Nike probes alleged 1.4TB data theft as extortion group claims leak of design and manufacturing files
Nike is investigating claims that an extortion group stole roughly 1.4 terabytes of internal data and published samples online. The alleged cache appears to involve product design and manufacturing workflows rather than consumer databases, raising concerns about intellectual property exposure, counterfeit risk, and supply chain disruption. The incident reflects a broader shift in cybercrime toward steal-and-leak extortion tactics.
- Published
- Updated

Nike is investigating a potential cybersecurity incident after an extortion group claimed it stole roughly 1.4 terabytes of internal company data and posted samples publicly. According to reporting, the group alleges it obtained a large set of files connected to Nike’s internal operations, and the company has said it is looking into the matter while not confirming the attackers’ claims.

The alleged leak appears to be centered on product and operational materials rather than customer databases. Filenames and folder structures described in coverage point to design, manufacturing and workflow documentation, suggesting the intrusion may have targeted the intellectual property and operational details that underpin Nike’s product pipeline.
That distinction matters because modern extortion campaigns increasingly aim to create leverage without necessarily encrypting systems. Instead, attackers focus on stealing sensitive corporate data and pressuring the victim to pay by threatening publication. For consumer brands, the damage can extend well beyond immediate IT disruption: leaked designs and production documentation can accelerate counterfeiting, reveal sourcing relationships, and expose negotiation leverage with suppliers.
If the data is authentic, risks could include competitive exposure of upcoming product roadmaps, internal costing information, or factory audits and compliance details. Even when personal data is not involved, the reputational and strategic harm of losing control over internal documents can be significant, particularly for a brand where product timing and design secrecy are part of the competitive advantage.
Nike has not publicly validated the stolen-data claims, and investigations typically take time to determine what was accessed, whether systems were laterally traversed, and what controls failed. Still, the episode fits a broader pattern: attackers are increasingly monetizing corporate data itself, turning operational information into a bargaining chip. For companies, that trend raises the bar on access controls, data classification, and monitoring for large-scale exfiltration.