Adidas Data Breach Exposes Customer Information
Adidas has confirmed a data breach impacting customer data, stemming from unauthorized access through a third-party customer service provider. The incident, first reported in May 2024, has prompted an investigation and enhanced cybersecurity measures by the sportswear giant.
Details of the Breach
According to Adidas’s official statement, an “unauthorized external party obtained certain consumer data through a third-party customer service provider.” McAfee reports that the compromised information includes contact details of customers who have previously contacted Adidas’s customer service aid desk.
While the breach primarily affected contact information, Adidas has stated that passwords, credit card data, and other payment information were not compromised. The UBJ
The breach specifically impacted Adidas Korea, marking the second major data security incident targeting Korean consumers in the fashion industry within the same month. Cybersecurity News
Security Expert Insights
Security leaders emphasize the importance of robust security measures for third-party software. Jonathan Stross, SAP Security Analyst at Pathlock, highlights the need for “quality gates and data loss prevention” for third-party software, noting that these systems are often “blindly trusted.” Security Magazine
Stross also points out that third-party software often lacks the necessary reporting APIs and capabilities to detect and block unusual access patterns indicative of data exports.
Jason Soroko, Senior Fellow at Sectigo, notes that the incident exposes an industry-wide “blind spot” related to call-center data security.
What Customers Should Do
Adidas advises affected customers to be vigilant against phishing attempts, unsolicited messages, and unusual online activity. The UBJ recommends monitoring emails for suspicious requests, avoiding unfamiliar links, and updating account passwords as a precautionary measure.
Even though financial data wasn’t leaked, customers should be aware that their contact information could be used for identity fraud. McAfee
Adidas’s Response
Upon discovering the breach, Adidas launched an internal investigation, collaborated with cybersecurity experts, and reported the incident to relevant data protection authorities, complying with regulations like the European Union’s General Data Protection Regulation (GDPR). The UBJ