Article

Cyber Security Lesson Brief from the Under Armour Breach

Written by Michael Peters

Topic: Business NetworkingPublished Recently added
No ratings yet1,226 viewsSign in to rate
Last week, athletic apparel manufacturer Under Armour announced that its popular MyFitnessPal weight loss and fitness tracking app had been hacked, compromising 150 million accounts. The Under Armour breach is the largest data breach so far this year and ranks among the top five to date. It also makes a good case study in the do’s and don’ts of enterprise cyber security. Let’s examine the lessons enterprises can take away from the Under Armour breach and its fallout, especially as the deadline for the EU GDPR approaches on May 25. If a breach does happen, prompt disclosure is crucial. The Under Armour breach was discovered on March 25 and disclosed only four days later; compare this to Equifax, which waited several weeks to notify users it had been hacked (and then chose to do so while the nation’s attention was focused on Hurricane Irma), and Uber, which waited more than a year (after attempting to cover the breach up). Prompt disclosure is going to be even more important under the GDPR, which will require organizations to report breaches within 72 hours. Segment your data, and collect only the data you need. The Under Armour breach involved only user names, email addresses, and encrypted passwords. The MyFitnessPal app does not collect Social Security numbers or other government identifiers, and payment information is stored separately, in a part of the system the hackers did not breach. The GDPR requires organizations to bake data security into their products, policies, procedures, and systems from day one. While network segmentation alone does not constitute data security, it goes a long way towards demonstrating due diligence. The GDPR will also require organizations to provide users with a plain-language explanation of what user data they are collecting and what they intend on doing with it. If you don’t absolutely need a particular piece of personal information to conduct your business, don’t collect it. Properly encrypt and salt user passwords. This is where Under Armour dropped the ball. The company states that while “the majority” of the compromised passwords were hashed using the robust bcrypt hashing function, at least some of the passwords were hashed using the notoriously hackable SHA-1 function. Under Armour has not disclosed why only some of the passwords were encrypted with bcrypt. It also has not specified whether the bcrypt-hashed passwords were salted for extra protection, which involves appending random data that is unique to each user and saving it along with their password. To properly protect user passwords and fulfill the security requirements of the GDPR, make sure you are using a robust hashing function and salting user passwords. As strong as bcrypt is, it is not unbreakable; the Ashley Madison hack involved 36 million passwords hashed using bcrypt. Do not reuse passwords. Although the Under Armour breach yielded “only” email addresses and login credentials, not payment data or sensitive personal data like Social Security Numbers, a lot of people use the same set of login credentials on multiple sites. Armed with these credentials, hackers could attempt to use them on banking, shopping, or social media sites and to access victims’ email accounts. This underscores the importance of using a different, strong password for every system, website, and app. If you have a MyFitnessPal account, you should log in and change your password right now. If you reused your MyFitnessPal password on any other sites, make sure to change those, too.

Article author

About the Author

Michael Peters is the CEO of Lazarus Alliance, Inc., the Proactive Cyber Security™ firm, and Continuum GRC. He has served as an independent information security consultant, executive, researcher, and author. He is an internationally recognized and awarded security expert with years of IT and business leadership experience and many previous executive leadership positions. He has contributed significantly to curriculum development for graduate degree programs in information security, advanced technology, cyberspace law, and privacy, and to industry standard professional certifications. He has been featured in many publications and broadcast media outlets as the “Go-to Guy” for executive leadership, information security, cyberspace law, and governance.

Further reading

Further Reading

4 total

Article

Introduction There was a time when the call center was seen as a place where phones rang endlessly and agents simply answered questions. That picture has changed dramatically. Today the modern call center sits at the center of customer experience, quietly coordinating returns, managing fulfillment concerns, and shaping how customers feel about every interaction with a brand. Instead of reacting to problems, teams now guide customers through complex journeys. Their role has gr

February 6, 2026

Article

Choosing the right POS terminal is more important now than ever. With customer expectations rising and payment methods changing quickly, businesses need a device that works fast, stays secure, and handles different payment types. The PAX A30 is a popular Android POS terminal that has gained attention for its modern design and strong features. In this review, we look at how well it performs in real life, what makes it stand out, and whether it can truly be called the best Andr

January 17, 2026

Article

Healthcare organizations face increasing pressure to safeguard medications, vaccines, and biological samples while meeting strict regulatory standards. Even minor temperature fluctuations can compromise drug efficacy, lead to costly waste, or create compliance concerns. As a result, many facilities are turning to advanced Drug Monitoring technologies that provide continuous visibility into storage conditions without relying on manual checks. TempGenius delivers monitoring sol

January 12, 2026

Article

In an ever-evolving global market, staying ahead of cultural trends has become a vital task for businesses and marketers alike. Market updates are crucial for understanding how different sectors are changing, and how these shifts are influencing cultural trends worldwide. From changes in consumer behavior to the rise of new technologies and innovations, market trends in cultural research play a pivotal role in shaping the cultural landscape. Industry news, top culture analysi

January 8, 2026