[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3bb7kaypkrsec":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"publishedAt":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":12,"affectedCountUnit":20,"hasEnglishDescription":4,"contentLocale":21,"availableLocales":22,"translations":24,"severity":27,"dataClasses":28,"description":35,"seoTitle":36,"seoDescription":37,"logoUrl":38,"isVerified":4,"isSensitive":39,"isSpamList":39,"isMalware":39,"company":40},"6a452308a20f867c8ba8e721","under-armour","Under Armour Data Breach","underarmour.com","2025-11-17T00:00:00.000Z","2026-01-21T06:34:18.000Z",null,"2026-07-03T09:46:49.029Z","2026-07-19T00:02:43.510Z","Third party breach","",[],72742892,"known","unknown","en",[21,23],"tr",{"en":25,"tr":26},{"slug":7},{"slug":7},"Critical",[29,30,31,32,33,34],"Dates of birth","Email addresses","Genders","Geographic locations","Names","Purchases","\u003Cp>The Under Armour data breach was recorded in November 2025 as a large-scale incident associated with the sportswear brand's customer data. The dataset published in January 2026 contained approximately 72.7 million unique email addresses, and many records included names, dates of birth, gender, geographic location, and purchase information. This scope poses a high risk in terms of retail fraud and personal profile extraction.\u003C\u002Fp> \u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2> \u003Cp>The data types listed in this record are Dates of birth, Email addresses, Genders, Geographic locations, Names, and Purchases. Password or payment card fields are not listed; however, having purchase and personal profile information together can make fake campaigns, returns, warranty, membership, and sports product-focused messages more convincing.\u003C\u002Fp> \u003Ch2>Sports Retail and Campaign Context\u003C\u002Fh2> \u003Cp>Under Armour customers may be accustomed to receiving messages such as discounts, orders, returns, product launches, sports applications, store campaigns, or membership notifications. Attackers can exploit this habit by preparing messages similar to past purchases or user profiles. Even if the message includes the correct name, location, or product interest, the transaction should be carried out through the official app or a known site.\u003C\u002Fp> \u003Ch2>Purchase History and Profile Effect\u003C\u002Fh2> \u003Cp>The Purchases section can provide context about which product categories the user is interested in. Context related to sports shoes, workout equipment, clothing, or seasonal products can reinforce fraudulent return and warranty messages. Campaign and return messages that ask the user for payment card, delivery fee, identification document, or verification code should be considered suspicious.\u003C\u002Fp> \u003Cp>The fields of dates of birth, genders, and geographic locations facilitate the personalization of targeted marketing or social engineering messages. Messages that appear to be a birthday campaign, regional store event, gender-based product recommendation, or membership gift can be prepared more realistically. Users should not automatically trust messages that contain accurate personal information.\u003C\u002Fp> \u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2> \u003Cp>It is important that payment card or password fields are not listed in this incident; however, account security is not entirely out of the question. If the same email address is used in different retail and sports applications, attackers may try to trick the user with fake login pages. Multi-factor authentication, strong passwords, and transaction notifications should be preferred for Under Armour or associated application accounts.\u003C\u002Fp> \u003Cp>From the perspective of organizations, the Under Armour incident shows that purchase history increases the impact of personal data. When it is combined what a customer buys, where they live, and which contact information they use, fraud scenarios become more realistic. Retail brands should not store customer data for unnecessary periods and should clearly state in campaign communications which information will not be requested from the user.\u003C\u002Fp> \u003Ch2>Necessary Precautions\u003C\u002Fh2> \u003Cp>Affected users should carefully check discount, return, warranty, membership, store event, sports app, or delivery messages coming under the name Under Armour. Even if personal information is correct, the official account should be manually visited before opening any links. Since fields like purchase history and date of birth can be used for a long time, this incident should be treated as a permanent social engineering risk.\u003C\u002Fp> \u003Ch2>Long-Term Sports Membership Risk\u003C\u002Fh2> \u003Cp>One of the areas that users should monitor in the long term in their Under Armour account is the sports app and connected membership accounts. If the same email address is used for the workout app, store account, event registration, or loyalty program, attackers can link these accounts. Therefore, not just the shopping account, but connected sports and health apps should also be checked.\u003C\u002Fp> \u003Cp>When the date of birth and purchase history are found together, personalized campaign messages become more effective. A birthday discount, a new model of a previous product, a regional store event, or an offer related to a sports goal can be sent to the user. Since these messages may resemble real campaigns, payment and login links must always be verified through the official app.\u003C\u002Fp> \u003Cp>Affected users should regularly check their saved payment methods and retail accounts. Although this breach does not directly list card data, purchase history can be used to redirect to fraudulent payment pages.\u003C\u002Fp>","Under Armour Data Breach (72.7 Million Reported Records)","Under Armour Data Breach. 72.7 Million reported records are reported. Reported data: Dates of birth, Email addresses, Genders. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Funderarmour_com.webp",false,{"name":41,"sector":42,"country":43,"website":9,"websiteArchiveUrl":16,"websiteStatus":16,"websiteCheckedAt":12},"Under Armour","Retail","United States"]