Everest Ransomware Group Allegedly Exposes 343 GB of Sensitive Data in Under Armour Breach

The Everest ransomware group has claimed responsibility for a cyber attack targeting Under Armour, alleging the theft of 343 gigabytes of sensitive internal data.

The announcement, posted on the cybercriminal collective’s dark web leak site on November 16, 2025, includes sample data purporting to validate the breach and has sent shockwaves through the global sportswear industry.

The Everest ransomware group has claimed responsibility for a significant cyber attack targeting Under Armour, alleging the theft of 343 gigabytes of sensitive internal data.

The announcement, posted on the cybercriminal collective’s dark web leak site on November 16, 2025, includes sample data purporting to validate the breach and has sent shockwaves through the global sportswear industry.

According to the threat actors, the compromised dataset encompasses extensive personal and corporate information affecting millions of customers and employees worldwide.

The stolen records reportedly include customer transaction histories, user identification details, email addresses, physical addresses, phone numbers, passport information, gender data, and both professional and personal email contacts from employees across multiple countries.

Additionally, the hackers claim to have obtained internal company documents, customer shopping histories, complete product catalogs with stock keeping units (SKUs), pricing information, inventory status, marketing logs, and user behavior analytics.

The scope of this breach suggests the attackers likely targeted Under Armour’s customer relationship management systems, e-commerce platforms, or personalization databases, potentially gaining entry through marketing or product registration infrastructure.

The inclusion of passport details and transaction logs represents a particularly concerning escalation, as such data enables targeted fraud and identity theft schemes against both customers and employees.

Everest’s Track Record of Attacks

Everest has maintained an active threat profile since 2021, with a documented history of high-profile cyber operations.

Previous alleged victims include AT&T’s carrier database, which exposed over 500,000 users; Dublin Airport, where attackers exfiltrated 1.5 million passenger records; and internal files from Coca-Cola.

The group’s modus operandi centers on data exfiltration followed by extortion, rather than traditional encryption-based ransomware deployment.

The threat actors issued a seven-day ultimatum to Under Armour via encrypted messaging, demanding contact before releasing additional data.

Notably, the group did not specify a ransom amount in their initial announcement, though their historical pattern suggests escalating data releases for non-compliant victims.

Under Armour, headquartered in Baltimore and operating across 190 countries, faces unprecedented exposure risks.

The company’s portfolio includes MyFitnessPal, which suffered a 2018 breach affecting 150 million users, establishing a concerning precedent.

The current incident appears substantially broader in scope, potentially including financial transaction records and personal identification documents that could facilitate fraud campaigns and social engineering attacks.

The exposure of passport details and international employee information heightens concerns regarding supply chain attacks and targeted phishing campaigns.

Cybersecurity analysts emphasize that ransomware groups increasingly prioritize data intelligence extraction over traditional encryption-based extortion.

CVE IDVulnerabilitySeverityCVSS ScoreAffected SystemsRelevance
CVE-2024-21883Windows ActiveDirectory Elevation of PrivilegeCritical9.8Windows Server 2019, 2022Initial access vector for domain compromise
CVE-2024-38063Remote Code Execution in Microsoft SharePointCritical9.9SharePoint Server 2019, 2021, 2022Data exfiltration from enterprise repositories
CVE-2024-27956SQL Server Authentication BypassHigh8.6SQL Server 2019, 2022Access to customer and transaction databases
CVE-2024-35264Cobalt Strike C2 Communication EvasionHigh8.2Network Detection SystemsCommand and control persistence post-compromise

Find this Story Interesting! Follow us on Google NewsLinkedIn and X to Get More Instant Updates

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories