Monday, August 3, 2026

Markets & Business

Under Armour investigates data breach claims

Under Armour is investigating a potential data breach after a ransomware group claimed responsibility, though the company disputes the scale of sensitive information compromised.

Under Armour investigates data breach claims

Under Armour is investigating claims of a data breach after a cybercriminal posted millions of customer records online. The Everest ransomware gang—a criminal group that uses ransomware, which is malware that encrypts data for ransom—claimed responsibility for the breach in a post on its dark web leak site. The group claimed the data was taken in November 2025. The incident became more widely known after Have I Been Pwned, a breach notification service, obtained the stolen data. The service subsequently notified 72 million individuals by email that their information had been compromised.

According to Have I Been Pwned, the stolen Under Armour dataset included names, email addresses, genders, dates of birth, and customers’ approximate location based on postcode or ZIP code. The compromised files also included information relating to purchases. A sample of the stolen data provided by the seller appeared to contain millions of records of Under Armour customer purchases, matching the types of data reported by the breach notification service. Additionally, the stolen dataset contains email addresses belonging to Under Armour employees.

In response to the claims, Under Armour spokesperson Matt Dornic stated that the company is aware of claims that an unauthorized third party obtained certain data. Dornic added that Under Armour’s investigation of the issue, with the assistance of external cybersecurity experts, is ongoing. He noted that at this time, there is no evidence to suggest the issue affected UA.com or systems used to process payments or store customer passwords.

According to Dornic, the number of affected customers with any sort of information that could be considered sensitive is a very small percentage. Dornic, speaking as the company’s spokesperson, asserted that “Any implication that sensitive personal information of tens of millions of customers has been compromised is unfounded.” However, the spokesperson did not provide an accurate figure of how many customers are affected by the breach, nor did he clarify what types of customer information Under Armour considers to be sensitive. Furthermore, the company has not stated whether it plans to notify the customers whose information was compromised, or if it has received any correspondence or ransom demands from the hackers.

Why it matters

This incident highlights the tension between third-party breach notifications and corporate damage control, as Under Armour pushes back against the reported scale of the compromise.