Under Armour says it is investigating a reported data breach that may have exposed customer email addresses and other personal details at very large scale, after external reporting and security community discussions drew attention to the incident.

The company acknowledged it is looking into the claims and emphasized that it has not found evidence that its main shopping site or the systems used for processing payments and storing customer passwords were compromised. That distinction matters because the consequences for consumers differ sharply between an email-only exposure and a breach involving credentials or financial data.
Information circulated by the breach-tracking community suggested the incident affected roughly 72 million email addresses and may have included other profile fields such as names, gender, birthdates, and ZIP codes. Even in the absence of passwords, this type of dataset can increase risks of targeted phishing, account takeover attempts on unrelated services, and identity-based social engineering.
Cybersecurity observers noted that large organizations typically face pressure to communicate clearly and quickly when incidents appear to affect broad segments of their customer base. At the same time, companies often balance disclosure with the need to validate technical facts, coordinate with law enforcement, and avoid releasing details that could help attackers.
The reported timeframe suggests the intrusion may have occurred in late 2025, which can add complexity for incident response teams: logs rotate, systems change, and it may be harder to reconstruct exactly when data was accessed and through which pathway. For customers, the delay can be frustrating because it reduces the lead time to watch for scams.
If the exposed information is confirmed, practical consumer steps typically include being wary of password reset emails that feel urgent, verifying account messages through official apps or direct site visits rather than links, and considering email-based filtering for spoofed brand domains. Users should also enable multi-factor authentication wherever it is available, especially on email accounts that act as the “keys” to other services.
Under Armour has not described specific remediation steps beyond investigating the allegations, but the incident adds to a growing list of high-profile consumer-data exposures, reinforcing how retail brands have become a recurring target for credential-harvesting and mass phishing campaigns.