Skip to the report indexPrague Post
PRAGUE NEWS INDEX28 / 20 09 2026

English-language Prague and Czech political, civic and cultural news.

FIND / QUERY
Reader desk ↗
REPORT / 28Tech

Under Armour investigates data breach after reports suggest tens of millions of customer records exposed

Under Armour says it is investigating claims of a customer data breach involving email addresses and other personal details. The company states it has no evidence that payment systems or customer passwords were affected, while the cybersecurity community points to a dataset that could involve roughly 72 million email addresses.

Published
Updated
Under Armour investigates data breach after reports suggest tens of millions of customer records exposed

What Under Armour says happened—and what is still unclear

Under Armour is investigating a reported data breach that may have exposed customer email addresses and other personal information. The Baltimore-based company said it has not found evidence indicating that the incident affected its primary retail site or systems used to process payments or store customer passwords, pushing back against broader claims that highly sensitive data was taken.

Under Armour investigates data breach after reports suggest tens of millions of customer records exposed
Related image

According to information cited in reporting, the breach is believed to have occurred in late 2025 and could involve about 72 million email addresses. Some records may also include personal details such as names, genders, birthdates, and ZIP codes. Even without passwords or financial data, large-scale exposure of emails and demographic data can increase the risk of targeted phishing, account-takeover attempts on other services, and more convincing social engineering scams.

Why email-only (or email-plus) leaks can still be dangerous

A dataset containing verified email addresses can be valuable to criminals because it improves the success rate of malicious campaigns. When paired with profile details—like birthdates or location data—it becomes easier to craft messages that appear legitimate. Attackers often use these details to impersonate customer support, send fake password-reset messages, or build “lookalike” invoices that trick recipients into revealing credentials.

Consumers who suspect their email may be included in the leak often take similar defensive steps: enabling multi-factor authentication on key accounts, changing reused passwords on other sites, and being especially cautious about links or attachments claiming to be from retailers, shipping companies, or banks. Companies, for their part, typically have to sort out breach scope, validate what was accessed, and determine which notifications are required under state and international rules.

What to watch next

The main unresolved questions are how the data was obtained, whether additional fields beyond those described are present, and whether the data is actively being used in fraud campaigns. Under Armour’s investigation is expected to clarify impact, timing, and any steps customers should take. In the meantime, the incident is another reminder that even when payment data is not compromised, large consumer datasets can still be weaponized.

SOURCE INDEX

Reporting record

  1. 01The Associated PressThe Associated Press