logo

Under Armour Ransomware Attack Exposes 72M Email Addresses

ID: eaefde37-2d9a-545b-937e-ee5240fd4524

STIX ID: report--eaefde37-2d9a-545b-937e-ee5240fd4524

Feed Name: TechRepublic Security

Threat Score
85/100

Date Published: 2026-01-22

Date Updated: 2026-04-23

Author: TechRepublic Staff

...
...

The Everest ransomware group reportedly exfiltrated 343 GB of Under Armour data (including an estimated 72 million email addresses and other PII) and posted the data publicly after issuing extortion demands. The report profiles Everest as a sophisticated criminal enterprise and initial access broker that uses stolen credentials and remote access tools (AnyDesk, Splashtop) and deploys AES/DES encryption with a '.EVEREST' extension; it warns consumers and organizations about imminent phishing and account takeover risks and recommends improved password hygiene and multifactor authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.