Under Armour Data Breach (2025): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Under Armour disclosed a data breach on November 17, 2025, exposing the names, email addresses, dates of birth, genders, and geographic locations of 72.7 million individuals. Users should check their accounts and monitor for suspicious activity.
Breaking down the breach
The incident first surfaced publicly on 17 November 2025 when Everest posted Under Armour on its leak site and demanded payment. The group asserted it held 343 GB of material. In January 2026 portions of that material, containing 72.7 million records, were posted on a separate hacking forum. The published sample included email addresses for approximately 72 million entries along with additional fields in many records.
No official statement from Under Armour has disclosed the date or vector of initial compromise, the precise scope of systems accessed, or whether the full 343 GB claim was accurate. The only confirmed public record remains the forum posting of the 72.7 million records.
The group behind it: everest
Everest is a ransomware operation that maintains a leak site to pressure victims and that has previously published data from organisations that refused payment. Its standard pattern involves initial network access, data exfiltration, encryption of systems, and a ransom demand followed, in some cases, by public disclosure when negotiations fail. The group’s listing of Under Armour followed this established sequence, though the company’s response to the demand remains undisclosed.
Under Armour and its sector
Under Armour is a global sportswear and footwear company that maintains large volumes of direct-to-consumer customer accounts. Retailers of this type routinely store names, contact details, dates of birth, purchase histories and location data to support online sales, loyalty programmes and shipping. A breach at such a firm therefore involves the kinds of records that can be aggregated for marketing or identity-related misuse.
The information in question
The records released on the forum contained email addresses, names, dates of birth, genders, geographic locations and purchase information. The exact number of records that included each additional field has not been published, nor has any confirmation been given that other categories of data were absent from the full set. Organisations in this sector commonly hold further details such as passwords, payment card tokens or account credentials, but those elements are not named in the available reporting.
The real-world impact
Exposed email addresses combined with names and dates of birth can be used for targeted phishing or to populate larger datasets sold on underground markets. Purchase histories may reveal spending patterns or product preferences that could be leveraged for social-engineering attempts. For Under Armour the incident adds to the operational costs of incident response, potential regulatory scrutiny and the need to restore customer trust. No evidence of immediate large-scale fraud campaigns linked to this specific dataset has been reported publicly.
Were you affected?
Individuals can check whether their email address appears in known breach datasets by using a free exposure-scanning service that queries public breach repositories. If an address is found, standard precautions include changing passwords on the affected account and any reused elsewhere, enabling multi-factor authentication, and monitoring financial and email accounts for unusual activity. Under Armour has not yet issued a formal notification process, so users should also watch for any direct communications from the company.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
FullBeauty Brands Listed by everest Ransomware GroupAupaircare and Intraxinc Listed by everest Ransomware GroupCrumbl Listed by everest Ransomware GroupCrumbl - Full leak published Listed by everest Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Under Armour Data Breach (2025) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.