Cybersecurity

🔥 Everest Ransomware Hits Under Armour — Hackers Claim “Millions of Customer Records” and 343GB of Stolen Data

December 13, 20253 min read

The cyber underground is buzzing again — and this time, a global retail giant is in the crosshairs.

Under Armour, the powerhouse behind athletic apparel and footwear worn by millions, has allegedly been breached by the Everest ransomware cartel, a crew known for targeting high-value global brands.

And according to the attackers, this isn’t just another hit — it’s a mass exfiltration event.

Everest claims to have stolen:

  • “Millions” of customer records across multiple countries

  • 343 GB of internal company documents

  • Extensive employee info from global offices

Under Armour has not yet released an official statement, but the damage — and the implications — are already massive.


⚠️ What Everest Says They Stole

The ransomware gang published their claims on their dark web leak site, boasting access to an “UNDER ARMOUR DataBase” full of highly sensitive information.

Their samples include:

🧑‍💼 Customer & Employee Profile Data

  • User IDs

  • Email addresses

  • Physical home addresses

  • Genders & countries of origin

  • Employee work locations & teams

🛒 Detailed Purchase & Order Histories

  • Purchase dates

  • Item details & prices

  • Shipment status

  • Return history

  • Currency used

📂 Internal Corporate Documents (343 GB)

Everest says their stolen doc cache includes:

  • Internal memos

  • Operational documents

  • Personal employee data

  • Miscellaneous confidential files

While the samples did not show credit card numbers, the level of personal detail revealed is more than enough to fuel identity theft, targeted phishing, and high-value social engineering attacks.

This is exactly the kind of data adversaries weaponize for months — even years — after a breach.


The Ransom Clock Is Already Running

Everest posted a countdown timer with instructions for Under Armour to play a pre-recorded ransom message.

Their threat is simple:

“A company representative should contact us before time runs out.”

As of this writing, Under Armour has just over seven days left before the gang threatens to publish everything.


🌍 A Global Brand With a Global Attack Surface

Under Armour operates across:

  • 15,000+ retail locations worldwide

  • Dual HQs in Baltimore and Amsterdam

  • Offices in Denver, Hong Kong, Toronto, Guangzhou

  • A workforce of ~1,400 employees

  • $5.1B in 2025 reported revenue

The more distributed the enterprise, the larger the attack surface — and Everest knows how to exploit that.


💀 Everest’s Expanding Victim List

Everest is no small-time actor. According to dark web intel tools, the gang has:

  • 250+ victims since 2023

  • 100+ in the past 12 months alone

Previous high-profile targets include:

  • Collins Aerospace — impacting European airport check-in systems

  • BMW

  • Coca-Cola Middle East

  • Pacific HealthWorks

  • Mailchimp

  • Radisson Country Inn & Suites

  • DZ Bank subsidiary (though the bank denied the breach)

Everest has recently targeted the Middle East, European infrastructure, U.S. healthcare, and major retail sectors — clearly focusing on high-yield domains with valuable data and large digital footprints.

Cyber intelligence analysts also note ties between Everest and BlackByte, another financially motivated ransomware collective.


🎯 Why This Breach Matters (Even If You Don’t Wear Under Armour)

This incident is a tactical reminder of three uncomfortable truths:

  1. Retail brands are massive data warehouses — and therefore irresistible targets.
    Customer analytics, purchase histories, and personal info are more valuable to threat actors than the apparel itself.

  2. Attackers increasingly rely on data theft over encryption.
    This is the new playbook: exfiltrate first, negotiate later.

  3. Once data leaves your environment, you can’t un-leak it.
    Even paying ransom doesn’t guarantee suppression.

Under Armour now faces a collision of regulatory exposure, customer trust erosion, and operational disruption.


🛡️ Elliptic Systems’ Take

This breach underscores a harsh reality:

Your data is only as secure as your cyber posture — and Everest is testing everyone’s posture right now.

Organizations of all sizes must adopt:

  • Zero Trust principles

  • AI-enhanced threat monitoring

  • Proactive incident response playbooks

  • Continuous penetration testing

  • Enterprise-wide identity & access reviews

If a household brand like Under Armour can be compromised, your business isn’t “too small,” “too new,” or “too obscure” to be targeted.

Cybercriminals don’t hunt brands — they hunt vulnerabilities.

Eric Stefanik

Eric Stefanik

Ai Consultant | Best-selling Author | Speaker | Innovator | Leading Cybersecurity Expert

LinkedIn logo icon
Instagram logo icon
Youtube logo icon
Back to Blog