ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Hacker claims Nike customer data theft; researchers suspect third-party source

A threat actor operating under the alias "Nocturne" has posted a database listing on a dark web forum claiming to have exfiltrated customer data from Nike, though the sportswear company has not confirmed the incident. The actor alleges the breach occurred in June 2026 and says millions of lines of customer data were taken, an amount estimated to be in the eight figures.


According to the listing, the material is limited to customer registration and order records from 2026, with nothing predating that year. The actor says the dataset is packaged as a 7z archive containing CSV files, with an uncompressed size exceeding 40GB, and included a sample screenshot as purported evidence.


Cybersecurity researchers who examined a data sample tied to the alleged breach described it as disorganized, consisting of a mix of JSON files containing purported user information alongside application logs. The researchers said that wherever personal information appeared in the sample, it was duplicated, making it difficult to determine how much unique data the leak actually contains or how many total records the sample holds.


The researchers also noted that Nike’s name surfaced mainly within application class names rather than in content that would directly tie the data to the company. Their analysis of the logs pointed to collection through Amazon Simple Queue Service, a messaging tool used by applications hosted on Amazon Web Services to process queued data. Based on these findings, the researchers said it is likely the data originated from a third-party vendor rather than from Nike directly, though the sample offered no way to identify which vendor might be involved. They added that such incidents would not be unusual, since smaller providers are increasingly targeted for having weaker security defenses than larger companies.


This is not the first time Nike has been named in a major data-leak claim in 2026. In January, the ransomware group WorldLeaks claimed it had stolen roughly 1.4 terabytes of internal Nike data, and after its demands went unmet, the group publicly released the material. Nike acknowledged a potential incident at the time and opened an investigation but has not confirmed that the leaked data belonged to the company.


The current claim involving customer data remains unverified. Nike has not issued a public statement confirming unauthorized access to its systems.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543