The Everest ransomware group has claimed responsibility for a cyber attack targeting Under Armour, alleging the theft of 343 gigabytes of sensitive internal data.
The announcement, posted on the cybercriminal collective’s dark web leak site on November 16, 2025, includes sample data purporting to validate the breach and has sent shockwaves through the global sportswear industry.
The Everest ransomware group has claimed responsibility for a significant cyber attack targeting Under Armour, alleging the theft of 343 gigabytes of sensitive internal data.
The announcement, posted on the cybercriminal collective’s dark web leak site on November 16, 2025, includes sample data purporting to validate the breach and has sent shockwaves through the global sportswear industry.
According to the threat actors, the compromised dataset encompasses extensive personal and corporate information affecting millions of customers and employees worldwide.
The stolen records reportedly include customer transaction histories, user identification details, email addresses, physical addresses, phone numbers, passport information, gender data, and both professional and personal email contacts from employees across multiple countries.
Additionally, the hackers claim to have obtained internal company documents, customer shopping histories, complete product catalogs with stock keeping units (SKUs), pricing information, inventory status, marketing logs, and user behavior analytics.
The scope of this breach suggests the attackers likely targeted Under Armour’s customer relationship management systems, e-commerce platforms, or personalization databases, potentially gaining entry through marketing or product registration infrastructure.
The inclusion of passport details and transaction logs represents a particularly concerning escalation, as such data enables targeted fraud and identity theft schemes against both customers and employees.
Everest’s Track Record of Attacks
Everest has maintained an active threat profile since 2021, with a documented history of high-profile cyber operations.

Previous alleged victims include AT&T’s carrier database, which exposed over 500,000 users; Dublin Airport, where attackers exfiltrated 1.5 million passenger records; and internal files from Coca-Cola.
The group’s modus operandi centers on data exfiltration followed by extortion, rather than traditional encryption-based ransomware deployment.
The threat actors issued a seven-day ultimatum to Under Armour via encrypted messaging, demanding contact before releasing additional data.
Notably, the group did not specify a ransom amount in their initial announcement, though their historical pattern suggests escalating data releases for non-compliant victims.
Under Armour, headquartered in Baltimore and operating across 190 countries, faces unprecedented exposure risks.
The company’s portfolio includes MyFitnessPal, which suffered a 2018 breach affecting 150 million users, establishing a concerning precedent.
The current incident appears substantially broader in scope, potentially including financial transaction records and personal identification documents that could facilitate fraud campaigns and social engineering attacks.
The exposure of passport details and international employee information heightens concerns regarding supply chain attacks and targeted phishing campaigns.
Cybersecurity analysts emphasize that ransomware groups increasingly prioritize data intelligence extraction over traditional encryption-based extortion.
| CVE ID | Vulnerability | Severity | CVSS Score | Affected Systems | Relevance |
|---|---|---|---|---|---|
| CVE-2024-21883 | Windows ActiveDirectory Elevation of Privilege | Critical | 9.8 | Windows Server 2019, 2022 | Initial access vector for domain compromise |
| CVE-2024-38063 | Remote Code Execution in Microsoft SharePoint | Critical | 9.9 | SharePoint Server 2019, 2021, 2022 | Data exfiltration from enterprise repositories |
| CVE-2024-27956 | SQL Server Authentication Bypass | High | 8.6 | SQL Server 2019, 2022 | Access to customer and transaction databases |
| CVE-2024-35264 | Cobalt Strike C2 Communication Evasion | High | 8.2 | Network Detection Systems | Command and control persistence post-compromise |
Find this Story Interesting! Follow us on Google News, LinkedIn and X to Get More Instant Updates