Skip to departures
NAIROBI NETWORK NEWSROUTE 24
Nairobi Express

Fast. Useful.
Close to home.

Business / REPORT 24

Under Armour investigates breach claims after report says tens of millions of emails were exposed

Under Armour says it is looking into claims that customer data was accessed without authorization, after outside reporting alleged tens of millions of email addresses and other profile details were exposed. The company said it has not found evidence that passwords or payment systems were compromised, but the episode highlights the growing scale of consumer data theft.

Under Armour investigates breach claims after report says tens of millions of emails were exposed

Under Armour is investigating a suspected data breach after reports said a large trove of customer information was accessed and circulated. The company acknowledged that it is reviewing the incident and working with cybersecurity specialists, as attention intensified around claims that a very large number of customer email addresses may have been exposed.

Under Armour investigates breach claims after report says tens of millions of emails were exposed
Related image

According to reporting that brought the issue into the open, the leaked data set may involve roughly 72 million email addresses, with other profile information also potentially included. Outside researchers said the incident appears to date back to late 2025, although the precise timeline and how the data was taken remain unclear based on public information so far.

Under Armour said it has not seen evidence that passwords or financial information were compromised, and it emphasized that its main website and payment processing systems were not believed to be affected. Still, security experts warn that exposed emails and personal profile fields can be valuable for criminals, who may use them for phishing, account takeover attempts on other services, and targeted scams that leverage brand familiarity.

The alleged scale of the breach also raises questions about disclosure timing and consumer notification, since major incidents can trigger legal duties depending on what data was involved and which jurisdictions are impacted. Even when payment details are not taken, companies can face reputational damage if customers feel the response was slow or if communications are vague.

Cybersecurity analysts note that stolen customer lists are often combined with other breached data and then used to automate large-scale attacks, especially during shopping seasons and product launches. That means companies sometimes see downstream fraud and brand spoofing even when their own core systems remain intact.

Under Armour’s investigation is ongoing, and the company has not confirmed all claims circulating online. Customers are typically advised in these situations to watch for suspicious emails, avoid clicking unexpected links, and consider changing passwords on any accounts that reuse credentials, while monitoring for updates from the company as more facts are verified.

ORIGIN CHECK

Sources for this report

  1. 01Associated PressAssociated Press