
A threat actor operating under the alias "Nocturne" has posted a database listing on a dark web forum claiming to have exfiltrated customer data from Nike, though the sportswear company has not confirmed the incident. The actor alleges the breach occurred in June 2026 and says millions of lines of customer data were taken, an amount estimated to be in the eight figures.
According to the listing, the material is limited to customer registration and order records from 2026, with nothing predating that year. The actor says the dataset is packaged as a 7z archive containing CSV files, with an uncompressed size exceeding 40GB, and included a sample screenshot as purported evidence.
Cybersecurity researchers who examined a data sample tied to the alleged breach described it as disorganized, consisting of a mix of JSON files containing purported user information alongside application logs. The researchers said that wherever personal information appeared in the sample, it was duplicated, making it difficult to determine how much unique data the leak actually contains or how many total records the sample holds.
The researchers also noted that Nike’s name surfaced mainly within application class names rather than in content that would directly tie the data to the company. Their analysis of the logs pointed to collection through Amazon Simple Queue Service, a messaging tool used by applications hosted on Amazon Web Services to process queued data. Based on these findings, the researchers said it is likely the data originated from a third-party vendor rather than from Nike directly, though the sample offered no way to identify which vendor might be involved. They added that such incidents would not be unusual, since smaller providers are increasingly targeted for having weaker security defenses than larger companies.
This is not the first time Nike has been named in a major data-leak claim in 2026. In January, the ransomware group WorldLeaks claimed it had stolen roughly 1.4 terabytes of internal Nike data, and after its demands went unmet, the group publicly released the material. Nike acknowledged a potential incident at the time and opened an investigation but has not confirmed that the leaked data belonged to the company.
The current claim involving customer data remains unverified. Nike has not issued a public statement confirming unauthorized access to its systems.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543