ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Adidas probes third-party data breach after Lapsus$ claims extranet compromise

Adidas is investigating a potential data breach at one of its independent licensing partners after a cybercrime group claimed it infiltrated the sportswear company’s extranet and stole hundreds of thousands of records.


The Germany-based athletic apparel and footwear manufacturer confirmed it became aware of a possible data protection incident involving an independent licensing partner and distributor for martial arts products. The partner operates its own information technology systems separate from Adidas’ core infrastructure.


Company representatives said there is no indication that Adidas’ internal IT systems, e-commerce platforms or consumer data have been affected by the incident. The company did not disclose when the breach may have occurred or specify the types of information that may have been accessed through the third-party partner.


Allegations of the intrusion surfaced Feb. 16 when an individual claiming affiliation with the Lapsus$ Group posted on the cybercrime forum BreachForums, asserting that the group had compromised Adidas’ extranet. The post claimed that 815,000 rows of data were taken, including first and last names, email addresses, passwords, dates of birth, company names and unspecified technical data.


The investigation marks the second third-party security incident to affect Adidas in recent months. In May 2025, the company notified customers that certain personal data had been accessed by an unauthorized individual through a third-party customer service provider.


Lapsus$ rose to prominence during a wave of high-profile cyberattacks in 2021 and 2022. The group targeted major corporations across telecommunications, technology and financial services, including BT, Nvidia, Microsoft, Samsung, Vodafone, Revolut and Okta. Its tactics included phone-based social engineering, SIM swapping and, in some cases, paying employees of target organizations to obtain credentials and multi-factor authentication codes.


In March 2022, U.K. authorities arrested seven individuals between the ages of 16 and 21 in connection with Lapsus$ activity. Two suspects were later re-arrested and charged that same month.


In early August 2025, members linked to Lapsus$ joined forces with cybercrime collectives Scattered Spider and ShinyHunters under the name Scattered Lapsus$ Hunters. In October 2025, the group listed Adidas on its leak site and claimed it had stolen more than 20 million sensitive records in February 2024.


Adidas’ investigation into the latest incident remains ongoing.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543