
🔥 Everest Ransomware Hits Under Armour — Hackers Claim “Millions of Customer Records” and 343GB of Stolen Data
The cyber underground is buzzing again — and this time, a global retail giant is in the crosshairs.
Under Armour, the powerhouse behind athletic apparel and footwear worn by millions, has allegedly been breached by the Everest ransomware cartel, a crew known for targeting high-value global brands.
And according to the attackers, this isn’t just another hit — it’s a mass exfiltration event.
Everest claims to have stolen:
“Millions” of customer records across multiple countries
343 GB of internal company documents
Extensive employee info from global offices
Under Armour has not yet released an official statement, but the damage — and the implications — are already massive.
⚠️ What Everest Says They Stole
The ransomware gang published their claims on their dark web leak site, boasting access to an “UNDER ARMOUR DataBase” full of highly sensitive information.
Their samples include:
🧑💼 Customer & Employee Profile Data
User IDs
Email addresses
Physical home addresses
Genders & countries of origin
Employee work locations & teams
🛒 Detailed Purchase & Order Histories
Purchase dates
Item details & prices
Shipment status
Return history
Currency used
📂 Internal Corporate Documents (343 GB)
Everest says their stolen doc cache includes:
Internal memos
Operational documents
Personal employee data
Miscellaneous confidential files
While the samples did not show credit card numbers, the level of personal detail revealed is more than enough to fuel identity theft, targeted phishing, and high-value social engineering attacks.
This is exactly the kind of data adversaries weaponize for months — even years — after a breach.
⏳ The Ransom Clock Is Already Running
Everest posted a countdown timer with instructions for Under Armour to play a pre-recorded ransom message.
Their threat is simple:
“A company representative should contact us before time runs out.”
As of this writing, Under Armour has just over seven days left before the gang threatens to publish everything.
🌍 A Global Brand With a Global Attack Surface
Under Armour operates across:
15,000+ retail locations worldwide
Dual HQs in Baltimore and Amsterdam
Offices in Denver, Hong Kong, Toronto, Guangzhou
A workforce of ~1,400 employees
$5.1B in 2025 reported revenue
The more distributed the enterprise, the larger the attack surface — and Everest knows how to exploit that.
💀 Everest’s Expanding Victim List
Everest is no small-time actor. According to dark web intel tools, the gang has:
250+ victims since 2023
100+ in the past 12 months alone
Previous high-profile targets include:
Collins Aerospace — impacting European airport check-in systems
BMW
Coca-Cola Middle East
Pacific HealthWorks
Mailchimp
Radisson Country Inn & Suites
DZ Bank subsidiary (though the bank denied the breach)
Everest has recently targeted the Middle East, European infrastructure, U.S. healthcare, and major retail sectors — clearly focusing on high-yield domains with valuable data and large digital footprints.
Cyber intelligence analysts also note ties between Everest and BlackByte, another financially motivated ransomware collective.
🎯 Why This Breach Matters (Even If You Don’t Wear Under Armour)
This incident is a tactical reminder of three uncomfortable truths:
Retail brands are massive data warehouses — and therefore irresistible targets.
Customer analytics, purchase histories, and personal info are more valuable to threat actors than the apparel itself.Attackers increasingly rely on data theft over encryption.
This is the new playbook: exfiltrate first, negotiate later.Once data leaves your environment, you can’t un-leak it.
Even paying ransom doesn’t guarantee suppression.
Under Armour now faces a collision of regulatory exposure, customer trust erosion, and operational disruption.
🛡️ Elliptic Systems’ Take
This breach underscores a harsh reality:
Your data is only as secure as your cyber posture — and Everest is testing everyone’s posture right now.
Organizations of all sizes must adopt:
Zero Trust principles
AI-enhanced threat monitoring
Proactive incident response playbooks
Continuous penetration testing
Enterprise-wide identity & access reviews
If a household brand like Under Armour can be compromised, your business isn’t “too small,” “too new,” or “too obscure” to be targeted.
Cybercriminals don’t hunt brands — they hunt vulnerabilities.
