Nike investigates data breach after extortion gang leaks files

Nike

Nike is investigating what it described as a “potential cyber security incident” after the World Leaks ransomware gang leaked 1.4 TB of files allegedly stolen from the sportswear giant.

“We always take consumer privacy and data security very seriously,” the company told BleepingComputer in an email statement. “We are investigating a potential cyber security incident and are actively assessing the situation.”

This comes after the extortion group added Nike to its dark web data-leak site, claiming it stole nearly 190,000 files containing corporate data providing information on Nike’s business operations.

Wiz

Before this article was published, World Leaks removed the Nike entry from its leak, suggesting that it may be negotiating with the company or that Nike has already paid a ransom to have the allegedly stolen documents removed.

However, Nike has yet to confirm the extortion gang’s claims of data theft, and BleepingComputer couldn’t independently verify whether the leaked files contained legitimate data.

Nike entry on World Leaks' leak website
Nike’s entry on World Leaks’ leak website (BleepingComputer)

​World Leaks is believed to be a rebrand of the Hunters International ransomware, following a switch from file encryption to data theft and extortion-only attacks in January 2025, citing concerns that ransomware operations were becoming too risky and were no longer profitable.

Hunters International emerged in late 2023 and was itself flagged as a possible Hive ransomware rebrand due to code similarities, after claiming responsibility for over 280 attacks.

The list of victims includes the U.S. Marshals Service, the Indian multinational tech giant Tata Technologies, the Japanese optics giant Hoya, the North American automobile dealership AutoCanada, and the U.S. Navy contractor Austal USA.

Since it surfaced, World Leaks has also published data stolen from dozens of organizations worldwide on its data leak site.

In July, World Leaks affiliates were linked to the breach of one of Dell’s product demonstration platforms and to the exploitation of end-of-life SonicWall SMA 100 devices to install custom OVERSTEP rootkit malware on compromised systems.


tines

The future of IT infrastructure is here

Modern IT infrastructure moves faster than manual workflows can handle.

In this new Tines guide, learn how your team can reduce hidden manual delays, improve reliability through automated response, and build and scale intelligent workflows on top of tools you already use.

Sergiu Gatlan
Read More

Latest

Newsletter

Don't miss

Family Business? Tee Grizzley Reacts After His Mom Accuses Him Of Leaving Her To Struggle (PHOTOS)

Y’all… it looks like some family tension might be brewing behind the scenes involving Tee Grizzley and his mom. What seemed like a regular social media post quickly turned into something deeper. And now, folks are side-eyeing the situation and wondering what’s really going on. RELATED: Tee Grizzley Shares A Message For Artists After His

SoE necessary but not sufficient, business leaders say

PE­TER CHRISTO­PHER Se­nior Mul­ti­me­dia Re­porter pe­ter.christo­pher@guardian.co.tt Heavy hand­ed but nec­es­sary giv­en the state of crime in T&T. This was a com­mon as­sess­ment from var­i­ous busi­ness groups when asked for their per­spec­tive on the lat­est de­c­la­ra­tion of a state of emer­gency in the coun­try. The T&T Cham­ber of In­dus­try and Com­merce, in a re­leased is­sued yes­ter­day

The Big Business of Carolyn Bessette-Kennedy

Can a nine-episode limited series really impact an entire season of shopping trends? Today brands are experiencing—and chasing—the “Carolyn Bessette-Kennedy effect” as a result of Ryan Murphy’s Love Story. And in many cases, it’s more pervasive than they could have prepared for. The FX series, based on the relationship between John F. Kennedy Jr. and