CSIDB logo
Incident

Adidas

Incident posture

Attack window
Nov 2025
Location
Germany
Status
Unknown
CIA posture
Available to members
Updated
2026-08-17 17:38

Linked entities

Victim
Adidas
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Undetermined
Disclosed
May 2025
Resolved
Pending

Summary

Adidas reported that an unauthorized external party accessed certain consumer data through a third‑party customer service provider, stressing that passwords and credit‑card information were not compromised. The exposed data primarily consisted of contact details from consumers who had previously reached out to the company’s help desk. Upon discovery, the company took immediate containment measures and launched a thorough investigation with the assistance of leading information‑security experts. The company is now in the process of notifying potentially affected individuals about the incident.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On May 23, 2025, Adidas announced that an unauthorized external party had accessed certain consumer data via a third‑party customer service provider. The breach was disclosed in a statement issued from Berlin, where the company confirmed that the compromised information did not include passwords or credit card details. According to Adidas, the data primarily consisted of contact information belonging to consumers who had previously reached out to its customer service help desk. The company said it became aware of the incident and immediately took steps to contain the unauthorized access. Adidas also launched a comprehensive investigation into the breach, enlisting leading information security experts to assist. The investigation aimed to determine the scope of the data exposure and the methods used by the external party.

As part of its response, Adidas began the process of notifying potentially affected consumers about the breach. The company emphasized that it was working closely with security specialists to ensure the incident was fully resolved and to prevent similar occurrences. No further details about the number of records involved or the identity of the third‑party provider were provided in the statement. Adidas reiterated that the breach did not expose financial credentials, limiting the potential impact to contact‑information misuse. The company’s actions focused on containment, investigation, and consumer communication to address the security incident.

Sources

Sources available to members: 1 source.

CSIDB