Skip to the report indexPrague Post
PRAGUE NEWS INDEX28 / 20 09 2026

English-language Prague and Czech political, civic and cultural news.

FIND / QUERY
Reader desk ↗
REPORT / 28Business

Under Armour probes breach after data tied to tens of millions of customers appears online

Under Armour says it is investigating after reports that customer data—primarily email addresses and other profile information—was exposed, underscoring how consumer brands remain frequent targets for large-scale credential and data theft.

Published
Updated
Under Armour probes breach after data tied to tens of millions of customers appears online

Under Armour is investigating a data breach that has been linked to customer information tied to a massive number of accounts. The company’s review follows outside reporting that a dataset connected to Under Armour customers surfaced, raising concerns for people who may have reused passwords across multiple services or rely on email as the primary account recovery method.

Under Armour probes breach after data tied to tens of millions of customers appears online
Related image

In a report published January 23, 2026, the Associated Press said Under Armour was looking into a breach believed to have exposed email addresses and other personal details for a large portion of its customer base. The report cited estimates that the number of impacted customers could be roughly 72 million, though the precise scope of affected records and the timeline of compromise are still being evaluated.

According to the reporting, the exposed data may include profile-level information such as names, gender, birth dates, and ZIP codes. Under Armour has indicated it has not found evidence that passwords or financial data were exposed, and said its main website and payment processing systems were not compromised. Still, even “non-financial” data can be useful for attackers, especially when combined with other leaked datasets.

The incident illustrates a recurring pattern in consumer cybersecurity: attackers often aim for large user databases that enable phishing, account takeovers elsewhere, and targeted scams. Email addresses—particularly when paired with any identifying details—can be used to craft convincing messages that imitate shipping notices, promotions, or password reset prompts.

Security researchers also noted that breaches can remain undisclosed for long periods, especially when the initial compromise is discovered outside the company. That lag can complicate mitigation because customers may not know they should be alert for new phishing attempts or unexpected login notifications.

For customers, the practical response is defensive hygiene: change passwords on any account that used the same or similar password, enable multi-factor authentication where possible, and treat unexpected “account security” emails or promotional offers with suspicion. Even if Under Armour passwords were not exposed, email-based targeting can still lead to broader harm if users are tricked into sharing credentials.

Under Armour’s ongoing investigation is expected to clarify how the data was obtained and whether additional categories of information were included. As with other major consumer breaches, attention will likely turn to the company’s notification posture, the completeness of its findings, and whether regulators or plaintiffs’ lawyers pursue follow-on inquiries.

SOURCE INDEX

Reporting record

  1. 01Associated PressAssociated Press