
Global sportswear brand Adidas has confirmed separate data breaches affecting customers in South Korea and Türkiye, marking a significant cybersecurity concern for the company and its regional consumers.
In both incidents, unauthorized parties gained access to personal customer information via third-party service providers. While the breaches did not involve financial data, they exposed sensitive personal details, prompting investigations and enhanced security measures by the company.
Adidas Korea publicly disclosed the breach on May 16, confirming that customer data was compromised through a third-party customer service provider. The company stated that individuals who contacted its service centers in 2024 or earlier may have had their names, email addresses, phone numbers, and in some instances, birthdates and physical addresses accessed. Adidas emphasized that no payment-related data or passwords were affected.
“We have confirmed that there was unauthorized access to some consumer data through a third-party customer service provider,” the company stated in an announcement published on its website. The breach has been reported to the relevant Korean authorities, and Adidas is working with cybersecurity experts to conduct a thorough investigation. Notifications have been sent to all affected Korean customers.
Adidas Türkiye also acknowledged a similar breach in a recent email to its customers. The incident, likewise attributed to third-party involvement, resulted in the exposure of personal information including full names, contact details, birthdates, and gender. As with the Korean breach, financial and password data remained unaffected.
“Dear customers, we want to inform you about a situation that may have affected your personal data,” read the email, which confirmed that those impacted had previously reached out to Adidas customer service. The company has initiated an internal review and reinforced its data security protocols in response.
While Adidas has not disclosed the number of individuals affected in either country, it advised all customers to stay alert for suspicious communications and phishing attempts. Thus far, there have been no reports of misuse of the compromised data.
The Adidas Korea breach follows a similar cybersecurity incident involving luxury fashion brand Dior. On May 13, Dior reported that personal customer data, including purchase history and contact information, had been accessed by unauthorized parties in January. The breach, discovered in May, drew criticism for the delayed disclosure and failure to promptly notify the Korea Internet & Security Agency (KISA).
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543