Skip to departures
NAIROBI NETWORK NEWSROUTE 24
Nairobi Express

Fast. Useful.
Close to home.

Tech / REPORT 24

Under Armour investigates massive customer-data breach affecting email addresses

Under Armour is investigating a data breach that may involve about 72 million customer email addresses, according to information cited by the cybersecurity site Have I Been Pwned. The company said it has no evidence that passwords or payment systems were compromised, though additional personal details may have been exposed in some records.

Under Armour investigates massive customer-data breach affecting email addresses

Under Armour said it is investigating a recent data breach that appears to involve customer email addresses and other personal information, a case that illustrates how consumer brands can become high-volume targets even when financial systems are not directly compromised.

Under Armour investigates massive customer-data breach affecting email addresses
Related image

The breach is believed to have occurred in late 2025, and information cited by the cybersecurity service Have I Been Pwned suggests roughly 72 million email addresses were affected. Some records referenced in reporting also included names, genders, birthdates and ZIP codes, expanding the potential usefulness of the data for phishing and identity-related scams.

Under Armour said it has no evidence the incident affected UA.com or systems used to process payments or store customer passwords, and it pushed back against suggestions that passwords or financial information were taken. That distinction matters: even without payment data, exposed contact details at this scale can increase fraud attempts against customers.

Have I Been Pwned founder Troy Hunt said he agreed with the company’s assessment based on the information that has surfaced so far, but he also expressed surprise that an official disclosure had not already been issued given the apparent size of the exposure and the time since the incident.

For consumers, the practical risk is not only the leaked data itself but the downstream ecosystem of impersonation attempts, credential-stuffing campaigns using unrelated stolen passwords, and targeted social engineering that can follow when criminals can match emails with other personal attributes.

For companies, the episode highlights the reputational cost of uncertainty in the early stages of a breach and the pressure to communicate clearly while investigations are still incomplete. Even when a firm believes payment information is safe, the volume of affected users can drive immediate scrutiny from customers, regulators and security researchers.

ORIGIN CHECK

Sources for this report

  1. 01Associated PressAssociated Press