Under Armour data breach (2025)
In November 2025, the Everest ransomware group claimed to have stolen 343GB of data from apparel maker Under Armour. After no ransom was paid, customer data was leaked in January 2026, exposing roughly 72.7 million unique email addresses with names, dates of birth, genders, locations and purchase histories. This is a separate incident from the 2018 MyFitnessPal breach.
- Victim
- Under Armour
- records
- 72.7M
- users
- 72.7M
In November 2025, the Everest ransomware group claimed to have stolen 343GB of data from the American apparel maker Under Armour. When no ransom was paid, the attackers leaked the stolen customer data in January 2026, exposing roughly 72.7 million unique email addresses. This is a separate incident from Under Armour's well-known 2018 MyFitnessPal breach, which affected about 150 million accounts.
What happened
On 16 November 2025, the Everest ransomware-and-extortion group added Under Armour to its dark-web leak site, claiming to hold 343GB of company data and giving Under Armour roughly seven days to make contact via encrypted messaging. Under Armour did not pay the demanded ransom, and the deadline passed without a published deal.
Roughly two months later, on 18 January 2026, Everest followed through and dumped the stolen dataset on a popular hacking forum. Shortly afterward, Have I Been Pwned ingested and verified the data. Everest is a long-running extortion group that increasingly operates as a data-theft-and-leak crew rather than relying solely on file encryption.
Data exposed
The leaked customer data, as assessed by Have I Been Pwned and reporting outlets, included:
- Names
- Email addresses (~72.7 million unique)
- Dates of birth
- Genders
- Geographic locations
- Purchase histories โ product IDs, prices, quantities, store preferences and marketing-campaign data
Have I Been Pwned recorded the dataset at 72,742,892 records. The full dump reportedly contained on the order of 191 million total rows, with the ~72.7 million figure representing distinct email addresses. Under Armour stated it found no evidence that passwords or payment systems were affected.
Response
Under Armour declined to pay the ransom and characterized the incident cautiously in public statements, emphasizing that account credentials and payment data did not appear to be involved. Following the January 2026 leak, the company was hit with a class-action lawsuit alleging it failed to meet minimum cybersecurity standards and that the breach was preventable.
Why it matters
This breach is notable for two reasons. First, scope and attribution clarity: unlike Under Armour's 2018 MyFitnessPal incident, this is a 2025 ransomware/extortion event tied to a named group (Everest) that monetized stolen data through public leaking after the company refused to pay. Second, it underscores the modern extortion playbook โ encryption is optional, but exfiltration and the threat of a public dump are the real leverage. For the tens of millions of customers exposed, the dominant risks are targeted phishing and identity-profiling built from names, dates of birth and detailed purchase histories, even though passwords and payment data were reportedly untouched.
Timeline
The Everest ransomware group lists Under Armour on its leak site, claiming 343GB of stolen data and demanding contact within seven days.
The breach is dated to mid-November 2025; reporting on Everest's extortion attempt emerges.
Under Armour does not pay the demanded ransom; the seven-day deadline lapses.
Everest publishes the stolen customer dataset on a popular hacking forum.
Have I Been Pwned loads the dataset; ~72.7 million unique email addresses are confirmed, and a class action is filed against Under Armour.
Sources
- haveibeenpwned.comhttps://haveibeenpwned.com/Breach/UnderArmour
- malwarebytes.comhttps://www.malwarebytes.com/blog/news/2026/01/under-armour-ransomware-breach-data-of-72-million-customers-appears-on-the-dark-web
- bankinfosecurity.comhttps://www.bankinfosecurity.com/ransomware-hackers-leak-under-armour-customer-data-a-30589
- cpomagazine.comhttps://www.cpomagazine.com/cyber-security/over-72-million-people-exposed-in-data-breach-at-apparel-giant-under-armour/
- brightdefense.comhttps://www.brightdefense.com/news/under-armour-data-breach/