Under Armour investigates massive breach reportedly exposing tens of millions of customer email addresses
Under Armour says it is investigating a breach that may have exposed customer email addresses and other personal data, while reporting indicates passwords and financial details were not included.

Under Armour is investigating a data breach that reportedly exposed the email addresses of a vast number of customers, along with other personal profile information. The company said it is looking into what happened and emphasized that it has not found evidence indicating that passwords or financial information were compromised.

The incident drew wider attention after a cybersecurity tracking service highlighted the scale of the dataset. Reporting indicates that the leaked information may include additional profile fields such as names and demographic details, though not the most sensitive categories typically associated with direct account takeover or payment fraud.
Even when passwords and card numbers are not part of a breach, large collections of verified email addresses can still carry serious downstream risk. Attackers can use them for targeted phishing, credential-stuffing attempts against other services, and social-engineering campaigns that impersonate brands and customer support.
For consumers, the most immediate concern is an increase in convincing scam messages. Criminals often tailor emails to match a brand’s tone, shipping language, or membership benefits, hoping to trick recipients into clicking malicious links or providing additional information. These campaigns can intensify after a breach becomes public because attention itself generates opportunity.
For the company, the breach raises questions about detection speed, disclosure timing, and the practical steps taken to limit harm. Large brands face a difficult tradeoff between confirming details before speaking publicly and warning users early enough to reduce exposure. Cybersecurity researchers noted that the apparent scale also increases the odds that the data will be replicated and redistributed.
The episode is part of a broader trend in which consumer-facing companies confront continual pressure from cybercriminals seeking large user databases. Even partial datasets—especially those with accurate contact information—can power a long tail of fraud attempts that persist for months.
Users concerned about exposure can take practical steps such as changing passwords on any accounts where they reused credentials, enabling multifactor authentication where available, and being cautious with email links and account reset prompts. Under Armour’s investigation will determine what additional notifications or remediation measures may follow.