Earlier this year, customer data relating to a major consumer brand was published publicly following a ransomware incident. The breach affected tens of millions of accounts and included personal information such as names, email addresses, dates of birth, location data and purchase history.
Incidents like this are no longer unusual. What matters is how organisations — and individuals — respond.
What Happened
In late 2025, a ransomware group claimed to have gained access to a large volume of customer data belonging to UnderArmour. In early 2026, a dataset associated with the incident was made publicly available on a hacking forum.
The information reported as exposed included:
- Email addresses
- Names and basic demographic data
- Geographic location details
- Purchase information
There is no indication that payment card data was included, but the scale of the exposure makes it a useful reminder that even well-known, well-resourced companies are not immune.
Why This Matters
Data breaches like this don’t just affect one service or account.
Once personal information is public, it can be reused for:
- Credential stuffing attacks
- Targeted phishing
- Social engineering
- Account takeover attempts elsewhere
In other words, the risk often shows up later, and somewhere else.
Practical Steps We Recommend
We regularly advise clients to take a few straightforward precautions. None of these are new or exotic, but together they make a material difference.
1. Use a password manager
Using unique, strong passwords for every service is no longer optional — and doing that without help is unrealistic.
We use 1Password internally and recommend reputable password managers to clients. They reduce the blast radius of breaches by ensuring one compromised service doesn’t expose others.
2. Change passwords after major breaches
If you’ve reused credentials — even partially — it’s worth rotating them after incidents of this scale, particularly for accounts tied to email addresses.
A password manager makes this manageable rather than painful.
3. Enable multi-factor authentication where possible
MFA won’t prevent all attacks, but it significantly raises the bar for account takeover, especially when credentials are already in circulation.
4. Sign up for breach notifications
Services that notify you when your details appear in known breaches provide early warning. They don’t prevent incidents, but they do give you time to respond before problems escalate. Have I Been Pwned is a good place to start.
A Final Thought
Security failures are rarely the result of a single mistake. They emerge from complexity, scale and the realities of modern systems.
The sensible response isn’t panic — it’s preparation.
Good password hygiene, sensible tooling and early awareness won’t eliminate risk entirely, but they do ensure that when something goes wrong elsewhere, it doesn’t automatically become your problem.
That’s a standard we try to hold ourselves and our work to.