Adidas discloses customer data breach at third-party service provider

Organization
Adidas
Exploit
Third-Party Data Breach
Industry
Retail

Adidas said on 23 May 2025 that an unauthorized party had obtained customer data through a third-party provider that handles customer service work for the sportswear company. The German group did not name the provider or say when the intrusion occurred.

The affected records consisted mainly of contact information belonging to people who had previously contacted the Adidas help desk. The company said the data did not include passwords, credit card numbers or any other payment-related information. Adidas did not itemize which contact fields were involved, and the outlets covering the disclosure described them only as contact details.

Adidas said it moved immediately to contain the incident and opened a comprehensive investigation with outside information security specialists. It said it was in the process of informing potentially affected consumers along with data protection and law enforcement authorities as required by law. The company did not publish a figure for the number of people involved or identify the countries affected.

The disclosure followed two other Adidas incidents earlier in May 2025 involving customers of its operations in South Korea and Turkiye. PYMNTS reported that it was not clear whether those events were connected to the customer service provider breach, and Adidas did not publicly link them.

Sources