Adidas disclosed in May 2025 that an unauthorized party accessed customer information held by a third-party customer-service provider. The company said the affected records related to people who had contacted Adidas support, and that passwords, credit-card data, payment information and other financial information were not involved. The incident still creates a realistic risk of targeted phishing and impersonation.
What Adidas confirmed
Adidas said a threat actor obtained company data through a breach at an outside customer-service provider. The records were associated with customers who had interacted with the Adidas help desk, rather than evidence of a compromise of Adidas’ core payment infrastructure.
Dark Reading reported the incident on May 27, 2025, after Adidas notified potentially affected people and authorities. Adidas said it began an investigation with outside information-security experts, worked to determine the scope, started notifying consumers and informed relevant data-protection and law-enforcement agencies as required.
Adidas’ U.S. data-security notice says customer notifications were being sent by email and SMS. Because those same channels can be imitated, an Adidas-branded message should not be trusted solely because it appears to be a breach notice.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
- Men's stylish, slip-on sneakers
- SNUG FIT: Adjustable laces provide a secure fit
- FLEXIBLE UPPER: Soft textile upper is stretchy and comfortable
- CUSHIONED MIDSOLE: Cloudfoam midsole for step-in comfort and superior cushioning
- MADE IN PART WITH RECYCLED CONTENT: This product features at least 20% recycled materials. By reusing materials that have already been created, we help to reduce waste and our reliance on finite resources and reduce the footprint of the products we make
What information was involved?
| Potentially affected | Adidas says not affected |
|---|---|
| Information associated with customer-service or help-desk interactions | Passwords |
| Customer contact information described in public reporting | Credit-card information |
| The exact data fields have not been fully published | Payment-related and other financial information |
Public reporting has characterized the material as contact information such as names, email addresses and telephone numbers. Adidas’ accessible notice does not provide a complete field-by-field inventory, so it would be inaccurate to assume that home addresses, order histories, account IDs, birth dates or identity documents were included.
The confirmed exclusions matter: Adidas says passwords, credit-card information, payment information and other financial information were not affected. That statement should be read as the company’s description of the incident, not as proof that no later phishing or fraud can occur.
Who may be affected?
The clearest potentially affected group is people who contacted an Adidas customer-service help desk during the period covered by the provider’s records. That could include customers who opened support tickets or used email, chat, telephone or another support channel.
- Customers whose support interaction was stored by the breached provider.
- People whose contact details appeared in a customer-service record.
- Customers in different regional Adidas operations, if those records were handled by the same provider.
The public information does not show that every Adidas customer was affected. Having an Adidas account or making a purchase alone is not evidence that a person was in the affected population.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #2
- Classic skate-inspired sneakers for stylish everyday wear
- FLEXIBLE UPPER: Soft textile upper is stretchy and comfortable
- REINFORCED TOE: Added protection in the toe area offers extra durability
- TEXTILE LINING: Textile lining provides a soft, comfortable feel
- RUBBER OUTSOLE: The rubber outsole provides outstanding grip and a sleek, low-profile look
Separate privacy-sector reporting indicated that Adidas Türkiye may have been involved, but the available global and U.S. notices do not establish a definitive country-by-country list. A Turkish privacy-law bulletin can be reviewed at this link; it should not be treated as a complete statement of Adidas’ worldwide scope.
What remains unknown
- Adidas has not publicly stated a total number of affected people in the cited notices.
- The identity of the customer-service provider has not been disclosed.
- The date of the provider’s compromise, Adidas’ detection date and the period covered by the records have not been published.
- The attack technique—such as credential theft, vulnerability exploitation, ransomware or insider access—has not been identified.
- No reliable public source identifies the attacker.
- The public material does not establish whether information was posted publicly, sold or used for fraud.
“Disclosed in May 2025” is therefore more precise than saying the breach occurred in May. The disclosure date and the underlying compromise date may be different.
Has Adidas identified the attacker?
No. The available reporting says it was unclear who was behind the incident. References to other retail attacks, including incidents associated with groups such as Scattered Spider or DragonForce, do not establish a connection to Adidas. Any such attribution should be treated as unverified unless Adidas, law enforcement or a credible incident-response investigation confirms it.
What Adidas customers should do
Verify any notification independently
- Do not click a link in an unexpected Adidas email or text.
- Open a browser and type the address for the official Adidas data-security page yourself.
- Use Adidas’ official contact page to ask whether a message or case number is genuine.
- Do not provide a password, full payment-card number, Social Security number, government-ID details or a one-time authentication code in response to an unsolicited message.
- Keep the sender information, message headers and case number if you need to report a suspicious notice.
Expect targeted phishing
If you contacted Adidas support, criminals may use that fact to make a scam sound credible. Be cautious of messages about refunds, order problems, delivery issues, account verification or a request to “secure” your Adidas account. Treat phone calls claiming to be from Adidas as untrusted until you independently verify the caller through the company’s published channels.
Recommended Free Tools
Rank #3
- CLEAN LINE SILHOUETTE: Contemporary profile delivers casual confidence for modern wardrobes; streamlined shape creates perfect building blocks for countless outfit combinations from jeans to dresses across seasons and occasions
- POLISHED AND DURABLE: Balanced material blend achieves polished appearance with practical resilience; the combination creates leather sneakers for women who value sophisticated styling and crisp presentation that withstands regular wear
- SUPPORTIVE ALL DAY: Time-tested construction ensures longevity and reliable performance; the cupsole foundation provides steady footing across surfaces, making these the perfect casual sneakers for women with unpredictable schedules
- RETRO T-TOE ACCENT: Subtle adidas heritage detail adds dimensional character; this design element connects to athletic history while keeping the overall look fresh for women who appreciate thoughtful details
- SECURE LACE ADJUSTMENT: Traditional closure enables personalized customization; 3-Stripes branding enhances the unmistakable identity, creating ladies' sneakers that move confidently through fast-paced days
Warning signs include requests for payment, attachments, software installation, urgent account-closure threats, links to look-alike domains or requests for government-identification numbers.
Use proportionate password precautions
Adidas said passwords were not part of the affected data. You do not need to change every password solely because of this incident. Change an Adidas password if you reused it elsewhere, receive a legitimate and independently verified account-security notice, or suspect account takeover. Use a unique password and multifactor authentication wherever available.
Monitor payment accounts normally
Because Adidas said payment and financial information were not affected, canceling cards solely because of this incident is not warranted by the confirmed facts. Continue ordinary account monitoring and report any unauthorized transaction directly to the card issuer or financial institution.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Why a third-party breach matters
Customer-service vendors may store support transcripts, contact details and case histories. Adidas’ 2025 annual-report material says customer-service providers process consumer complaints and requests under contractual obligations and internal due-diligence processes. It also describes assessing whether a reported security incident is likely to affect personal data and individuals.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Rank #4
- Classic skate-inspired sneakers for stylish everyday wear
- FLEXIBLE UPPER: Soft textile upper is stretchy and comfortable
- REINFORCED TOE: Added protection in the toe area offers extra durability
- TEXTILE LINING: Textile lining provides a soft, comfortable feel
- RUBBER OUTSOLE: The rubber outsole provides outstanding grip and a sleek, low-profile look
That context does not prove a specific control failure in this incident. It illustrates the supply-chain risk: a vendor can hold valuable customer records, and a compromise there can require the brand to investigate, notify consumers and coordinate with regulators even when the initial intrusion did not occur in the brand’s own systems. Contact information is less sensitive than payment credentials, but it can still support convincing social-engineering attacks.
Exposure is not the same as misuse
The confirmed fact is unauthorized access to customer information. That does not by itself prove that every record was copied, publicly released, sold, used for fraud or used to take over an account. The available sources do not establish the extent of any later criminal use.
Bottom line
Adidas customers who contacted support should be alert for highly tailored phishing and impersonation attempts. The company’s published account says passwords, card details and other financial information were not affected, and the public material does not support claims that millions of customers were involved or that a particular threat group was responsible.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.




