Latest / Tech Talks With Kinsoft / Under Armour Breach – 72 Million Customer Accounts Exposed
Transcript
- 0:00Welcome to Tech Talks with Kinsoft. Imagine waking
- 0:03up one morning and, you know, finding your front
- 0:06door just wide open, just swinging in the breeze.
- 0:08Oh, that is literally the worst feeling. Right.
- 0:10Your heart instantly drops to your stomach. You
- 0:13rush inside, you check the obvious spots, and
- 0:16the TV is still mounted on the wall. Okay, that's
- 0:19a relief. Yeah. You run to the bedroom, and your
- 0:22jewelry box is completely untouched. Your wallet
- 0:24is sitting exactly where you left it on the dresser.
- 0:27So you think you're safe? Exactly. You let out
- 0:29this massive full -body sigh of relief. But then...
- 0:34Then you walk into your home office and you realize
- 0:36someone has taken your personal diary, your address
- 0:38book, your calendar and like copies of every
- 0:42single receipt you've collected for the last
- 0:43five years. Yeah, that is a very specific, incredibly
- 0:47unsettling kind of a violation because the obvious
- 0:51financial valuables are safe. Right. But the
- 0:53context of your life is just gone. It's totally
- 0:55gone. The burglar knows exactly where you shop,
- 0:58who you talk to, what your daily routines look
- 1:00like. And that unsettling feeling. is exactly
- 1:04what we're confronting today in the digital world
- 1:07because we're looking at the recent massive Under
- 1:10Armour data breach. It's a huge one. It really
- 1:13is. We're pulling from some extensive reporting
- 1:15by TechCrunch and analysis from Malwarebytes
- 1:19to piece together exactly what happened between
- 1:22late 2025 and January of 2026. Right. And our
- 1:28mission for this conversation is to just cut
- 1:30straight through the competing narratives. Because
- 1:31right now you have aggressive cyber criminals
- 1:34making these huge apocalyptic claims on one side.
- 1:37And then highly cautious corporate PR teams doing,
- 1:40you know, highly choreographed damage control
- 1:42on the other. Exactly. So we need to figure out
- 1:44the truth. And more importantly, what this actually
- 1:47means for your personal data. Yeah. And to understand
- 1:50the actual risk you face right now, we have to
- 1:52rewind. We have to start with how this whole
- 1:54incident began. Let's do it. Because the way
- 1:56this story was initially told by the hackers
- 1:58versus how it was framed by the brand, I mean,
- 2:00it's like they were describing two completely
- 2:02different universes. So let's go back to late
- 2:042025, specifically November. There's this ransomware
- 2:08group known as Everest, and they publicly claim
- 2:11that the sportswear giant Under Armour. is their
- 2:14latest victim. Right. And Everest alleges that
- 2:17they have accessed around 343 gigabytes of corporate
- 2:21data. Which is I mean, just to put that in perspective,
- 2:25343 gigabytes of text based data like customer
- 2:28records, logs, emails. That is a monstrous amount
- 2:31of information. Massive. And they claim they
- 2:34are going public with this simply because. Under
- 2:37Armour essentially ignored them and failed to
- 2:40respond by their extortion deadline. Which is
- 2:42a very standard psychological pressure tactic
- 2:44in modern ransomware negotiations. How so? While
- 2:46these groups don't just lock up your systems
- 2:48anymore, they steal the data and hold it hostage.
- 2:50So when a company refuses to engage or stalls
- 2:54the negotiation, the hackers announce the breach
- 2:57on their dark web leak sites to force the company's
- 2:59hand. Basically hoping the bad press will terrify
- 3:02investors and executives into paying up. But
- 3:04Under Armour's official response means a remarkably
- 3:07different picture. Their spokesperson, Matt Dornick,
- 3:11comes out and states that the company is actively
- 3:14investigating the situation alongside external
- 3:17cybersecurity experts. Right. The standard PR
- 3:19response. Right. But then they draw these very
- 3:22firm, very specific lines in the sand. They claim
- 3:25there is absolutely no evidence that UA... Their
- 3:29payment processing systems or their customer
- 3:32password systems were affected in any way. Yeah.
- 3:35And they were meticulously careful what they're
- 3:37phrasing there. If you read that statement like
- 3:39a lawyer, they are building a very specific defensive
- 3:41wall. OK, let's unpack this. Yeah. Because Under
- 3:44Armour also stated that the number of customers
- 3:46who had what they called sensitive information
- 3:49compromise was a very small percentage. Right.
- 3:51And they flat out called the hackers claims.
- 3:54Yeah. You know, that tens of millions of people
- 3:55had sensitive personal information exposed. They
- 3:58called that completely unfounded. Yes, they did.
- 4:00So if Under Armour is definitively saying that
- 4:03our passwords are safe, our credit cards are
- 4:05safe, our payment systems are untouched, and
- 4:08this legally defined sensitive info is barely
- 4:13impacted. I mean, is this really just a minor
- 4:15hiccup or is the word sensitive doing a massive
- 4:18amount of heavy lifting for the corporate legal
- 4:20team here? What's fascinating here is the massive
- 4:23disconnect between the strict legal definition
- 4:26of sensitive data and the real world value of
- 4:30the data that hackers actually target. Because
- 4:32from a corporate liability standpoint, sensitive
- 4:35almost exclusively means highly regulated data.
- 4:38We're talking about Social Security numbers,
- 4:40full credit card numbers, bank account routing
- 4:43details. The big stuff. Exactly. If those specific
- 4:46fields aren't breached, a company will technically
- 4:49and legally tell you that sensitive data wasn't
- 4:51exposed. Because according to the letter of the
- 4:53law, they are arguably correct. Precisely. It's
- 4:56a compliance definition, not a practical one.
- 4:59But hackers don't operate on legal definitions.
- 5:02To a cybercriminal, your purchase history, your
- 5:05geographical location and your birth date are
- 5:07incredibly valuable commodities on the underground
- 5:10market. So the real world fallout from losing
- 5:13that supposedly nonsensitive data is actually
- 5:16pretty severe. Oh, absolutely. In fact, a class
- 5:18action lawsuit has already been filed in the
- 5:20U .S. alleging negligence against Under Armour
- 5:22regarding this very breach. So regardless of
- 5:25the careful corporate framing, you know, and
- 5:27the reassurance that the wider breach claims
- 5:29are unfounded, the legal and practical consequences
- 5:32are actively unfolding. Which brings us to the
- 5:34moment where we actually get to see who is telling
- 5:36the truth, because corporate statements heavily
- 5:39downplayed the severity of this throughout the
- 5:41end of 2025. Right. PR is telling everyone to
- 5:44stay calm. Everything is legally fine. Exactly.
- 5:47But let's look at what the hackers actually dumped
- 5:49on the dark web when their extortion deadline
- 5:51finally expired. Does the evidence actually back
- 5:55up that corporate confidence? Well, unfortunately
- 5:57for the millions of people in that database,
- 6:00the hackers weren't bluffing. No, they certainly
- 6:03were not. In January of 2026, Everest's threats
- 6:07materialized. A massive data set was published
- 6:10on a popular hacking forum, and Everest claimed
- 6:12this data was quickly duplicated across various
- 6:15leak sites and underground databases. And the
- 6:17scale of what was published is just staggering.
- 6:20It really is. The data set contains roughly 72
- 6:23million customer email addresses. That equates
- 6:26to about 72 .7 million unique user accounts,
- 6:30all pulled from a larger database of over 191
- 6:33million total records. Yeah, and at this point,
- 6:35we aren't just taking the cybercriminals at their
- 6:37word. The verification process for this kind
- 6:39of leak is actually very robust. Right, both
- 6:42TechCrunch and the widely respected breach notification
- 6:44site. Have I Been Proud obtained the data? Have
- 6:47I Been Proud officially listed the breach and
- 6:49actually went ahead and notified 72 million individuals
- 6:52that their information was circulating in the
- 6:53wild? That's a massive notification. It is. But
- 6:57here is the critical detail. It's not just a
- 6:59list of random email addresses. Many of these
- 7:02records contain full names, dates of birth, genders,
- 7:06approximate physical locations based on ZIP or
- 7:09postcodes, and highly detailed purchase histories.
- 7:13And the location data and purchase histories
- 7:15are really what elevate this from a minor nuisance
- 7:17to a major threat. And it's worth noting, too,
- 7:20that the leak even includes the email addresses
- 7:23belonging to Under Armour's own employees. Wow,
- 7:26really? Yeah, which raises massive questions
- 7:28about how compartmentalized their internal data
- 7:31actually was. I mean, that completely shatters
- 7:33the illusion that this is a minor incident affecting
- 7:35a very small percentage of people. Bringing you
- 7:38back to our earlier analogy. The hackers don't
- 7:40have the keys to your bank account, but they
- 7:42have that highly detailed dossier of your life.
- 7:44Exactly. They broke in, ignored the safe and
- 7:47took your diary and your shopping receipts. And
- 7:49from an analytical perspective, when we look
- 7:52at the balance of probabilities during a breach,
- 7:54we have to recognize the reality of cybercrime
- 7:57economics. Do ransomware groups sometimes lie
- 8:00or exaggerate their access to cause panic? Absolutely.
- 8:03Sure. But spinning up a massive leak entry. formatting
- 8:06and publishing 72 million verifiable records
- 8:10across multiple underground forums, and then
- 8:12distributing sample data to journalists. That
- 8:16requires a significant investment of time and
- 8:18resources. And I would assume it would also be
- 8:20instantly disproven the second anyone searched
- 8:23for their own data in the dump. Like if a journalist
- 8:25checks their own email and sees fake purchase
- 8:27history, the hackers lose all their credibility.
- 8:30That's exactly how the verification works. The
- 8:32data set is simply too robust, too internally
- 8:35consistent to be faked. Wow. Which means we need
- 8:39to emphasize that this specific combination of
- 8:42data, your date of birth, your location, what
- 8:44you bought and when, is an absolute goldmine
- 8:47to bad actors, even without your password attached
- 8:49to it. Okay, let's explore that. Because if I'm
- 8:51a hacker and I have this mask spreadsheet, but
- 8:53I don't have your password, what do I actually
- 8:55do with it? I'm not going to try and manually
- 8:56guess your password. I'm going to weaponize the
- 8:59information I do have to trick you, right? Yeah,
- 9:01that leads us directly to the real world risks.
- 9:04Now that we've established exactly what kind
- 9:06of data is circulating in the wild, we really
- 9:08need to bridge the gap between this abstract
- 9:11cyber event happening on dark web forums and
- 9:13your daily digital life. Right. The primary weapon
- 9:16here is targeted phishing. Here's where it gets
- 9:19really interesting. Let's build that scenario.
- 9:21Because instead of a generic spammy email saying,
- 9:25dear customer, your account is locked. Click
- 9:27here. The hackers. now have the context to be
- 9:30terrifyingly specific. Exactly. Hackers use the
- 9:34specific, supposedly non -sensitive data to craft
- 9:37highly convincing personalized attacks. You might
- 9:40get an email that says, Dear John, there is an
- 9:43issue with the warranty on the exact size 10
- 9:45running shoes you bought last October and had
- 9:47shipped to your Chicago ZIP code. Please click
- 9:49here to verify your account. If I get that email,
- 9:52I'm almost certainly going to assume it's legitimately
- 9:54from Under Armour. How else would anyone know
- 9:57the shoe size, the purchase month, and my specific
- 10:00ZIP code? It bypasses my mental spam filter instantly.
- 10:04They impersonate the brand or they might even
- 10:06impersonate delivery services like FedEx or UPS,
- 10:09referencing real past purchases to create a false
- 10:12sense of urgency. And this is why the actionable
- 10:15advice from sources like Malwarebytes is so critical
- 10:18right now. Because the playbook for defending
- 10:20yourself have to evolve based on how these attacks
- 10:23are structured. Exactly. So let's figure out
- 10:26our actual move here. If Under Armour is adamant
- 10:29that passwords weren't leaked in this specific
- 10:32breach. Why does a security firm like Malwarebytes
- 10:36recommend changing passwords as one of the very
- 10:39first steps? Isn't that fixing a lock that isn't
- 10:41broken? If we connect this to the bigger picture.
- 10:44You have to understand the full lifecycle of
- 10:46a hack. The initial data breach, the dumping
- 10:49of those 72 million records, is rarely the end
- 10:52of the story. It's really just the gathering
- 10:54phase. The gathering phase. The leaked data we
- 10:56just talked about, your name, your email, your
- 10:58purchase history, that is the ammunition. Hackers
- 11:00are stockpiling that ammunition to trick you
- 11:03into handing over your password tomorrow during
- 11:05one of those highly targeted phishing attacks
- 11:07we just described. Ah, I see. So they use the
- 11:10trusted context of my purchase history to lower
- 11:12my defenses. I click the link in that fake warranty
- 11:15email. It takes me to a fake Under Armour login
- 11:17page that looks completely authentic. I type
- 11:20in my password and boom, now they actually have
- 11:23it. Precisely. Furthermore, people reuse passwords
- 11:25constantly. If they can trick you into revealing
- 11:28your Under Armour password, they will immediately
- 11:30test that same email and password combination
- 11:33on your banking app, your email provider, your
- 11:36social media accounts. That's called credential
- 11:38stuffing. So changing your passwords now, using
- 11:41a password manager to ensure every single account
- 11:44has a strong, completely unique password disrupts
- 11:47their ability to pivot if they do manage to trick
- 11:50you. That makes perfect sense. Now, Malwarebytes
- 11:52also strongly recommends enabling two -factor
- 11:54authentication, or 2FA, but they make a very
- 11:57crucial distinction here. They specifically highlight
- 11:59using FIDO2 -compliant hardware keys or FIDO2
- 12:03-compliant laptops and phones. Wait, pause for
- 12:06a second. When you say FIDO2 hardware key, are
- 12:08we talking about a literal... physical key I
- 12:11put on my keychain, how does that actually plug
- 12:14into my digital life? It often is a literal physical
- 12:18device, yes. It looks like a small USB thumb
- 12:21drive that you keep on your keychain or plugged
- 12:23into your laptop. FIDO2 is really just the technical
- 12:26standard it uses. Sometimes this technology is
- 12:29also built directly into your modern smartphone
- 12:31or laptop, utilizing your fingerprint or FaceSight.
- 12:34But the reason cybersecurity experts are practically
- 12:37begging people to use FIDO2 instead of the traditional
- 12:40six -digit code you get via text message is because
- 12:43of how it handles the authentication map. How
- 12:45so? Because a text message code seems pretty
- 12:48secure to the average person. A text message
- 12:50code can be intercepted, or more commonly, a
- 12:52hacker can just build a fake website that asks
- 12:55you to type in the code they just triggered.
- 12:57But a FIDO2 hardware key uses something called
- 12:59cryptographic origin binding. Okay, let's keep
- 13:02that jargon free for everyone listening. How
- 13:04does origin binding actually protect me? Think
- 13:07of it like a highly trained, deeply paranoid
- 13:10bouncer. When you try to log in, your FIDO2 key
- 13:13doesn't just verify your identity. It looks at
- 13:16the actual underlying URL of the website you
- 13:19are on. How interesting. If you click a phishing
- 13:22link and end up on fake -underarmor .com, you
- 13:25might be fooled because the website looks identical.
- 13:27But when you press the button on your hardware
- 13:29key, the key checks the URL mathematically. It
- 13:32realizes, wait. This isn't the real Under Armour
- 13:35server, and it simply refuses to provide the
- 13:37cryptographic token. So even if I completely
- 13:39fall for the phishing email and I type in my
- 13:42password on the fake site, the hacker still can't
- 13:44get in because my physical key refuses to sign
- 13:47off on the fake location. That is the beauty
- 13:49of it. The math won't let the hacker succeed
- 13:51regardless of human error. It stops the phishing
- 13:54attack dead in its tracks. Unlike an SMS text
- 13:57message code, IDO2 physically cannot be phished.
- 14:00That is why it is the inevitable next step in
- 14:02securing... That is incredibly empowering to
- 14:06know. And alongside setting up hardware to F
- 14:09.A., Malwarebytes suggests a few other defensive
- 14:12maneuvers. They say you need to be hypervigilant
- 14:15against impersonators. Always independently verify
- 14:17the source of urgent emails or text messages.
- 14:20Absolutely. If you get a weird warranty claim,
- 14:22don't click the link. Open a new browser tab,
- 14:25go to the actual website yourself, and check
- 14:27your account there. It's about breaking the chain
- 14:29of urgency. Hackers rely on you panicking and
- 14:32clicking quickly. Taking a 10 -second pause to
- 14:35navigate to the site independently ruins their
- 14:37entire strategy. They also suggest you consider
- 14:40not storing your credit card details on retail
- 14:42sites in the future. Just enter it fresh every
- 14:45time or use virtual card numbers to universally
- 14:48minimize your risk. And finally, set up identity
- 14:51monitoring to track if your personal data is
- 14:53actively being traded illegally. Identity monitoring
- 14:56gives you visibility. You can't undo a data breach,
- 14:58but knowing exactly what information of yours
- 15:01is out there allows you to anticipate the specific
- 15:03types of scams that will be thrown at you. Which
- 15:05really brings this whole journey to a sobering
- 15:08but clarifying close. We started with a vague,
- 15:11carefully worded corporate claim in late 2025.
- 15:15a PR statement that dismissed a massive breach
- 15:18as unfounded and insisted it only affected a
- 15:21very small percentage of people because no legally
- 15:24regulated data was stolen. And we followed the
- 15:27evidence to a verified reality where 72 million
- 15:30incredibly detailed customer records were dumped
- 15:33on the dark web in January of 2026. To summarize
- 15:37everything we've unpacked, while Under Armour
- 15:39maintains to this day that their payment processing
- 15:41and password systems are entirely safe, The Everest
- 15:44ransomware group successfully leaked a massive
- 15:47dataset of personal histories. What this proves,
- 15:50beyond a shadow of a doubt, is that data corporations
- 15:53eagerly classify as non -sensitive, like your
- 15:56purchase history, your gender, your location,
- 15:58and your birthday, can still pose a massive phishing
- 16:00and privacy threat to your everyday life. It
- 16:02radically shifts the burden of security. If the
- 16:04data that makes you vulnerable isn't protected
- 16:06by law, the responsibility to defend against
- 16:09the fallout lands squarely on the consumer. It
- 16:11really does. And it leaves us with a pretty massive
- 16:14question to chew on. Think about this. We essentially
- 16:17built a massive legal fortress around the credit
- 16:19card number, complete with strict regulations
- 16:21and compliance laws. Yeah. But if a major corporation
- 16:25can lose 72 million detailed customer profiles
- 16:29dossiers that map out where people live, what
- 16:32they buy, and when they were born, and that corporation
- 16:34can still successfully argue to the public that
- 16:37no legally sensitive information was compromised.
- 16:40Have we built the moat around the wrong castle?
- 16:41Exactly. Do our legal definitions of data privacy
- 16:44need a massive modern overhaul that protects
- 16:48the human being, not just the financial asset?
- 16:50It's a crucial debate. Because right now, the
- 16:53framework is incredibly outdated compared to
- 16:55how cyber criminals actually monetize our identities.
- 16:58Taking control of your own digital security is
- 17:01truly no longer optional. You absolutely have
- 17:03to be proactive. And on that note, we'll warmly
- 17:06encourage you to visit www .kinsoft .com .au
- 17:09to discuss your own security and IT needs. Staying
- 17:12proactive, setting up those Fighter 2 hardware
- 17:14keys we talked about, and understanding the real
- 17:16value of your personal data is the absolute best
- 17:19defense you have in this rapidly changing landscape.
- 17:21Thank you so much for joining us and stay safe
- 17:23out there.