HomeSecurityEverest ransomware group breached Under Armour

The Everest ransomware group breached Under Armour

The notorious Everest ransomware group has claimed responsibility for a major breach against Under Armour, the global sportswear giant, claiming the theft of 343GB of internal data that could affect millions of customers and employees worldwide.

See also: Akira ransomware spreads to Nutanix AHV

Everest ransomware

The announcement, posted on the group's dark web leak site on November 16, 2025, includes a sample of stolen files to substantiate the claims, escalating concerns about potential risks of identity theft and electronic phishing.

According to Everest, the compromised dataset includes a wide range of personal and corporate information from Under Armour's systems.

This includes millions of customer records with transaction history, user IDs, email addresses, physical addresses, phone numbers, passport details, gender information, and email contacts for both work and personal information.

Employee data from various countries is also involved, along with internal company documents. The sample provided by the hackers reveals sensitive customer purchase history, product catalogs with SKUs, prices, and availability, as well as marketing logs and user behavior analytics.

See also: Cyberextortion: Strategies for companies under ransomware attack

The Everest ransomware group breached Under Armour

These details suggest the breach targeted Under Armour's customer relationship management, personalization, or e-commerce databases, possibly originating from marketing or product registration systems.

Everest, which has been operating since 2021, has a history of high-profile attacks, including claims against AT&T's carrier database, which exposed over 500,000 users, 1.5 million passenger records from Dublin Airport, and internal files from Coca-Cola.

The group issued a seven-day ultimatum to Under Armour via Tox messenger, demanding communication before the countdown timer expires and threatening to leak data if the demand is not fully met. No ransom amount was specified in the initial post, but Everest's pattern involves escalating leaks for non-compliant victims.

Customers are urged to monitor accounts for unusual activity, change passwords on Under Armour-connected services, enable multi-factor authentication and watch out for phishing emails masquerading as breach notifications.

See also: Ransomware: New groups emerge and LockBit returns

The Everest ransomware group breached Under Armour

Businesses should scan for signs of an Everest breach, such as Qakbot or Cobalt Strike beacons, which the group often uses. Until verified, these allegations remain speculative, but the detail of the sample lends credibility.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS