Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
adidas

adidas Vendor Cyber Rating & Cyber Score

adidas-group.com

Inspired by our heritage, our brand is rooted in sports and the culture born from it. Headquartered in Herzogenaurach, Germany, we’re a global leader in the sporting goods industry, employing 62,035 worldwide.


adidas A.I CyberSecurity Scoring

adidas
Company Information
Website:http://www.adidas-group.com/
Employees number:95,967
Number of followers:4,824,426
NAICS:
Industry Type:Sporting Goods
Homepage:adidas-group.com
adidas Risk Score (AI oriented)
Between 0 and 549
logo
adidasSporting Goods
Updated:
07/08/2026
533/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
adidas Global Score (TPRM)
xxxx
logo
adidasSporting Goods
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

adidas
adidasCritical
Current Score
533C (CRITICAL)
01000
9 incidents
-27 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
531Before Incident
JULY 2026
637Before Incident
JUNE 2026
634Before Incident
MAY 2026
631Before Incident
APRIL 2026
628Before Incident
MARCH 2026
622Before Incident
FEBRUARY 2026
629Before Incident
Cyber Attack
01 Feb 2026adidas
Adobe, Netflix, Coca-Cola, OpenAI, PepsiCo, Adidas, FIFA and Delta: Phishing poses as big-brand job interview to steal Google accounts

Phishing Campaign Targets Marketing Professionals with Fake Job Offers from Major Brands

615After Incident
CRITICAL-14
PEPDELADOFIFTHEADINETOPE1783376814
Phishing Campaign Targets Marketing Professionals with Fake Job Offers from Major Brands A sophisticated phishing campaign is impersonating over 30 high-profile brands including Adobe, Netflix, Coca-Cola, and OpenAI to steal Google account credentials from marketing professionals under the guise of fake job interviews. The operation leverages legitimate cloud-based platforms, including PeopleForce (an HR service) and Salesforce Marketing Cloud, to lend credibility to its attacks before redirecting victims to malicious landing pages. The threat actor enhances trust by using real recruiters’ names and photos from the impersonated companies. Researcher Will Thomas of Team Cymru identified at least 34 domains mimicking brands across multiple sectors, such as airlines (American Airlines, Delta), food and beverage (Coca-Cola, PepsiCo), tech (Adobe, OpenAI), and entertainment (Netflix, FIFA). The campaign employs nested redirects, routing victims through multiple legitimate services before reaching the phishing page. For example, links in phishing emails initially resolve to exct[.]net (a Salesforce-operated domain) before redirecting to Wise Agent, a real estate CRM, and finally to the fraudulent site. The operation has been active for at least five months, initially using Outlook email addresses branded with the impersonated companies’ names. One phishing email, posing as an Adidas recruiter, invited recipients to schedule a meeting via a link that led to adidas-hiring[.]com. Victims were prompted to sign in with their Google accounts, triggering a fake Google authentication popup a browser-in-the-browser (BitB) technique that mimics a legitimate login window using HTML and CSS. While the exact method of access to the legitimate platforms remains unclear, the abuse does not indicate a compromise of PeopleForce or Salesforce. The attacker may have created genuine accounts or used stolen credentials to configure the redirect chain. A full list of the malicious domains is available in Thomas’ GitHub analysis.
INCIDENT DETAILS -
TYPE
Phishing
MOTIVATION
Credential Theft
IMPACT
Data Compromised: Google account credentialsBrand Reputation Impact: Potential reputational damage to impersonated brandsIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Google account credentialsSensitivity Of Data: HighPersonally Identifiable Information: Potentially (if credentials include PII)
JANUARY 2026
620Before Incident
DECEMBER 2025
642Before Incident
Cyber Attack
29 Dec 2025adidas
Adidas, Heathrow Airport, Harrods, Marks and Spencer, Co-op Group and Jaguar Land Rover: How 2025 Became The Year Of The Cyberattack For British Businesses

617After Incident
CRITICAL-25
ADIHEAHARMARTHEJAG1767017696
2025: A Year of Rising Costs—and Escalating Cyber Threats for UK Businesses As 2025 draws to a close, UK businesses and charities have faced a surge in financial pressures—from soaring employment costs and supply chain disruptions to oil and tariff shocks. Yet, one of the most damaging expenses has been the fallout from cyberattacks, which have hit nearly half of British companies and 30% of charities over the past year. High-profile victims include retail giants Marks & Spencer, Adidas, and the Co-op Group, as well as Heathrow Airport, Harrods, and Jaguar Land Rover (JLR). The public sector hasn’t been spared either: Germany’s parliament and the UK Foreign Office (breached in October) were among those targeted. Attacks ranged from phishing scams to full-scale digital shutdowns, with some incidents costing hundreds of millions. The scale of cybercrime has reached staggering proportions. Cybersecurity Ventures estimates the global cost of cyberattacks in 2025 at $10.5 trillion (£7.8 trillion)—a figure that would rank cybercrime as the world’s third-largest economy, trailing only the US and China. The financial and operational toll underscores the growing threat to organizations across sectors.
INCIDENT DETAILS -
TYPE
phishingdata breachdigital shutdownransomware
IMPACT
Financial Loss: hundreds of millions of poundsOperational Impact: digital shutdown
NOVEMBER 2025
559Before Incident
Breach
24 Nov 2025adidas
Salesforce

Salesforce Data Breach: ShinyHunters Hack via Gainsight Integration

517After Incident
CRITICAL-42
GAI1122911112425
The Salesforce data breach involved the ShinyHunters (UNC6240) hacking group, which exploited stolen OAuth tokens from Salesloft’s GitHub account to infiltrate Drift’s Salesforce integration and subsequently compromise Gainsight, a customer process management platform. The attackers gained unauthorized access to over 200 Salesforce instances, exfiltrating enterprise customer data through third-party service integrations (including HubSpot and Zendesk). While Salesforce revoked access keys and removed affected apps from the AppExchange, the breach exposed sensitive customer data, though the full scope of the leak remains undisclosed. The attack leveraged supply-chain vulnerabilities rather than a direct Salesforce platform flaw. ShinyHunters claimed delayed detection (1–2 weeks post-intrusion) and sought internal accomplices for further exploitation. Salesforce refused ransom demands, but the incident highlights risks in third-party integrations and credential-based attacks.
INCIDENT DETAILS -
TYPE
Data BreachUnauthorized AccessSupply Chain Attack
MOTIVATION
Data TheftExtortionFinancial GainEspionage
IMPACT
Salesforce Instances (200+)GainsightSalesloftDriftHubSpotZendeskTemporary Disruption of Gainsight Apps on Salesforce AppExchangeLimited Functionality of HubSpot/Zendesk ConnectorsRevocation of Access KeysRemoval of Gainsight Apps from AppExchangeInternal Reviews by Affected CompaniesPotential Erosion of Trust in Salesforce EcosystemNegative Publicity for Gainsight, HubSpot, ZendeskHigh (Enterprise Customer Data Exposed)
DATA BREACH
Enterprise Customer DataCRM RecordsIntegration LogsSensitivity Of Data: High (Potential PII, Business-Critical CRM Data)Personally Identifiable Information: Likely (Enterprise Customer Data)
OCTOBER 2025
635Before Incident
SEPTEMBER 2025
632Before Incident
AUGUST 2025
625Before Incident
Breach
01 Aug 2025adidas
Gainsight

Gainsight Unauthorized Salesforce Data Access via Stolen OAuth Tokens

540After Incident
CRITICAL-85
GAI0292402112125
The incident at Gainsight stemmed from a downstream effect of the August 2025 Salesloft breach, where the Scattered Lapsus$ Hunters group stole OAuth tokens tied to Salesloft’s Drift AI chat integration with Salesforce. These tokens granted unauthorized API access to 760 Salesforce instances, leading to the exfiltration of 1.5 billion records, including passwords, AWS keys, and Snowflake tokens.A subgroup, ShinyHunters, exploited the stolen credentials to breach Gainsight’s systems, extracting customer contact data (names, business emails, phone numbers, regional details), licensing information, and support case contents. Salesforce responded by revoking all active Gainsight-associated tokens and temporarily removing its apps from the AppExchange to mitigate further exposure. While Salesforce clarified that its platform itself was not vulnerable, the breach originated from Gainsight’s external app connections, compromising sensitive corporate and customer data across hundreds of organizations.
INCIDENT DETAILS -
TYPE
Data BreachUnauthorized AccessCredential Theft
MOTIVATION
Data TheftFinancial Gain (Potential Dark Web Sale)Reputation Damage
IMPACT
Salesforce Instances (760 in Salesloft breach)Gainsight-published ApplicationsToken RevocationAppExchange RemovalCustomer NotificationsLoss of TrustNegative PublicityBusiness Contact Details Exposed
DATA BREACH
Business Contact Details (Names, Emails, Phone Numbers)Licensing InformationSupport Case ContentsRegional/Location DetailsPasswords (Salesloft Breach)AWS Keys (Salesloft Breach)Snowflake Tokens (Salesloft Breach)1.5 Billion (Salesloft Breach)Undisclosed (Gainsight Breach)Moderate to High (Business PII, Credentials, API Keys)Business PII (Names, Emails, Phone Numbers)
JUNE 2025
660Before Incident
Breach
10 Jun 2025adidas
Adidas

Adidas Customer Data Breach

618After Incident
CRITICAL-42
ADI852090225
Adidas disclosed a cyber-attack in which hackers compromised the personal data of customers who had previously contacted the company’s customer service helpdesk. While the breach did not expose passwords, credit card details, or other payment information, it involved unauthorized access to personal data, raising concerns over potential misuse for identity fraud or targeted phishing. The company notified affected individuals via email, advising them on precautionary measures such as password changes and monitoring for suspicious activity. The incident highlights the risks of data exposure even when financial details remain secure, as stolen personal information can still be leveraged for secondary attacks like credential stuffing or social engineering scams. Adidas emphasized that only a subset of customers—those with prior helpdesk interactions—were impacted, but the breach underscores the broader vulnerability of customer support systems as entry points for cybercriminals.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Personal information (e.g., names, contact details)Brand Reputation Impact: Potential reputational harm due to loss of customer trustIdentity Theft Risk: Moderate (personal data exposed, but no financial or payment data)Payment Information Risk: None (payment data not compromised)
DATA BREACH
Personal information (e.g., names, contact details)Sensitivity Of Data: Moderate (no financial or payment data exposed)Data Exfiltration: Yes (personal data stolen)Personally Identifiable Information: Yes (limited to non-financial PII)
MAY 2025
673Before Incident
Cyber Attack
27 May 2025adidas
Adidas

Adidas Data Breach

659After Incident
CRITICAL-14
ADI845052725
Adidas disclosed a data breach where attackers hacked a customer service provider and stole some customers' data, including contact information. The stolen information did not include payment-related information or passwords. Adidas immediately contained the incident and launched an investigation, collaborating with information security experts. The company notified relevant authorities and will alert affected customers. Adidas has not revealed further details about the incident, including the name of the impacted service provider, the detection date, the number of individuals affected, or if its own network was compromised.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
contact information
DATA BREACH
Type Of Data Compromised: Contact informationSensitivity Of Data: Medium
MAY 2025
799Before Incident
Breach
01 May 2025adidas
Adidas and Double D: Prolific hacking gang claims Adidas Extranet, promises more

Lapsus$ Claims Breach of Adidas Extranet

671After Incident
CRITICAL-128
ADIDOU1771324504
Lapsus$ Claims Breach of Adidas Extranet, But Scope Remains Disputed The hacking group Lapsus$ has claimed responsibility for breaching the Adidas Extranet a secure portal used by the company’s business partners, suppliers, and employees allegedly exposing around 815,000 rows of data. The compromised information reportedly includes usernames, passwords, and technical details, though only 130 accounts appear to have been directly affected. Lapsus$ suggested the breach was part of a larger operation, hinting at an upcoming "something bigger." However, cybersecurity researchers at Cybernews dispute the severity of the incident, arguing that the group exaggerated its impact. The leaked data, they say, primarily originates from Double D, a French Adidas licensee specializing in combat sports, rather than Adidas itself. The exposed records include personal details such as names, email addresses, passwords, birthdates, and company information. While Lapsus$ is considered one of the most active English-speaking cybercrime groups alongside Scattered Spider and ShinyHunters analysts note that the breach may have been inflated for notoriety. The group also claimed to possess 420GB of Adidas-related data tied to the French market, though researchers found the dataset included irrelevant entries, such as SQL commands. Adidas confirmed a third-party breach in May 2025, though the connection to this incident remains unclear. The potential for phishing attacks using the leaked data persists, but experts caution against overstating the breach’s scale.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Notoriety, Potential Financial Gain
IMPACT
Data Compromised: Usernames, passwords, technical details, names, email addresses, birthdates, company informationSystems Affected: Adidas Extranet (third-party portal)Brand Reputation Impact: Potential reputational damage due to data exposureIdentity Theft Risk: High (due to PII exposure)
DATA BREACH
Type Of Data Compromised: Personal Identifiable Information (PII), Credentials, Technical DetailsNumber Of Records Exposed: 815,000 rows (130 accounts directly affected)Sensitivity Of Data: High (PII, passwords)Personally Identifiable Information: Names, email addresses, birthdates, company information
NOVEMBER 2023
794Before Incident
Ransomware
01 Nov 2023adidas
Nike, Adidas and Under Armour: Nike and Under Armour’s Potential Ransomware Attacks: What to Know

Nike and Under Armour Hit by Ransomware Attacks

692After Incident
CRITICAL-102
NIKADIUND1769229125
Nike and Under Armour Hit by Ransomware Attacks as Cyber Threats Target Major Brands Nike and Under Armour have become the latest high-profile victims of ransomware attacks, with cybercriminals leveraging extortion tactics to demand payments. The incidents highlight the growing threat to global apparel brands, following similar breaches at Adidas and The North Face last year. Nike is currently investigating a potential cybersecurity incident after the ransomware group WorldLeaks claimed responsibility, threatening to release stolen data by 6 p.m. Saturday unless a ransom is paid. While the full scope of compromised data remains unclear, ransomware attacks typically involve customer details such as names, emails, and birthdates. Nike confirmed it is actively assessing the situation, stating, “We always take consumer privacy and data security very seriously.” Under Armour, meanwhile, disclosed a breach that occurred in November 2023, with the ransomware gang Everest taking credit. Initial reports suggested 72 million email addresses were exposed, but a source close to the investigation disputed this, indicating only a “fraction” of that number was compromised. Under Armour confirmed the breach but emphasized that its e-commerce platform (UA.com) and payment systems remain unaffected. The company is working with external cybersecurity experts to determine the full impact. These attacks follow a pattern of escalating cyber threats against major fashion and apparel brands. Last year, Adidas confirmed a breach via a third-party customer service provider, exposing consumer contact details but no financial data. The North Face also faced a credential-stuffing attack, though payment information remained secure. International brands, including Dior, Harrods, Kering, and Marks & Spencer, have also been targeted in recent years. As ransomware groups continue to pressure victims with public leaks and countdown threats, the incidents underscore the persistent risks to corporate data security in the retail sector.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Extortion
IMPACT
Data Compromised: Customer details such as names, emails, and birthdates (Nike); email addresses (Under Armour)Payment Information Risk: None (Under Armour)
DATA BREACH
Customer details (names, emails, birthdates)Email addressesNumber Of Records Exposed: 72 million (disputed, likely a fraction)Sensitivity Of Data: Personally identifiable informationData Exfiltration: Threatened by WorldLeaks (Nike)Personally Identifiable Information: Yes
JUNE 2018
807Before Incident
Breach
01 Jun 2018adidas
adidas

Adidas Data Breach

766After Incident
CRITICAL-41
ADI1641311223
The athletic apparel manufacturer Adidas declared that it has opened an inquiry following information about a possible security breach that might affect millions of its clients in the United States. An attacker may have gained unauthorised access to client data, including email addresses, encrypted passwords, and addresses, according to the German sportswear manufacturer. Contact details, usernames, and encrypted passwords are among the limited material, according to the early inquiry. Adidas has no grounds to think that the consumers' payment card or fitness information was compromised.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
email addressesencrypted passwordsaddresses
DATA BREACH
email addressesencrypted passwordsaddressesData Encryption: encrypted passwordsemail addressesaddresses

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for adidas ?
?
What was adidas's A.I Rankiteo Cyber Score in July 2026 ?
?
What was adidas's A.I Rankiteo Cyber Score in June 2026 ?
?
What was adidas's A.I Rankiteo Cyber Score in May 2026 ?
?
What was adidas's A.I Rankiteo Cyber Score in April 2026 ?
?
What was adidas's A.I Rankiteo Cyber Score in March 2026 ?
?
What was adidas's A.I Rankiteo Cyber Score in February 2026 ?
?
What was adidas's A.I Rankiteo Cyber Score in January 2026 ?
?
What was adidas's A.I Rankiteo Cyber Score in December 2025 ?
?
What was adidas's A.I Rankiteo Cyber Score in November 2025 ?
?
What was adidas's A.I Rankiteo Cyber Score in October 2025 ?
?
What was adidas's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on adidas's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with adidas ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view adidas's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
adidas Cyber Scoring History | Rankiteo