{"id":8528,"date":"2025-11-18T10:03:33","date_gmt":"2025-11-18T10:03:33","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/11\/18\/everest-ransomware-group-allegedly-exposes-343-gb-of-sensitive-data-in-major-under-armour-breach\/"},"modified":"2025-11-18T10:03:33","modified_gmt":"2025-11-18T10:03:33","slug":"everest-ransomware-group-allegedly-exposes-343-gb-of-sensitive-data-in-major-under-armour-breach","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/11\/18\/everest-ransomware-group-allegedly-exposes-343-gb-of-sensitive-data-in-major-under-armour-breach\/","title":{"rendered":"Everest Ransomware Group Allegedly Exposes 343 GB of Sensitive Data in Major Under Armour Breach"},"content":{"rendered":"<p>    Everest Ransomware Group Allegedly Exposes 343 GB of Sensitive Data in Major Under Armour Breach<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The notorious <a href=\"https:\/\/cybersecuritynews.com\/bmw-allegedly-breached\/\" target=\"_blank\" rel=\"noreferrer noopener\">Everest ransomware group<\/a> has claimed responsibility for a major cyber breach against Under Armour, the global sportswear giant, alleging the theft of 343 GB of internal data that could impact millions of customers and employees worldwide.<\/p>\n<p>The announcement, posted on the group\u2019s dark web leak site on November 16, 2025, includes a sample of stolen records to substantiate the claims, escalating concerns over potential identity theft and <a href=\"https:\/\/cybersecuritynews.com\/phishing-attack\/\">phishing<\/a> risks.<\/p>\n<p>According to Everest, the compromised dataset encompasses a vast array of personal and corporate information from Under Armour\u2019s systems.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-everest-ransomware-group-armour-breach\"><strong>Everest Ransomware Group Armour Breach<\/strong><\/h2>\n<p>This includes millions of client records with transaction histories, user IDs, email addresses, physical addresses, phone numbers, passport details, gender information, and both work and personal email contacts.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjS1P270fSOIyDTP7YxZ0aGeBJcXRZUxZnlkrPinVJlYv2cnesbyOwZgqAcbOysEemBC0dK-To4MgH2r_JmxfFrrVZLJLzhoT7SzJoq7bni9-n81PhVdoo6V0AIH3cFzSs27uObMxzMBrIjL8NklIKwoTSMf6KaGsxnFxdLf16eeo6mjq74OpgnJplKuuOc\/s16000\/everst%2520group%2520claim.webp?ssl=1\" alt=\"\"><\/figure>\n<p>Employee data from various countries is also implicated, alongside internal company documents. The sample provided by the hackers reveals sensitive customer shopping histories, product catalogs with SKUs, prices, and availability, as well as marketing logs and user behavior analytics.<\/p>\n<p>These details suggest the breach targeted Under Armour\u2019s customer relationship management, personalization, or e-commerce databases, potentially originating from marketing or product registration systems.\u200b<\/p>\n<p>Everest, active since 2021, has a track record of high-profile attacks, including claims against AT&amp;T\u2019s carrier database, which exposed over 500,000 users, 1.5 million passenger records from <a href=\"https:\/\/cybersecuritynews.com\/european-airport-ransomware-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">Dublin Airport<\/a>, and internal files from Coca-Cola.<\/p>\n<p>The group issued a seven-day ultimatum to Under Armour via Tox messenger, demanding contact before the countdown timer expires and threatening to leak the data if the demand is not fully met. No ransom amount was specified in the initial post, but Everest\u2019s pattern involves escalating leaks for non-compliant victims.\u200b<\/p>\n<p>Under Armour, headquartered in Baltimore, Maryland, has not yet publicly confirmed or denied the breach as of November 18. The company, which serves over 190 countries and boasts brands like MyFitnessPal (previously hit in a 2018 incident affecting 150 million users), could face significant fallout.<\/p>\n<p>Past breaches at the firm exposed usernames, emails, and hashed passwords, but spared financial data; this incident appears far broader, potentially including passports and transaction logs that enable targeted fraud.\u200b<\/p>\n<p>Cybersecurity experts warn that such exposures heighten the risk of supply chain attacks and social engineering. \u201cRansomware groups like Everest are pivoting to data exfiltration over encryption, turning breaches into intelligence goldmines,\u201d noted a Mandiant analyst.<\/p>\n<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has not yet listed this in its Known Exploited Vulnerabilities catalog, but similar incidents have prompted federal alerts.<\/p>\n<p>Customers are urged to monitor accounts for unusual activity, change passwords on Under Armour-linked services, enable multi-factor authentication, and watch for phishing emails masquerading as breach notifications.<\/p>\n<p>Enterprises should scan for Everest indicators of compromise, such as <a href=\"https:\/\/cybersecuritynews.com\/qbot-malware\/\" target=\"_blank\" rel=\"noreferrer noopener\">Qakbot malware<\/a> or Cobalt Strike beacons, which the group often uses. Under Armour has been contacted for comment; until verified, these remain allegations, but the sample\u2019s detail lends credibility.\u200b<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/everest-ransomware-group-armour-breach\/\">Everest Ransomware Group Allegedly Exposes 343 GB of Sensitive Data in Major Under Armour Breach<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/everest-ransomware-group-armour-breach\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Everest Ransomware Group Allegedly Exposes 343 GB of Sensitive Data in Major Under Armour Breach The notorious Everest ransomware group has claimed responsibility for a major cyber breach against Under Armour, the global sportswear giant, alleging the theft of 343 GB of internal data that could impact millions of customers and employees worldwide. The announcement, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,156],"tags":[130],"class_list":["post-8528","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-data-breach","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8528"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8528"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8528\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8528"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8528"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8528"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}