University of Alaska
Incident posture
Linked entities
- Victim
- University of Alaska
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
A sportswear and fitness brand is investigating claims of a massive data breach after customer records from approximately 72 million people were posted on a hacker forum. The leaked dataset is reportedly linked to a ransomware attack during which the Everest ransomware group claimed responsibility and attempted to extort the company by threatening to leak internal files. Customer data from that incident later appeared publicly on a popular hacking forum before breach notification services obtained a copy and began alerting affected users by email. The exposed information may include names, email addresses, dates of birth, genders, approximate locations based on postal codes, and purchase history, along with email addresses belonging to company employees. The company stated that its investigation is ongoing with external cybersecurity experts and noted there is no evidence at this time that the issue affected systems used to process payments or store customer passwords.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In November 2025, the Everest ransomware group claimed responsibility for a cyberattack against Under Armour, a sportswear and fitness brand, and attempted to extort the company by threatening to release internal files. Following the ransomware intrusion, threat actors allegedly obtained a large volume of customer-related data from Under Armour's environment. The stolen files were reported to include a broad range of personal information associated with purchases, though payment card data and customer passwords were not confirmed to be part of the exposure at the time of disclosure. The Everest group publicized its activity in connection with the November intrusion, and the extortion attempt became part of the public record surrounding the incident.
In January 2026, customer records tied to the November 2025 breach began circulating publicly on a popular hacker forum. A seller on the forum claimed the leaked files came directly from the earlier compromise and contained millions of customer records. The dataset was subsequently obtained by the breach notification service Have I Been Pwned, which determined that it contained email addresses linked to approximately 72 million people. Have I Been Pwned then sent direct notification emails to affected individuals, alerting them that their information may have been compromised. The public appearance of the data and the resulting notification campaign significantly expanded awareness of the breach's scale and reach.
The exposed data, as described by cybersecurity researchers reviewing the leaked files, reportedly included names, email addresses, dates of birth, genders, approximate locations derived from ZIP codes or postcodes, and purchase history. Researchers also identified email addresses belonging to Under Armour employees within the dataset. Even without confirmed payment card details or passwords, the combination of personal identifiers and purchase information was recognized as highly valuable to cybercriminals, who could use the data to craft convincing phishing messages, build detailed identity profiles, and target affected individuals with fraud attempts referencing real account or order details. The presence of employee email addresses within the dataset indicated that internal personnel information was also part of the exposure.
Under Armour acknowledged the incident publicly through a spokesperson, stating that the company was aware of claims that an unauthorized third party had obtained certain data. The company indicated that it had engaged external cybersecurity experts to assist with an ongoing investigation into the issue. Under Armour emphasized that, as of the time of its statement, there was no evidence to suggest the issue affected UA.com or the systems used to process payments or store customer passwords, and it characterized any implication that sensitive personal information of tens of millions of customers had been compromised as unfounded. The company also stated that the security of its systems and data was a top priority and that it was taking the matter seriously. These public statements were issued while the investigation was still in progress, and the company did not provide a complete technical breakdown of the intrusion or the full scope of affected systems at that stage.
The incident timeline demonstrates a delay of roughly two months between the initial ransomware intrusion in November 2025 and the public emergence of customer data in January 2026, during which the Everest group held the data while attempting to pressure Under Armour. The subsequent posting on a hacker forum and the involvement of Have I Been Pwned in acquiring and distributing notifications marked the transition from an extortion-focused attack to a broad public data exposure. The scale of approximately 72 million affected email addresses positioned the incident among the larger consumer data exposures recorded, even though the exact categories of compromised information continued to be assessed.
As awareness of the leaked dataset spread, affected individuals began receiving breach notification messages from Have I Been Pwned, and media coverage amplified the disclosure. Researchers continued to review the data to confirm its contents and origins, while Under Armour's investigation, supported by external cybersecurity experts, remained ongoing. The combination of personal identifiers, purchase history, and employee email addresses within the leaked files underscored the breadth of the exposure and the continued risks faced by affected customers in the weeks following the public appearance of the data.
Sources
Sources available to members: 1 source.