Under Armour probes massive breach after reports that customer email addresses were exposed
Under Armour says it is investigating a data breach after reports indicated customer account information, including email addresses, may have been exposed at large scale. The company said there is no evidence that passwords or payment systems were compromised, but the incident highlights how leaked identity data can still fuel phishing and account-takeover attempts.
- Published
- Updated

What Under Armour says happened
Under Armour is investigating a data breach after external reporting indicated the information of a large number of customers was exposed. The company said it has not found evidence that passwords or financial information were compromised, and it emphasized that its main website and payment processing systems were not affected. Still, even limited exposure—especially email addresses paired with names or other profile details—can create meaningful downstream risk for consumers.

The breach reportedly involved customer information such as email addresses and other personal details like names and demographic or location fields. Under Armour has described the incident as criminal activity directed at the company, and it is working to assess the scope and implications. Incidents like this can take time to fully map because investigators must determine what systems were accessed, how long access persisted, and whether exfiltrated data has been altered or combined with other datasets.
Why email exposure still matters
Even when passwords and credit cards are not involved, exposed email addresses can be weaponized for phishing campaigns, targeted spam, and social engineering. Attackers often use breached datasets to craft messages that look legitimate—account alerts, password reset prompts, delivery notifications—designed to trick recipients into giving up credentials on look-alike sites.
If an exposed email address is reused as a login across multiple services, the risk can compound: a single breach can help attackers identify likely targets and then test leaked passwords from older breaches elsewhere. That is why security experts typically advise consumers to enable multi-factor authentication and avoid reusing passwords, even when a company says passwords were not exposed in a particular incident.
Practical steps for customers
- Be skeptical of unexpected Under Armour emails—especially urgent “verify account” or “reset password” prompts.
- Use a password manager and ensure your Under Armour password is unique (not reused elsewhere).
- Turn on multi-factor authentication wherever it is available on key accounts (email first, then retail/finance).
- Watch for a spike in targeted spam or account-reset attempts; consider filtering rules and stronger recovery settings.
For many consumers, the most immediate threat is phishing rather than direct financial theft. The safest approach is to assume exposed contact data will be used to try to trick you later—and to harden your email and authentication settings now, before those attempts begin.