LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Under Armour Data Breach (2025)

CRITICAL severityConfirmedHow we verify

Under Armour Data Breach (2025): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·November 17, 2025

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Under Armour Data Breach (2025)

Reported November 17, 2025. Approximately 72.7M people affected.

CRITICAL
Severity
72.7M
People affected
6
Data types exposed
November 17, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Under Armour disclosed a data breach on November 17, 2025, exposing the names, email addresses, dates of birth, genders, and geographic locations of 72.7 million individuals. Users should check their accounts and monitor for suspicious activity.

Severity & verification
CRITICAL severityConfirmed
Contact / identity PII exposed.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
72.7M accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In November 2025 the Everest ransomware group listed Under Armour as a claimed victim and stated it had obtained access to 343 GB of data. Customer records from the incident later appeared on a public hacking forum in January 2026, exposing information tied to 72.7 million individuals. The listing and subsequent publication constitute the only confirmed public details available at this stage. No independent verification of the initial access method or the full volume of material has been released by Under Armour or by investigators.

Breaking down the breach

The incident first surfaced publicly on 17 November 2025 when Everest posted Under Armour on its leak site and demanded payment. The group asserted it held 343 GB of material. In January 2026 portions of that material, containing 72.7 million records, were posted on a separate hacking forum. The published sample included email addresses for approximately 72 million entries along with additional fields in many records.

No official statement from Under Armour has disclosed the date or vector of initial compromise, the precise scope of systems accessed, or whether the full 343 GB claim was accurate. The only confirmed public record remains the forum posting of the 72.7 million records.

The group behind it: everest

Everest is a ransomware operation that maintains a leak site to pressure victims and that has previously published data from organisations that refused payment. Its standard pattern involves initial network access, data exfiltration, encryption of systems, and a ransom demand followed, in some cases, by public disclosure when negotiations fail. The group’s listing of Under Armour followed this established sequence, though the company’s response to the demand remains undisclosed.

Under Armour and its sector

Under Armour is a global sportswear and footwear company that maintains large volumes of direct-to-consumer customer accounts. Retailers of this type routinely store names, contact details, dates of birth, purchase histories and location data to support online sales, loyalty programmes and shipping. A breach at such a firm therefore involves the kinds of records that can be aggregated for marketing or identity-related misuse.

The information in question

The records released on the forum contained email addresses, names, dates of birth, genders, geographic locations and purchase information. The exact number of records that included each additional field has not been published, nor has any confirmation been given that other categories of data were absent from the full set. Organisations in this sector commonly hold further details such as passwords, payment card tokens or account credentials, but those elements are not named in the available reporting.

The real-world impact

Exposed email addresses combined with names and dates of birth can be used for targeted phishing or to populate larger datasets sold on underground markets. Purchase histories may reveal spending patterns or product preferences that could be leveraged for social-engineering attempts. For Under Armour the incident adds to the operational costs of incident response, potential regulatory scrutiny and the need to restore customer trust. No evidence of immediate large-scale fraud campaigns linked to this specific dataset has been reported publicly.

Were you affected?

Individuals can check whether their email address appears in known breach datasets by using a free exposure-scanning service that queries public breach repositories. If an address is found, standard precautions include changing passwords on the affected account and any reused elsewhere, enabling multi-factor authentication, and monitoring financial and email accounts for unusual activity. Under Armour has not yet issued a formal notification process, so users should also watch for any direct communications from the company.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyUnder Armour security record
58/100
DoxxScan™ · Elevated doxx risk
F 33Severe breach history

1 reported incident on record.

See Under Armour’s full breach history →

More recent breaches

FullBeauty Brands Listed by everest Ransomware GroupNovember 13, 2025Aupaircare and Intraxinc Listed by everest Ransomware GroupAugust 29, 2025Crumbl Listed by everest Ransomware GroupJuly 23, 2025Crumbl - Full leak published Listed by everest Ransomware GroupJuly 23, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Under Armour Data Breach (2025) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram