AP: Under Armour investigates breach reportedly affecting tens of millions as consumers face continuing data exposure risks
Under Armour is looking into a breach that reportedly exposed customer email addresses and other personal details, underscoring how frequently large consumer datasets remain vulnerable even when financial systems aren’t hit.
- Published
- Updated

Under Armour is investigating a data breach that reportedly exposed the email addresses and personal information of a large number of customers, according to an Associated Press report published January 23, 2026. The incident highlights the ongoing scale of consumer-data exposure across major brands, even when payment systems and passwords are not believed to be involved.

The AP report said the breach may involve around 72 million customers and could include details such as names, genders, birthdates, and ZIP codes. Under Armour stated there is no evidence that passwords or financial information were compromised, and said its main website and payment processing systems were not affected.
The breach was surfaced publicly through “Have I Been Pwned,” a well-known service that aggregates compromised datasets. Its founder, Troy Hunt, said the exposed fields appear to include personal attributes alongside email addresses, and he expressed surprise that there had not been an earlier public disclosure given the apparent size and timing of the incident.
Even when payment data is not stolen, mass exposure of email addresses and identity details can be consequential. Cybersecurity experts warn that criminals use such datasets for targeted phishing, account takeover attempts through password reuse, and social engineering campaigns that impersonate legitimate brands.
For consumers, the practical risk is that attackers can combine breached email addresses with other sources to build more convincing lures, often timed around real-world events like tax season, shipping notifications, or password-reset prompts. That makes rapid communication and clear remediation steps from companies essential in the aftermath of an incident.
Under Armour’s investigation is expected to focus on how the data was accessed, which systems were involved, and what steps are needed to prevent recurrence. In the meantime, consumers affected by large breaches are generally advised to treat brand-related emails with caution and to enable multi-factor authentication where possible.