← Blog

Nike Forum Claim: 40 GB Customer CSV Alleged (Unverified)

Share on X

Unverified claim — July 2026: A threat actor advertised on a criminal forum purported Nike customer datasets: 40+ gigabytes of uncompressed CSV files described as 2026 registration and order data with names, emails, contact fields, and transaction details. Nike has not publicly confirmed the listing. This is distinct from the January 2026 WorldLeaks ~1.4 TB internal-document extortion wave Nike was already investigating, per The Record.

What was allegedly exposed

  • Customer names and email addresses
  • Contact information
  • Order and transaction-related fields
  • Other PII tied to 2026 registrations (actor description—unverified)

Why treat this as unverified

Forum sellers routinely repackage old e-commerce leaks, scrape public data, or inflate row counts. Without Nike confirmation, regulator filings, or independent sample verification in reputable security journalism, the CSV claim remains actor marketing.

Action items for Nike shoppers

  1. Enable Nike account MFA and rotate passwords not used elsewhere.
  2. Ignore refund or "order failed" emails that reference leaked order numbers until Nike issues official guidance.
  3. Monitor payment cards used on nike.com for unauthorized charges.

See also: Nike WorldLeaks investigation (Jan 2026) · Canonical claim row: Nike forum customer CSV claim (unverified).