said any implication that sensitive personal information of tens of millions of customers was compromised is unfounded, and that the company has found no evidence that UA.com or payment and password systems were affected. The company did not, in that statement, confirm the breach or its size. Meanwhile, litigation continues: the proposed class action survived dismissal in September 2026, according to Law360.
What Should You Do If You Were Affected?
Be cautious with emails or texts referencing Under Armour, your order history, or a "breach refund." Attackers can use real purchase details to seem credible. Avoid clicking links in unsolicited messages.
Change the password on your Under Armour account if you have one, and anywhere you reused it.
Turn on multi-factor authentication for your email and shopping accounts, since email resets are a common takeover path.
Watch your financial statements and credit reports for unfamiliar activity. You can request free reports from the major credit bureaus and consider a fraud alert.
Watch for official communications. If Under Armour sends direct notifications, follow the steps in them and verify any link against the company's own website.
In the news
- Cybersecurity News: Everest Ransomware Group Claims Under Armour Breachcybersecuritynews.com (opens in a new tab)
- Fox News: Under Armour investigates data breach claimsfoxnews.com (opens in a new tab)
- TechRadar: Under Armour cyberattack may put millions at risktechradar.com (opens in a new tab)
- The 5K Runner: Under Armour confirms second major data breachthe5krunner.com (opens in a new tab)
- Mozilla Monitor: Under Armour Data Breachmonitor.mozilla.org
