Company · Athletic apparel and footwear · Global retail brand · Global
Athletic apparel company.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
The Everest ransomware group targeted Under Armour in November 2025, claiming to have exfiltrated 343GB of data from the athletic apparel company. Using double extortion tactics, the group threatened to publish the stolen data unless a ransom was paid. When Under Armour did not meet the seven-day deadline, Everest released download links to the alleged data on dark web forums. The breach was subsequently confirmed to contain records for approximately 72.7 million customers. The exposed data includes email addresses, names, dates of birth, genders, geographic locations, and purchase histories. This combination is particularly valuable to cybercriminals because it goes beyond basic contact information. Purchase histories and profile data tied to a fitness brand can enable highly targeted phishing attacks and behavioral profiling, while email addresses paired with personal details increase the risk of account takeover through credential stuffing attacks on other platforms where victims reuse passwords. Multiple class-action lawsuits were filed in federal courts in Maryland and Texas, alleging negligence and failure to adequately protect customer data. As of early 2026, Under Armour had not publicly confirmed the full scope of the breach or detailed what steps were being taken to notify affected individuals. People whose data was exposed should treat any emails referencing Under Armour with caution, update passwords on Under Armour accounts and any other accounts sharing the same credentials, and monitor for suspicious account activity.
Full threat analysis, exploitation vectors, and principal guidance below.
11 additional sections · verified field analysis · defensive doctrine
72.7M records analyzed
Under Armour is an American athletic apparel, footwear, and accessories company headquartered in Baltimore, Maryland. Founded in 1996 by Kevin Plank, it sells performance gear globally under its core brand and subsidiaries. It is publicly traded on the NYSE and competes primarily with Nike and Adidas in the performance sportswear market.
Consumer fitness and retail brands collect account emails, usernames, and passwords, along with profile and activity data tied to brand ecosystems and digital services.
Under Armour has been executing a multi-year strategic reset under CEO Kevin Plank, who returned to lead the company in 2024. The company announced a restructuring plan in May 2024 valued at $140 million to $160 million, targeting distribution network consolidation, workforce reductions, and operational simplification. Revenue fell 9 percent to $5.2 billion in fiscal year 2025, and the company reported a net loss of $201 million for the year. Share buybacks of $90 million were completed by March 2025 as part of a three-year $500 million repurchase program. Restructuring charges continued into fiscal 2026.
In November 2025 the Everest ransomware group claimed responsibility for a breach, alleging theft of 343GB of data including customer records, employee information, and internal company files. Under Armour confirmed it was investigating the incident but did not formally verify the full scope of the compromise. When the seven-day ransom deadline passed without payment, Everest published download links to the alleged data on dark web forums. Have I Been Pwned subsequently confirmed 72 million email addresses in the leaked dataset alongside names, dates of birth, genders, geographic locations, and purchase histories. Multiple class-action lawsuits were filed in federal courts in Maryland and Texas, alleging negligence and failure to safeguard personal information. As of early 2026 Under Armour had not publicly confirmed the full scale of the breach or detailed its response to affected customers.
• Identity verification bypass using name + date of birth combination | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure
A consumer-service breach: contact and account data supports phishing, account takeover and profile enrichment. For a high-profile principal the main risk is credible impersonation and enrichment of existing exposure.
Motivation: Financial
An extortion operation active since at least 2020. Everest evolved from ransomware and data extortion toward initial access brokerage and leak-based extortion.
Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.
Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation