2026 Under Armour / MyFitnessPal — ~72.7M emails in HIBP reload (Jan)
Data compromised
Email addresses and related credential or account metadata as indexed—overlap with 2018 incident expected
Technical writeup
Have I Been Pwned and consumer-data roundups in January 2026 surfaced a large Under Armour / MyFitnessPal–labeled credential or email set on the order of ~72.7 million addresses, widely interpreted by analysts as renewed visibility of recycled 2018 breach material, stealer logs, or reindexed forum dumps rather than a freshly confirmed perimeter intrusion at the same scale. Treat as a disclosure/indexing event pending any new Under Armour forensic statement distinct from the historic MyFitnessPal incident.
Root cause
Recirculation or recompilation of legacy breach/stealer data (per HIBP and analyst framing)
References
- https://haveibeenpwned.com/
- https://www.wired.com/story/under-armour-myfitnesspal-hack/
- https://tech.co/news/data-breaches-updated-list
- https://www.acilearning.com/blog/the-biggest-cybersecurity-breaches-of-2026-so-far-and-the-training-that-could-have-prevented-them/
- https://www.pkware.com/blog/2026-data-breaches
- https://www.securitymagazine.com/articles/102110-7-data-breaches-exposures-to-know-about-january-2026