News: 1771459050

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Adidas investigates third-party data breach after criminals claim they pwned the sportswear giant

(2026/02/19)


Adidas has confirmed it is investigating a third-party breach at one of its partner companies after digital thieves claimed they stole information and technical data from the German sportswear giant.

"We have been made aware of a potential data protection incident at one of our independent licensing partners and distributor for martial arts products," an Adidas spokesperson told The Register . "This is an independent company with its own IT systems."

Adidas declined to answer our questions about when the compromise occurred, or what information the crooks pilfered during the intrusion. The spokesperson added that there's "no indication that the adidas IT infrastructure, our own e-commerce platforms, or any of our consumer data are affected by the incident."

[1]

Allegations of an incident at Adidas emerged on February 16, when someone claiming to be the Lapsus$ Group posted on BreachForums (screenshot shared [2]here on Daily Dark Web) that they compromised the sportswear giant’s extranet. According to the crooks, the stolen files – 815,000 rows of information – allegedly include: first and last names, email addresses, passwords, birthdays, company names, and "a lot of technical data."

[3]

This latest breach follows a similar, third-party security incident last year affecting the sportswear multinational in May 2025. As we reported at the time, [4]Adidas notified customers that some of their data was stolen after an "unauthorized" person swiped it from a "third-party customer service provider."

[5]Adidas confirms criminals stole data from customer service provider

[6]Oh, great. Three notorious cybercrime gangs appear to be collaborating

[7]ShinyHunters allegedly drove off with 1.7M CarGurus records

[8]Fraudster hacked hotel system, paid 1 cent for luxury rooms, Spanish cops say

Lapsus$ is a chaotic crew of teens and young people that gained notoriety during a 2021-2022 crime spree. The gang broke into and attempted to extort telecoms giant BT, [9]Nvidia , [10]Microsoft , Samsung, Vodafone, fintech firm Revolut, and [11]Okta , using a mix of phone-based social engineering, SIM swapping, and even paying employees of target organizations for access to credentials and multi-factor authentication (MFA) codes.

In March 2022, UK police [12]arrested and then released seven people, aged 16 to 21, for their alleged role in Lapsus$ activities. Police [13]re-arrested and charged two of the teens for their involvement with the cybercrime gang later that month.

More recently, in early August 2025, the crew – or at least some of its members – [14]joined a cybercrime collective with Scattered Spider and ShinyHunters, operating under the name Scattered Lapsus$ Hunters. Two months later, in October 2025, the extortion collab listed Adidas on its leak site, and claimed to have stolen more than 20 million sensitive records back in February 2024. ®

Get our [15]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aZaY8vSaJC9w3xhO8DH5RgAAAcw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://dailydarkweb.net/adidas-extranet-data-breach-exposes-815000-records/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aZaY8vSaJC9w3xhO8DH5RgAAAcw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://www.theregister.com/2025/05/27/adidas_confirms_data_theft

[5] https://www.theregister.com/2025/05/27/adidas_confirms_data_theft/

[6] https://www.theregister.com/2025/08/12/scattered_spidershinyhunterslapsus_cybercrime_collab/

[7] https://www.theregister.com/2026/02/18/shinyhunters_cargurus_breach/

[8] https://www.theregister.com/2026/02/18/fraudster_hotel_hack_one_cent_luxury_room/

[9] https://www.theregister.com/2022/02/26/nvidia_security_breach/

[10] https://www.theregister.com/2022/03/21/microsoft_lapsus_breach_probe/

[11] https://www.theregister.com/2022/03/23/olkta_microsoft_lapsus/

[12] https://www.theregister.com/2022/03/24/police_lapsus_arrests/

[13] https://www.theregister.com/2022/04/01/lapsus_uk_charges/

[14] https://www.theregister.com/2025/08/12/scattered_spidershinyhunterslapsus_cybercrime_collab

[15] https://whitepapers.theregister.com/



Adidas intrusion policy

Winkypop

Three stripes and you’re out!

Law of Continuity:
Experiments should be reproducible. They should all fail the same way.