Adidas
Incident posture
Timeline
Summary
Adidas reported that an unauthorized external party accessed certain consumer data through a third‑party customer service provider, stressing that passwords and credit‑card information were not compromised. The exposed data primarily consisted of contact details from consumers who had previously reached out to the company’s help desk. Upon discovery, the company took immediate containment measures and launched a thorough investigation with the assistance of leading information‑security experts. The company is now in the process of notifying potentially affected individuals about the incident.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On May 23, 2025, Adidas announced that an unauthorized external party had accessed certain consumer data via a third‑party customer service provider. The breach was disclosed in a statement issued from Berlin, where the company confirmed that the compromised information did not include passwords or credit card details. According to Adidas, the data primarily consisted of contact information belonging to consumers who had previously reached out to its customer service help desk. The company said it became aware of the incident and immediately took steps to contain the unauthorized access. Adidas also launched a comprehensive investigation into the breach, enlisting leading information security experts to assist. The investigation aimed to determine the scope of the data exposure and the methods used by the external party.
As part of its response, Adidas began the process of notifying potentially affected consumers about the breach. The company emphasized that it was working closely with security specialists to ensure the incident was fully resolved and to prevent similar occurrences. No further details about the number of records involved or the identity of the third‑party provider were provided in the statement. Adidas reiterated that the breach did not expose financial credentials, limiting the potential impact to contact‑information misuse. The company’s actions focused on containment, investigation, and consumer communication to address the security incident.
Sources
Sources available to members: 1 source.