Under Armour says ~150M MyFitnessPal accounts affected by a data breach in late February; data taken included usernames, email addresses, and hashed passwords
Shares of Under Armour dropped 3.8 percent, before paring losses, after the active-wear company informed users of its online fitness and nutrition website of a data breach.
Context & Ripple Effects
The breach lands on an asset Under Armour assembled during its connected-fitness push: it launched an app platform after buying MapMyFitness, then paid $475M for MyFitnessPal and Endomondo in 2015. Roughly 150 million accounts — usernames, emails, hashed passwords — are now exposed, and the stock fell about 3.8% on the disclosure.
The incident also foreshadows the asset's trajectory: two years later Under Armour exited at $345M to Francisco Partners, below its purchase price, while consumer-marketplace breaches like Poshmark's showed this was a sector-wide exposure rather than a one-off.
First-order effects
- About 150 million MyFitnessPal users must treat their credentials as compromised, and Under Armour absorbs an immediate market penalty — a 3.8% share drop — plus the cost of forced password resets and breach response.
- Under Armour's disclosure obligations kick in immediately, putting its security practices under regulator and press scrutiny at the same moment it is defending a $475M acquisition thesis.
Second-order effects
- The breach hands buyers leverage over Under Armour's digital portfolio: when Francisco Partners eventually priced MyFitnessPal at $345M versus the $475M paid in 2015, a dented trust record was part of the negotiating backdrop.
- Rival consumer apps face the same audit cycle — Poshmark's disclosure of stolen names and encrypted passwords months later shows marketplace and lifestyle platforms being forced into reactive, reputation-costly breach disclosures as a class.
Third-order effects
- If the pattern holds, data-rich consumer acquisitions get structurally repriced for breach liability: the buyer inherits not just users but a security surface whose failure can erase acquisition premium, pushing acquirers toward heavier pre-deal security diligence.
- Hashed-password exposures at this scale normalize credential-stuffing risk across every service where users reused those logins, strengthening the case for regulators to treat large consumer databases as systemic infrastructure rather than private assets.
The trend: Consumer data platforms are learning that breach liability now discounts the very user bases that justified their acquisition prices, from Under Armour's fitness apps to marketplace startups.