Skip to main news
Warsaw Daily
WARSZAWA
16.09.2026
THE CAPITAL, CLEARLY REPORTED
REPORT
WAW
25.01
Business / CITY DESK

Under Armour investigates breach after data tied to millions of customers appears online

Under Armour says it is investigating a data breach after a large dataset tied to customers circulated online. Reports indicate the exposed information includes email addresses and other personal details, though the company says there’s no evidence passwords or payment data were compromised — a disclosure that underscores the growing risk of consumer-data leaks for major brands.

PUBLISHED
UPDATED
Under Armour investigates breach after data tied to millions of customers appears online

What Under Armour says was exposed

Under Armour is investigating a data breach after reports indicated a dataset tied to its customers was circulating online. The company said it has not found evidence that passwords or financial information were taken, but it acknowledged concerns about customer information and is working to understand what happened and what systems were involved.

Under Armour investigates breach after data tied to millions of customers appears online
Related image

Independent reporting and breach-tracking disclosures have suggested that the dataset includes customer email addresses and other profile details. Even when payment data is not involved, email exposure at scale can create significant downstream risk, including targeted phishing campaigns, credential-stuffing attempts on unrelated services, and impersonation scams tailored to a brand’s customer base.

Why email-only breaches still matter

Large consumer brands often see email addresses as relatively low-sensitivity data compared with financial credentials, but attackers can combine email lists with other leaked databases to build accurate identity profiles. That can make fraud attempts more convincing, especially if messages reference real purchase histories, shipping addresses, or loyalty-program details obtained elsewhere.

For customers, the near-term impact is often a spike in suspicious messages that appear to come from the affected company, shipping carriers, or payment services. For businesses, the longer-term costs can include customer-support surges, brand trust erosion, and expensive incident-response work, even when the breach did not reach payment systems.

What customers should watch for next

Customers should expect possible official notifications if the investigation confirms exposure and triggers legal reporting requirements. In the meantime, consumers can reduce risk by treating Under Armour-themed emails and texts with skepticism, avoiding links in unsolicited messages, and using unique passwords plus multi-factor authentication on accounts that share the same email address.

As the investigation continues, the key open questions include when the data was accessed, whether any internal systems were compromised, and whether the breach involved a third-party vendor. Those details will determine whether the incident is best understood as a one-off data leak or part of a broader supply-chain security problem affecting consumer brands.

SOURCE BLOCK

Reporting record

  1. 01The Associated PressThe Associated Press