Nike Investigating Data Breach Following WorldLeaks Ransomware Group Claim
Nike is currently investigating a potential cybersecurity incident following claims by the ransomware group WorldLeaks of a significant data breach. The group announced the breach on its darknet leak site on January 22, 2026, asserting the exfiltration…
Nike is currently investigating a potential cybersecurity incident following claims by the ransomware group WorldLeaks of a significant data breach. The group announced the breach on its darknet leak site on January 22, 2026, asserting the exfiltration of over 1.4 terabytes of internal data and threatening to release the information if ransom demands are unmet.
Nike has acknowledged the incident and is actively assessing the situation, emphasizing its commitment to consumer privacy and data security. However, the company has not disclosed details regarding the breach's scope or whether customer information was compromised.
WorldLeaks claims the exfiltrated data includes internal documentation, customer information, employee credentials, supply chain records, and manufacturing operations archives from the past five years. Initial reports suggest approximately 481,183 user accounts, 220 employee records, and 444 third-party employee credentials may be affected.
WorldLeaks, which emerged as a rebrand of the Hunters International operation in January 2025, employs an extortion-only model focusing on data theft. This approach facilitates faster attack execution and reduces detection risk. Cybersecurity researchers have identified potential links between WorldLeaks administrators and the dismantled Hive ransomware operation.
Nike is currently investigating a potential cybersecurity incident following claims by the ransomware group WorldLeaks of a significant data breach.
To date, WorldLeaks claims over 116 victims, including Dell Technologies, where they allegedly stole 1.3 terabytes of data. The group typically gains access through compromised websites, phishing campaigns, unpatched applications, and VPNs lacking multi-factor authentication.
This incident is part of ongoing cyberattacks targeting the retail and athletic apparel sectors. Last week, Under Armour reported a separate incident involving the exposure of millions of customer records.
Security experts advise organizations to implement mandatory multi-factor authentication on all remote access points to mitigate such threats. The incident highlights the persistent risk posed by ransomware groups targeting high-value organizations.
Based on reporting by Cyber Security News.
