Desk live·
ForensicPost
Ransomware/Verification/File 25-1001

Three Hundred and Forty-Three Gigabytes, Claimed in November

The Everest group claimed Under Armour as a victim in November 2025, alleging 343GB of data. Email addresses were published on a hacking forum the following year.

Constructed geometry · not a chart of case data
JurisdictionUSABaltimore, Marylandthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetUnder Armour
ActorEverest
S. Rosler12 min readConfidence: low3 sources reviewed

The Everest ransomware group claimed Under Armour as a victim in November 2025, alleging it had obtained 343GB of data. Customer data was subsequently published on a hacking forum in early 2026, including a large volume of email addresses. Reporting has placed the affected population at tens of millions.

This File Is About The Gap Between Claim And Evidence

Graded low, and deliberately so. The 343GB figure originates with the attacking group. The affected population figures derive from analysis of published material rather than from company disclosure. The corpus has not established what the company confirmed, when, or to whom.

This desk filed the standing objection at 26-0425 and 25-1111: leak-site figures are advertisements written by the seller, and gigabytes are a particularly poor unit because a single video archive can outweigh every customer record a company holds.

The Sequence Is The Useful Part

Claim in November. Publication months later. That interval is the extortion window — the period in which the threat has value because it has not yet been carried out.

Publication is the point at which the attacker’s leverage is spent, which is why it happens after negotiation fails. The corpus recorded the same at 25-0815, where Saint Paul refused and 43GB went up, and at 25-1018, where health records went to public Telegram.

And Email Addresses Are The Least Of It

A published set of tens of millions of email addresses is widely reported because it is easy to count. It is also the least sensitive field likely to be in a retailer’s customer database.

This desk argued at 25-1130 that order history describes a person more completely than contact details, and at 25-0501 that a loyalty scheme is built to be complete. What was counted is not what matters, and what matters was not counted.

How we reported this

Compiled from public reporting and breach-tracking sources, listed below. The volume figure is an attacker claim. Population figures derive from third-party analysis of published material, not from company disclosure. Corrections: corrections@forensicpost.com.

Sources
  1. Under Armour investigates data breach claims affecting 72 millionFox News
  2. Under Armour data breachHave I Been Pwned
  3. Under Armour failed to protect sensitive info from November 2025 data breach, class action saysClassAction.org
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary