72.7 million Under Armour accounts exposed in reported ransomware breach
Everest ransomware gang is reported to have held a substantial amount of Under Armour’s data. Have I Been Pwned disclosed that approximately 72.7 million customer accounts were compromised in an alleged ransomware attack that took place in November. This cyber-breach platform revealed that the leaked files were made public by a member of the Everest ransomware group on a cybercrime forum on January 18. The leaked data included names, email addresses, dates of birth, genders, geographical locations, and details of previous purchases.
While Have I Been Pwned shared this information, Under Armour, the renowned athletic apparel company, has not officially acknowledged the alleged security breach. Despite multiple attempts to seek a response from the company regarding the attack back in November, there has been no statement or comment from Under Armour on the matter.
The ransomware attack claims surfaced when Everest included Under Armour on its leak site about two months ago, presenting a demand for a ransom payment within a week to prevent data disclosure. Apart from the information already confirmed by Have I Been Pwned, Everest asserted that additional data such as phone numbers, physical addresses, loyalty program details, and preferred stores were also part of the breached data.
Following the initial details provided by Everest, a law firm named Chimicles Schwartz Kriner & Donaldson-Smith announced a lawsuit on behalf of an affected Under Armour customer, Orvin Ganesh. Everest ransomware group is renowned for its significant cyber-attacks, having targeted organizations like Collins Aerospace, Sweden’s power grid, and the Brazilian government. Recently, Asus disclosed that it was impacted by an attack orchestrated by Everest, where the group infiltrated through a supplier and accessed internal files.
Despite the extensive operations and high-profile attacks conducted by Everest since 2020, it does not feature in any lists ranking the most hazardous or prevalent ransomware groups. Everest has managed to sustain its criminal endeavors through three main revenue streams – double extortion ransomware, network access brokerage, and an insider recruitment program. These avenues enable the group to generate profits discreetly, flying under the radar compared to more vociferous ransomware entities.
In conclusion, Everest, as a seasoned player in the ransomware arena, continues to operate proficiently, utilizing different tactics to maintain revenue streams and evade widespread recognition compared to its more visible counterparts.