Quick Summary
The Securityish Brief
Adidas confirmed an investigation into a data breach linked to one of its independent licensing partners, specifically a distributor for martial arts products. The breach was publicly announced on February 16 by the Lapsus$ Group, which claimed to have compromised Adidas’ extranet and stolen 815,000 rows of sensitive information. This data allegedly includes first and last names, email addresses, passwords, birthdays, company names, and technical data.
This incident follows a similar breach in May 2025, where Adidas reported unauthorized access to customer data from a third-party service provider. The Lapsus$ Group, known for its chaotic cybercrime activities, has previously targeted major companies like BT, Nvidia, Microsoft, and Samsung using various tactics, including social engineering and SIM swapping.
In early August 2025, some members of Lapsus$ reportedly joined forces with other cybercriminals to form a new collective named Scattered Lapsus$ Hunters. This collaboration has raised concerns about the potential for increased cyber threats, as they have claimed to have stolen over 20 million sensitive records from Adidas back in February 2024.
Understanding the Risks
The breach highlights the vulnerabilities associated with third-party partnerships, emphasizing the importance of robust security measures for companies relying on external vendors. Organizations should be aware that even if their own systems are secure, breaches at third-party partners can lead to significant data exposure.
For users, this incident serves as a reminder to regularly update passwords and monitor accounts for suspicious activity, especially if they have interacted with Adidas or its partners. The nature of the data stolen, including passwords and personal information, could lead to identity theft or further phishing attempts.
As cybercriminals continue to evolve their tactics, organizations must prioritize cybersecurity training for employees and implement strong access controls to mitigate risks associated with third-party relationships.
Key Takeaways
- Regularly update your passwords and use unique ones for different accounts.
- Monitor your accounts for any suspicious activity, especially if you have used Adidas products.
- Consider enabling multi-factor authentication on your accounts for added security.
- Stay informed about data breaches affecting companies you interact with.
- Review your third-party vendor contracts to ensure they have adequate security measures in place.
Key Terms & Concepts
- Lapsus$ Group: In this article, Lapsus$ Group refers to a notorious cybercrime gang known for targeting major companies and extorting them.
- extranet: An extranet is a controlled private network allowing access to partners, vendors, and suppliers, often used for sharing information.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.