In re Under Armour, Inc. Data Incident Litigation

District Court, D. Maryland·Decided September 11, 2026·No. 1:25-cv-03857·Unknown

Opinion

IN THE UNITED STATES DISTRICT COURT FOR THE DISTRICT OF MARYLAND

* IN RE UNDER ARMOUR, INC. * DATA INCIDENT LITIGATION * * * Civil Case No.: SAG-25-03857 * * * * * * * * * * * * * * MEMORANDUM OPINION

Four plaintiffs brought three separate actions against Under Armour, Inc. (“UA” or “Defendant”), individually and on behalf of those similarly situated, alleging injuries from a ransomware attack of UA’s computer system, which contained their personal information. ECF 7. The separate actions were consolidated into the instant case, in which eight individuals, bringing suit on behalf of themselves and all others similarly situated (“Plaintiffs”), filed the Consolidated Class Action Complaint (“CCAC”) on March 6, 2026. ECF 19. The CCAC alleges common law negligence and contract claims on behalf of all Plaintiffs, along with a violation of the Maryland Consumer Protection Act on behalf of Plaintiffs who reside in Maryland. Id. UA has filed a Motion to Dismiss the CCAC. ECF 29. Plaintiffs oppose the motion, ECF 32, and UA filed a reply, ECF 33. This Court has reviewed the filings and finds that no hearing is necessary. See Loc. R. 105.6 (D. Md. 2025). For the reasons explained below, the Motion will be granted in part and denied in part. I. BACKGROUND The following facts are derived from Plaintiffs’ CCAC, ECF 19, and are assumed to be true for the purpose of the motion to dismiss. UA is a Maryland-based corporation, and an “inventor, marketer, and distributor of branded athletic performance apparel, footwear, and accessories.” Id. ¶ 22. It “operates a global retail and e‑commerce business, with online stores, mobile apps, loyalty programs, and other digital services.” Id. ¶ 27. In the course of its business, UA “collects and stores vast quantities of Personal Information from customers and employees.” Id. This “Personal Information” includes “email addresses, phone numbers, gender, dates of birth,

passport information, zip codes, location data for cities and regions, deep‑link tracking entries, and identifiers tied to user accounts and transactions.” Id. ¶ 2. The Data Breach In November, 2025, Everest, a ransomware gang, “infiltrated Under Armour’s systems and stole approximately 343 GB of internal company data, including the personal data of over 72 million Under Armour consumers and employees.” Id. ¶ 1. Everest gave UA a seven-day window to meet a ransom demand for the data, id. ¶ 41, and when UA did not pay the ransom, Everest “leaked the unique records of 72 million individuals on the dark web.” Id. ¶ 43. Sources, “including TechCrunch, Have I Been Pwned, BankInfoSecurity, Hackread, SentryBay, and Bitedefender … confirm that a dataset containing information for approximately 72 million Under Armour

accounts has been posted on the dark web and tied to the Everest ransomware group.” Id. ¶ 3. “On information and belief,” Plaintiffs allege that Everest and other actors have: • Advertised Plaintiffs’ and Class Members’ Personal Information on dark‑web forums and marketplaces; • Bundled Plaintiffs’ and Class Members’ stolen Personal Information— including names, email addresses, phone numbers, dates of birth, passport information, location and store‑preference data, and detailed purchase and browsing histories—into saleable “profiles”; and • Sold and distributed those profiles to other criminal actors.

Id. ¶ 64. UA has not provided notice of the breach to any customers or employees whose Personal Information may have been affected. Id. ¶ 44. Plaintiffs’ Injuries Named Plaintiffs are eight former employees or customers of UA, or both. Plaintiffs allege that they suffered the following actual injuries and damages from UA’s data breach: (a) lost time and money related to monitoring [their] accounts and credit reports for fraudulent activity, (b) loss of privacy due to [their] Personal Information being accessed and stolen by cybercriminals; (c) loss of the benefit of the bargain because Under Armour did not adequately protect [their] Personal Information; (d) emotional distress because identity thieves now possess [their] Personal Information; (e) imminent and impending injury arising from the increased risk of fraud and identity theft now that [their] Personal Information has likely been stolen and published on the dark web; (f) diminution in the value of [their] Personal Information, a form of intangible property that Under Armour obtained from [Plaintiffs]; and (g) other economic and non-economic harm.

Id. ¶¶ 157, 167, 179, 192, 207, 217, 229, 240. Further, all named Plaintiffs anticipate “spending considerable time and money on an ongoing basis to try to mitigate and address harms caused by the Data Breach.” Id. ¶¶ 155, 165, 177, 190, 203, 215, 226, 238. Seven of the eight named Plaintiffs have already spent time and effort monitoring their accounts and attempting to mitigate harm from the data breach. Id. ¶¶ 154, 164, 176, 186, 199, 224, 236. At various times in December, 2025 and January, 2026, five named Plaintiffs—Boyle, Wilkins, Malone, Ganesh, and Cai—received notice that the Personal Information that they provided to UA was posted on the dark web. Id. ¶¶ 153, 163, 187, 225, 237. In addition, four named Plaintiffs allege additional, individualized injuries: a. In January, 2026, Plaintiff Martin experienced fraudulent activity on her debit card when the card “was charged for a gas station transaction that she did not make.” Id. ¶ 175. She “called her bank to dispute and rescind the charge and was issued a replacement debit card by her bank.” Id. b. Plaintiff Malone has “received multiple emails from various lenders and loan companies stating that she owes them money, even though she has never applied for loans from those companies, and has no prior relationship with them,” and was “notified of a fraudulent attempt to access her direct express following the Data Breach.” Id. ¶ 188. c. An unauthorized individual fraudulently opened a bank account with Bank of America using Plaintiff Costar’s Personal Information without her knowledge or consent. Id. ¶ 200.

An individual also fraudulently applied for an apartment in Pennsylvania using Plaintiff Costar’s Personal Information, opened an Indigo credit card in her name, and “reported income that Plaintiff Costar supposedly earned in Pennsylvania although Plaintiff Costar has never earned any income or lived in Pennsylvania before.” Id. ¶ 201. As a result, Plaintiff Costar’s credit score has dropped significantly. Id. ¶ 202. d. Plaintiff Ganesh has received “a significant increase in unsolicited spam calls.” Id. ¶ 227. The Class Action The eight named Plaintiffs seek to represent a class of “[a]ll individuals residing in the United States whose Personal Information was accessed and/or acquired by an unauthorized party as a result of the Data Breach” (the “Nationwide Class”). Id. ¶ 242. Plaintiff Malone, who resides

in Maryland, also seeks to represent a class of “[a]ll individuals residing in the State of Maryland whose Personal Information was accessed and/or acquired by an unauthorized party as a result of the Data Breach” (the “Maryland Subclass”). Id. ¶ 242. The Nationwide Class asserts four claims: negligence and negligence per se (Count I), breach of express or implied contract (Count II), breach of fiduciary duty (Count III), and unjust enrichment (Count IV). The Maryland Subclass asserts one claim, a violation of the Maryland Consumer Protection Act (Count V). The classes seek injunctive relief and monetary damages. Id. at 61. II. LEGAL STANDARDS UA has now filed a Motion to Dismiss the CCAC under Federal Rules of Civil Procedure 12(b)(1) and 12(b)(6). ECF 29. A. Rule 12(b)(1) Standard

Free access — add to your briefcase to read the full text and ask questions with AI

In re Under Armour, Inc. Data Incident Litigation, (D. Md. 2026).

In re Under Armour, Inc. Data Incident Litigation (In re Under Armour, Inc. Data Incident Litigation) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Lujan v. Defenders of Wildlife
504 U.S. 555 (Supreme Court, 1992)
Bennett v. Spear
520 U.S. 154 (Supreme Court, 1997)
Bell Atlantic Corp. v. Twombly
550 U.S. 544 (Supreme Court, 2007)
Doe v. Obama
631 F.3d 157 (Fourth Circuit, 2011)
Adams v. Bain
697 F.2d 1213 (Fourth Circuit, 1982)
Clapper v. Amnesty International USA
133 S. Ct. 1138 (Supreme Court, 2013)
Kerns v. United States
585 F.3d 187 (Fourth Circuit, 2009)
Peer v. First Federal Savings & Loan Ass'n
331 A.2d 299 (Court of Appeals of Maryland, 1975)
Hill v. Cross Country Settlement, LLC
936 A.2d 343 (Court of Appeals of Maryland, 2007)
Kann v. Kann
690 A.2d 509 (Court of Appeals of Maryland, 1997)
Lloyd v. General Motors Corp.
916 A.2d 257 (Court of Appeals of Maryland, 2007)
Walpert, Smullian & Blumenthal, P.A. v. Katz
762 A.2d 582 (Court of Appeals of Maryland, 2000)
Patton v. United States Rugby Football
851 A.2d 566 (Court of Appeals of Maryland, 2004)
Chicago Title Insurance v. Allfirst Bank
905 A.2d 366 (Court of Appeals of Maryland, 2006)
Remsburg v. Montgomery
831 A.2d 18 (Court of Appeals of Maryland, 2003)
Mogavero v. Silverstein
790 A.2d 43 (Court of Special Appeals of Maryland, 2002)