The Everest ransomware group claimed Under Armour as a victim in November 2025, alleging it had obtained 343GB of data. Customer data was subsequently published on a hacking forum in early 2026, including a large volume of email addresses. Reporting has placed the affected population at tens of millions.
This File Is About The Gap Between Claim And Evidence
Graded low, and deliberately so. The 343GB figure originates with the attacking group. The affected population figures derive from analysis of published material rather than from company disclosure. The corpus has not established what the company confirmed, when, or to whom.
This desk filed the standing objection at 26-0425 and 25-1111: leak-site figures are advertisements written by the seller, and gigabytes are a particularly poor unit because a single video archive can outweigh every customer record a company holds.
The Sequence Is The Useful Part
Claim in November. Publication months later. That interval is the extortion window — the period in which the threat has value because it has not yet been carried out.
Publication is the point at which the attacker’s leverage is spent, which is why it happens after negotiation fails. The corpus recorded the same at 25-0815, where Saint Paul refused and 43GB went up, and at 25-1018, where health records went to public Telegram.
And Email Addresses Are The Least Of It
A published set of tens of millions of email addresses is widely reported because it is easy to count. It is also the least sensitive field likely to be in a retailer’s customer database.
This desk argued at 25-1130 that order history describes a person more completely than contact details, and at 25-0501 that a loyalty scheme is built to be complete. What was counted is not what matters, and what matters was not counted.
Compiled from public reporting and breach-tracking sources, listed below. The volume figure is an attacker claim. Population figures derive from third-party analysis of published material, not from company disclosure. Corrections: corrections@forensicpost.com.