Skip to departures
NAIROBI NETWORK NEWSROUTE 24
Nairobi Express

Fast. Useful.
Close to home.

Business / REPORT 24

Under Armour investigates breach tied to roughly 72 million customer email addresses

Under Armour says it is investigating claims of a data breach involving customer email addresses and other personal details, while stressing there is no evidence that passwords or payment systems were compromised. A cybersecurity site flagged the dataset, raising questions about disclosure and consumer notification.

Under Armour investigates breach tied to roughly 72 million customer email addresses

What Under Armour says happened

Under Armour is investigating a data breach that reportedly exposed customer email addresses and additional personal information, a development that could affect a large portion of its consumer base. The Baltimore-based athletic apparel company said it has not seen evidence that the incident affected its main e-commerce site or systems used to process payments or store customer passwords, pushing back on claims that highly sensitive account or financial data was taken.

Under Armour investigates breach tied to roughly 72 million customer email addresses
Related image

The breach is believed to have occurred in late 2025 and is said to involve about 72 million email addresses, according to information cited by the cybersecurity website “Have I Been Pwned.” Reports indicate some of the records also contained names and demographic details such as gender, birthdates and ZIP codes, which—while not always sufficient for direct account takeover—can increase the risk of targeted phishing and identity-related scams.

Why this matters even if passwords weren’t taken

Even when passwords and credit card numbers are not exposed, large collections of real customer emails can be valuable to criminals. Lists can be used to craft convincing messages that imitate brands, trigger “account security” panic, or push malicious links that steal credentials elsewhere. In addition, personal details like birth dates and ZIP codes can help attackers personalize scams or attempt verification with third parties.

Have I Been Pwned founder Troy Hunt said that, based on the data observed so far, he agrees with Under Armour’s assertion that passwords and financial information do not appear to be included. He also noted surprise at the apparent lack of an earlier official disclosure given the size and age of the incident, while acknowledging the company is a victim of criminal activity and may have been managing the situation internally.

What customers can do now

  • Be cautious of emails or texts claiming there is a problem with your Under Armour account, especially messages urging urgent action.
  • Avoid clicking links in unexpected messages; instead, navigate directly to the company site via your browser or official app.
  • Use unique passwords across sites and enable multi-factor authentication where available.
  • Watch for phishing attempts that reference real details (ZIP code, birth date) to seem legitimate.

Under Armour said it is continuing to review the claims and emphasized that payment systems were not impacted, but consumers should still expect an uptick in brand-impersonation scams when a breach is widely publicized.

ORIGIN CHECK

Sources for this report

  1. 01Associated PressAssociated Press