Nike probes potential cyber incident after hackers claim data leak

Sportswear giant Nike said it is investigating a potential cybersecurity incident after a hacking group claimed it had leaked a large volume of the company’s internal data.

The company said in a brief statement that it takes consumer privacy and data security seriously and is “actively assessing the situation,” but offered few details about the scope of the alleged breach or whether customer information may have been exposed.

Earlier this week a ransomware group known as WorldLeaks claimed on the dark web that it had leaked more than 1.4 terabytes of data allegedly belonging to Nike. The group said the material includes internal documents, archives from the past five years and information related to the company’s supply chain and manufacturing operations.

The authenticity of the data has not been independently verified, and it remains unclear whether customer data is part of the purported leak. Nike did not say whether it had received ransom demands or whether it was in contact with the attackers. The company did not immediately respond to a request for comment.

WorldLeaks is believed to be a rebranding of the now-defunct Hunters International operation, which shut down last year. Cybersecurity researchers have previously suggested that some administrators behind both groups may have ties to the Hive ransomware operation, a prolific ransomware syndicate dismantled by law enforcement in 2023.

The group has claimed hundreds of victims so far. Earlier in July, it allegedly breached tech manufacturer Dell, though the company said at the time that no sensitive information had been involved.

Nike is the latest sportswear brand to face cyberattack claims. Last week, Under Armour said it was investigating allegations that hackers had posted millions of customer records on an online forum, including names, email addresses and purchase-related data. It was not immediately clear whether the incidents involving Nike and Under Armour were connected.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Daryna Antoniuk

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.

 

Total
0
Shares
Previous Post

ClickFix Attacks Expand Using Fake CAPTCHAs, Microsoft Scripts, and Trusted Web Services

Next Post

Experts Detect Pakistan-Linked Cyber Campaigns Aimed at Indian Government Entities

Related Posts

Cisco Warns of New Firewall Attack Exploiting CVE-2025-20333 and CVE-2025-20362

Cisco on Wednesday disclosed that it became aware of a new attack variant that's designed to target devices running Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software releases that are susceptible to CVE-2025-20333 and CVE-2025-20362. "This attack can cause unpatched devices to unexpectedly reload, leading to denial-of-service
Read More

WhatsApp Worm Spreads Astaroth Banking Trojan Across Brazil via Contact Auto-Messaging

Cybersecurity researchers have disclosed details of a new campaign that uses WhatsApp as a distribution vector for a Windows banking trojan called Astaroth in attacks targeting Brazil. The campaign has been codenamed Boto Cor-de-Rosa by Acronis Threat Research Unit. "The malware retrieves the victim's WhatsApp contact list and automatically sends malicious messages to each contact to further
Read More