Skip to the report indexPrague Post
PRAGUE NEWS INDEX28 / 20 09 2026

English-language Prague and Czech political, civic and cultural news.

FIND / QUERY
Reader desk ↗
REPORT / 28Tech

Under Armour investigates breach tied to customer emails as cybersecurity questions mount

Under Armour says it is investigating claims of a breach affecting customer email addresses and related profile details, while stating there is no evidence passwords or payment systems were compromised. The incident highlights continuing risks for consumer-facing brands managing large user databases.

Published
Updated
Under Armour investigates breach tied to customer emails as cybersecurity questions mount

Under Armour is investigating a reported data breach that exposed customer email addresses and other profile information, a reminder that consumer brands remain frequent targets even when payment systems and passwords are not believed to be affected. The Baltimore-based apparel company said it is looking into the incident after external reporting drew attention to a large dataset allegedly tied to its customers.

Under Armour investigates breach tied to customer emails as cybersecurity questions mount
Related image

The breach is believed to have occurred in late 2025 and to involve tens of millions of customer records. The cybersecurity site “Have I Been Pwned” cited information indicating that approximately 72 million email addresses were affected, and that some records included additional personal details such as names, genders, birthdates, and ZIP codes.

Under Armour said it has no evidence that its main website (UA.com) or the systems used to process payments were impacted, and it also said there is no sign that customer passwords were compromised. In other words, the company is presenting the incident as a leak of contact and profile data rather than a direct compromise of transactional systems.

Troy Hunt, the creator of “Have I Been Pwned,” said he agreed with the company’s view based on what has surfaced so far, but he also noted surprise that a public disclosure had not been made sooner given the scale of the reported exposure. He pointed out that large organizations typically publish breach notices quickly when a significant number of customers may be affected.

Even when financial data is not involved, email-centric exposures can still create downstream risk. Attackers frequently use email lists and basic profile details to craft convincing phishing messages, attempt account takeovers on other platforms, or target individuals with personalized scams that exploit familiar brand names.

For consumers, the practical takeaway is to treat unexpected Under Armour-themed messages with caution, avoid clicking unknown links, and use unique passwords plus multi-factor authentication across services. For companies, the episode underscores that brand trust is a cybersecurity asset—and that communication strategy after an incident can be nearly as important as technical containment.

SOURCE INDEX

Reporting record

  1. 01The Associated PressThe Associated Press