Under Armour investigates breach after data for tens of millions of customers appears exposed, with emails among the leaked details
Under Armour says it is investigating a data breach after reports indicated information tied to about 72 million customers was exposed, renewing concerns about credential reuse, targeted phishing, and delayed disclosure after large incidents.
- BYLINE
- Lagos Tribune News Desk
- PUBLISHED
- UPDATED

What Under Armour says happened
Under Armour is investigating a reported data breach after outside reporting indicated that information connected to roughly 72 million customers was exposed. The company has said it has not found evidence that passwords or financial information were accessed, but reports suggest customer email addresses—and possibly other profile details—were included in the compromised data.

The incident has drawn attention in part because the breach is believed to have occurred in late 2025, yet became widely discussed after it was flagged by the breach-tracking service Have I Been Pwned. Security researchers often note that even when payment data is not affected, email exposure at scale can enable follow-on attacks.
Why exposed emails matter
Email lists tied to recognizable brands can be used to craft convincing phishing campaigns, password-reset scams, and fake customer-support outreach. Attackers may also combine brand-linked email data with other leaks to build detailed identity profiles, increasing the success rate of social engineering.
For customers, the immediate technical risk often depends on whether passwords were leaked and whether they reused those passwords elsewhere. Even when a company says passwords were not accessed, caution is warranted: phishing attempts can exploit the public narrative of a breach to push users toward malicious links.
What customers can do next
- Be wary of breach-related emails asking you to “confirm” account details or reset passwords via embedded links; navigate directly to the company site instead.
- Enable multi-factor authentication where available and review account recovery settings.
- Use unique passwords (or a password manager) to reduce the impact if any credential set is later found compromised.
- Monitor inbox rules and unexpected forwarding settings, which attackers sometimes change after taking over an email account.
Under Armour’s investigation will likely focus on how the intrusion occurred, which systems were affected, and whether more sensitive data was accessed than initial reporting suggests. The case also highlights an ongoing problem in consumer tech: even partial personal-data exposure can create a long tail of fraud attempts months after the original incident.