Under Armour investigates breach after emails and profile details reportedly exposed
Under Armour said it is looking into a reported breach involving customer email addresses and other profile information. The company said there is no evidence passwords or payment systems were affected as it assesses what data was exposed and how.

Company responds to a large reported exposure
Under Armour said it is investigating a reported data breach that may have exposed customer email addresses and related profile information tied to its digital services. The incident drew attention after the breach was highlighted publicly, prompting questions about what was accessed, how it occurred and what customers should do next.

While details are still being clarified, reported exposed fields include emails and other account-related data such as basic demographics and location elements like ZIP code. Under Armour said it has not seen evidence that passwords or financial information were compromised, and it indicated its main website and payment systems were not affected.
Why email exposure still matters
Even when passwords and payment cards are not included, a large dataset of valid email addresses paired with personal details can still be valuable to criminals. Such lists can be used for targeted phishing, credential-stuffing attempts on other sites, and scams that mimic customer support messages or “account verification” prompts.
Security experts typically advise customers to be cautious of unexpected password-reset emails, suspicious promotional messages, or communications that pressure immediate action. Attackers often exploit breach headlines by sending realistic-looking messages that claim to help people “secure their account” while actually stealing credentials.
Steps customers can take
- Change passwords for any accounts that reused the same or similar credentials elsewhere.
- Enable multi-factor authentication where available, especially on email accounts.
- Treat urgent “verify your account” emails and links with skepticism and use official apps or typed URLs instead.
Under Armour’s investigation is expected to focus on confirming which systems were accessed, what information was taken, and whether additional notifications are required under privacy and breach disclosure laws.