
Adidas is investigating a potential data breach at one of its independent licensing partners after a cybercrime group claimed it infiltrated the sportswear company’s extranet and stole hundreds of thousands of records.
The Germany-based athletic apparel and footwear manufacturer confirmed it became aware of a possible data protection incident involving an independent licensing partner and distributor for martial arts products. The partner operates its own information technology systems separate from Adidas’ core infrastructure.
Company representatives said there is no indication that Adidas’ internal IT systems, e-commerce platforms or consumer data have been affected by the incident. The company did not disclose when the breach may have occurred or specify the types of information that may have been accessed through the third-party partner.
Allegations of the intrusion surfaced Feb. 16 when an individual claiming affiliation with the Lapsus$ Group posted on the cybercrime forum BreachForums, asserting that the group had compromised Adidas’ extranet. The post claimed that 815,000 rows of data were taken, including first and last names, email addresses, passwords, dates of birth, company names and unspecified technical data.
The investigation marks the second third-party security incident to affect Adidas in recent months. In May 2025, the company notified customers that certain personal data had been accessed by an unauthorized individual through a third-party customer service provider.
Lapsus$ rose to prominence during a wave of high-profile cyberattacks in 2021 and 2022. The group targeted major corporations across telecommunications, technology and financial services, including BT, Nvidia, Microsoft, Samsung, Vodafone, Revolut and Okta. Its tactics included phone-based social engineering, SIM swapping and, in some cases, paying employees of target organizations to obtain credentials and multi-factor authentication codes.
In March 2022, U.K. authorities arrested seven individuals between the ages of 16 and 21 in connection with Lapsus$ activity. Two suspects were later re-arrested and charged that same month.
In early August 2025, members linked to Lapsus$ joined forces with cybercrime collectives Scattered Spider and ShinyHunters under the name Scattered Lapsus$ Hunters. In October 2025, the group listed Adidas on its leak site and claimed it had stolen more than 20 million sensitive records in February 2024.
Adidas’ investigation into the latest incident remains ongoing.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543