CSIDB logo
Incident

Under Armour

Incident posture

Attack window
H1 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 11:17

Linked entities

Victim
Under Armour
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Under Armour suffered a data breach in the first half of 2026 affecting approximately 72.7 million accounts, as reported by the Identity Theft Resource Center.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

In early 2026, Under Armour was involved in a large-scale data breach that contributed significantly to the overall rise in victim notices recorded by the Identity Theft Resource Center during the first half of the year. According to ITRC figures cited in the CNET report, the Under Armour incident affected approximately 72.7 million accounts. Combined with the even larger Canvas education platform breach, which generated an estimated 275 million victim notices, these two incidents alone produced more victim notices than the total number of data compromises recorded during all of 2025. The scale of the Under Armour breach placed it among the "megabreaches" that drove a doubling of victim notices in the first half of 2026, even though the total number of breach incidents rose only modestly compared with the previous year. The ITRC reported 1,803 publicly disclosed data compromises in the first half of 2026, resulting in roughly 471.2 million victim notices, more than double the revised total from the same period in 2025 and 58% more than were issued during the entirety of 2025.

Limited public information was made available about the specifics of the Under Armour breach, in line with a broader trend of reduced transparency in breach disclosures noted by the ITRC. Across all 1,803 breach notices analyzed during the first half of 2026, only 24% included details about the attack method, the lowest disclosure rate the ITRC has ever recorded and a sharp drop from 93% in 2021. In 77% of the cases tracked, the notices did not identify the specific nature of the breach, such as whether phishing, ransomware, malware, or another vector was involved. An additional 402 incident reports contained so little information that the ITRC could not determine even the broad cause. The article does not specify what type of attack was used against Under Armour, what particular systems or databases were compromised, when the intrusion was first detected, or how it was contained. No details are provided about whether employee credentials, an unpatched vulnerability, a third-party vendor, or insider access played a role in the breach.

The consequences of the breach, as reported, center on the exposure of account information belonging to approximately 72.7 million individuals. The article does not specify the exact categories of personal information that were exposed in the Under Armour incident, such as whether passwords, Social Security numbers, financial data, or other sensitive identifiers were involved. Victim notices are generally sent to individuals whose information was exposed or potentially exposed, but they do not represent a count of unique individuals, since a single person affected by multiple breaches could receive multiple notices. The article does not describe any specific response actions taken by Under Armour following the breach, such as password resets, credit monitoring offers, public statements, or regulatory filings. It also does not indicate whether the company confirmed the ITRC's estimate of 72.7 million affected accounts or provided its own count.

Sources

Sources available to members: 1 source.

CSIDB