Skip to main news
Warsaw Daily
WARSZAWA
16.09.2026
THE CAPITAL, CLEARLY REPORTED
REPORT
WAW
26.01
Tech / CITY DESK

Under Armour investigates reported breach tied to tens of millions of customer records, including emails

Under Armour says it is investigating a reported data breach that may involve about 72 million customer email addresses and other basic personal details. The company says there is no indication that passwords or payment systems were compromised, as the incident highlights how major consumer brands are increasingly targeted for large-scale data theft.

PUBLISHED
UPDATED
Under Armour investigates reported breach tied to tens of millions of customer records, including emails

What’s alleged to have been exposed

Under Armour is investigating a reported incident in which hackers may have obtained customer email addresses and other personal information linked to roughly 72 million records. Reports indicate some of the stolen data could include names, gender markers, dates of birth and ZIP codes—information that, while not necessarily giving direct access to accounts, can still fuel phishing attempts, identity fraud and targeted scams.

Under Armour investigates reported breach tied to tens of millions of customer records, including emails
Related image

The cybersecurity site Have I Been Pwned flagged the dataset, and its operator said the data appears consistent with a customer breach, drawing attention to the scale of what may have been taken. Under Armour acknowledged it is looking into the matter and emphasized that it has not found evidence that passwords were stolen or that payment processing systems and the company’s main e-commerce site were compromised.

Why email-only breaches still matter

Even when financial information and passwords are not exposed, large collections of verified email addresses can be highly valuable to criminals. Attackers can use them to send convincing phishing messages that mimic shipping notices, warranty claims, account resets or “security alerts,” and they can pair the emails with other personal details to increase credibility.

Security experts generally advise customers to treat any breach involving personal data as a prompt to tighten account defenses. That includes enabling multi-factor authentication where possible, watching for unexpected password-reset emails, and being skeptical of urgent messages that pressure recipients into clicking links or sharing codes.

Company response and what comes next

Under Armour said it is investigating and characterized the claims of highly sensitive exposure as unfounded based on what it has seen so far. The company’s next steps are likely to include confirming the dataset’s origin, determining how the data was accessed, and coordinating with law enforcement and regulators if required.

Practical steps for customers

  • Be wary of Under Armour-themed emails asking you to “verify” your account or payment details.
  • Use unique passwords for shopping and fitness accounts; consider a password manager.
  • Enable multi-factor authentication on email accounts, since email is often the gateway to resets elsewhere.
  • Monitor for suspicious login attempts, password-reset messages and unusual marketing emails.

As brands accumulate more user profiles across apps, loyalty programs and e-commerce, incidents like this underscore how protecting even basic customer data has become a core cybersecurity challenge.

SOURCE BLOCK

Reporting record

  1. 01Associated PressAssociated Press