Under Armour investigates massive customer data breach exposing email addresses for about 72 million accounts
Under Armour says it is investigating reports that hackers obtained customer email addresses and other profile data, potentially affecting about 72 million records. The company says it has no evidence passwords or payment systems were compromised, but security experts say the scale highlights the ongoing risks of data reuse and phishing.
- BYLINE
- Lagos Tribune News Desk
- PUBLISHED
- UPDATED

BALTIMORE — Under Armour is investigating a large data breach that reportedly exposed customer email addresses and other personal information tied to tens of millions of accounts, the athletic apparel company said.

The breach is believed to have occurred late last year and may have affected roughly 72 million email addresses, according to information referenced by the cybersecurity website Have I Been Pwned. The stolen records may also include profile details such as names, genders, birthdates and ZIP codes.
Under Armour said it has not found evidence that the incident compromised payment systems, customer passwords or the infrastructure used to process transactions. In a statement, the company pushed back on claims that highly sensitive information had been taken, while acknowledging it is continuing to investigate what happened and how widely the data spread.
Security researchers note that even when financial data is not stolen, large troves of email addresses and profile details can fuel follow-on attacks. Criminals can use exposed data to craft targeted phishing messages, attempt credential-stuffing on other services, or build more convincing social-engineering campaigns.
The episode also illustrates a common gap between discovery and disclosure in the breach economy. Under Armour’s case drew attention because reports suggest the data may have been circulating for some time, raising questions about when companies should notify customers and what level of certainty is required before going public.
Have I Been Pwned founder Troy Hunt said the data exposed appears consistent with what has been reported so far, and he expressed surprise that there had not been a more prominent public disclosure given the size of the incident. Under Armour, however, stressed that it is still assessing the situation and that its main commerce systems remain unaffected.
For consumers, incidents like this often matter most in what comes next. Even without passwords, an exposed email address can become a long-lived identifier that attackers reuse to target victims repeatedly, particularly during major news events when people expect messages about accounts or “security updates.”
Under Armour said it will continue reviewing the incident as it works to understand the breach and reduce the risk of further misuse. Cybersecurity specialists recommend customers remain vigilant for suspicious emails, avoid clicking unknown links, and use unique passwords and multi-factor authentication where possible to limit the impact of data reuse.