Friday, September 11, 2026

Nike Alleged Breach: Threat Actors Claim Leak of Millions of Customer Records

A threat actor on a prominent cybercrime forum has claimed responsibility for leaking data allegedly belonging to Nike and Alcon, posting the purported datasets for download.

The claims, currently unverified, suggest a significant breach affecting millions of records across both organizations.

Nike Alleged Breach

According to the forum post, the threat actor alleges the Nike-related leak contains customer data spanning eight figures in total line count, meaning tens of millions of individual records.

The actor claims the dataset includes recent customer registrations and order-related information dated from 2026, indicating the data may be relatively fresh rather than recycled from older breaches.

The leaked material is reportedly packaged as a 7z archive containing CSV files with user data. The 7z format, known for its high compression ratios, is commonly used by threat actors to package large datasets for easier distribution on forums and marketplaces.

If accurate, the inclusion of order-related records could mean exposed data spans purchase history, account details, and potentially personally identifiable information (PII) tied to Nike’s customer base.

The official alert detailing the sample file trees, metadata markers, and target profiles was disseminated natively by Dark Web Informer (@DarkWebInformer) on X.

The same actor claims a parallel leak involving Swiss eye-care company Alcon, describing a broader and more varied dataset. This dual-targeting approach shadows an ongoing surge in corporate extortion campaigns throughout 2026.

For example, security analysts are closely tracking modern initial access vectors, such as how threat groups target critical vulnerabilities in edge infrastructure to pivot into corporate databases. The alleged Alcon leak reportedly includes:

  • User Account Data: Granular login credentials and customer portal metrics.
  • MARLO Signup Records: Patient and specialty portal registration profiles.
  • Salesforce Integrations: Vendor and supplier data tied directly to internal supply chain channels.
  • Development Assets: Internal conversation logs, order histories, and proprietary source code files.
Alleged Victim TargetPurported Asset Class ExposedFile Structure FormatReported Volumetric Scale
NikeCustomer PII, registration dates, order histories7z compressed archive (CSV logs)Tens of millions of rows
AlconSource code, Salesforce logs, customer signupsBroad development directory treeCombined uncompressed 40GB+

The presence of source code alongside customer and supplier data, if verified, would suggest a more extensive compromise potentially involving internal systems rather than just customer-facing databases.

To isolate these multi-stage pivot tactics, enterprises have increasingly turned to AI-driven network detection systems to block lateral unauthorized traffic before data exfiltration occurs.

Salesforce data exposure is particularly notable given the platform’s widespread use in enterprise CRM and supply chain management, raising questions about whether the breach originated from a third-party integration or direct system access.

The threat actor claims the combined Nike and Alcon datasets total over 40GB uncompressed, a substantial volume that, if legitimate, would place this among the more significant retail and healthcare-adjacent data leaks disclosed this year. Neither company has issued a public statement confirming or denying the claims as of this writing.

As with many forum-based breach claims, independent verification remains pending. Threat actors frequently exaggerate scope, recycle old data, or fabricate claims entirely to build reputation or attract buyers.

Organizations named in such claims are advised to conduct internal audits, monitor for anomalous access patterns, and prepare incident response protocols even while verification is ongoing.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News