Nike probes potential cyber incident after hackers claim data leak

Sportswear giant Nike said it is investigating a potential cybersecurity incident after a hacking group claimed it had leaked a large volume of the company’s internal data.

The company said in a brief statement that it takes consumer privacy and data security seriously and is “actively assessing the situation,” but offered few details about the scope of the alleged breach or whether customer information may have been exposed.

Earlier this week a ransomware group known as WorldLeaks claimed on the dark web that it had leaked more than 1.4 terabytes of data allegedly belonging to Nike. The group said the material includes internal documents, archives from the past five years and information related to the company’s supply chain and manufacturing operations.

The authenticity of the data has not been independently verified, and it remains unclear whether customer data is part of the purported leak. Nike did not say whether it had received ransom demands or whether it was in contact with the attackers. The company did not immediately respond to a request for comment.

WorldLeaks is believed to be a rebranding of the now-defunct Hunters International operation, which shut down last year. Cybersecurity researchers have previously suggested that some administrators behind both groups may have ties to the Hive ransomware operation, a prolific ransomware syndicate dismantled by law enforcement in 2023.

The group has claimed hundreds of victims so far. Earlier in July, it allegedly breached tech manufacturer Dell, though the company said at the time that no sensitive information had been involved.

Nike is the latest sportswear brand to face cyberattack claims. Last week, Under Armour said it was investigating allegations that hackers had posted millions of customer records on an online forum, including names, email addresses and purchase-related data. It was not immediately clear whether the incidents involving Nike and Under Armour were connected.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Daryna Antoniuk

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.

 

Total
0
Shares
Previous Post

ClickFix Attacks Expand Using Fake CAPTCHAs, Microsoft Scripts, and Trusted Web Services

Next Post

Experts Detect Pakistan-Linked Cyber Campaigns Aimed at Indian Government Entities

Related Posts

ThreatsDay Bulletin: WhatsApp Hijacks, MCP Leaks, AI Recon, React2Shell Exploit and 15 More Stories

This week’s ThreatsDay Bulletin tracks how attackers keep reshaping old tools and finding new angles in familiar systems. Small changes in tactics are stacking up fast, and each one hints at where the next big breach could come from. From shifting infrastructures to clever social hooks, the week’s activity shows just how fluid the threat landscape has become. Here’s the full rundown of what
Read More

ThreatsDay Bulletin: AI Malware, Voice Bot Flaws, Crypto Laundering, IoT Attacks — and 20 More Stories

Hackers have been busy again this week. From fake voice calls and AI-powered malware to huge money-laundering busts and new scams, there’s a lot happening in the cyber world. Criminals are getting creative — using smart tricks to steal data, sound real, and hide in plain sight. But they’re not the only ones moving fast. Governments and security teams are fighting back, shutting down fake
Read More

Webinar: Learn to Spot Risks and Patch Safely with Community-Maintained Tools

If you're using community tools like Chocolatey or Winget to keep systems updated, you're not alone. These platforms are fast, flexible, and easy to work with—making them favorites for IT teams. But there’s a catch... The very tools that make your job easier might also be the reason your systems are at risk. These tools are run by the community. That means anyone can add or update packages. Some
Read More