Skip to content
All resources
Cybersecurity Intel · № 02 · 19 January – 1 February 2026

No encryption required: the fortnight of the mega-leak

72 million Under Armour records surface online, an extortion crew dumps SoundCloud, Crunchbase and Betterment data after failed negotiations, and 1.4 TB of Nike R&D walks out the door. Not one headline incident used encryption, and a state actor weaponised an Office zero-day in days.

Published 2 February 2026 By Blacklight Threat Intelligence Classification TLP:CLEAR · Public
72M
Under Armour customer records posted on a hacking forum
1.4TB
Nike internal R&D and manufacturing data published by extortionists
677
Organisations claimed on ransomware leak sites in January, a record 58 active groups
9
CVEs added to CISA KEV in the fortnight, incl. an Office zero-day

Executive summary

  • Leak-based extortion owned the fortnight. Everest, WorldLeaks and a mass-leak crew monetised months-old intrusions at Under Armour, Nike, SoundCloud, Crunchbase and Betterment by publishing data after failed negotiations. No encryptor was deployed in any headline incident.
  • Speed-to-weaponisation kept collapsing. A SmarterMail authentication bypass was exploited roughly 48 hours after its patch, and Russia's APT28 weaponised a Microsoft Office zero-day within three days of disclosure, with attack infrastructure registered a fortnight before the CVE was public.
  • Stolen R&D is the quiet story. The Nike leak was not customer PII but 188,000 files of design workflows, bills of materials and factory audits: intellectual property and supply-chain exposure that outlives any credit-monitoring offer.

Key findings

22 January 2026 ATT&CK T1657

72 million Under Armour records surface from a November intrusion

A dataset of 72 million email addresses with names, dates of birth and purchase information was posted to a hacking forum, stemming from a November 2025 intrusion claimed by the Everest group. Under Armour said payment systems and password stores were unaffected. Exfiltrated data is a liability with a long fuse: the crisis arrived months after the breach.

22 – 27 January 2026 ATT&CK T1078

Mass-leak spree hits SoundCloud, Crunchbase and Betterment

After failed pay-or-leak extortion, one crew dumped data from three platforms in a week: 29.8 million SoundCloud accounts (about 20% of its user base) obtained via an internal service dashboard, plus alleged datasets from Crunchbase and Betterment. Emails and profile data were exposed rather than passwords, exactly the raw material for downstream phishing.

22 – 24 January 2026 IP theft

1.4 TB of Nike design and manufacturing data published

The WorldLeaks extortion group published roughly 188,000 files pointing to design and manufacturing workflows: technical packs, bills of materials, prototypes, schematics, factory audits and partner information. When the loot is R&D rather than PII, the damage is competitive and contractual, and it cannot be rotated like a password.

26 – 29 January 2026 CVE-2026-21509 · KEV

APT28 weaponises an Office zero-day within days of disclosure

Microsoft disclosed an Office security-feature bypass with in-the-wild exploitation on 26 January; by 29 January Russia's APT28 was exploiting it against more than 60 addresses at Ukrainian government authorities, with malicious documents triggering WebDAV chains that deploy stealers and implants. Researchers found the group's infrastructure was registered two weeks before public disclosure.

17 – 27 January 2026 CVE-2026-23760 · KEV

SmarterMail bypass goes from patch to ransomware staging in days

An authentication bypass in SmarterMail's password-reset API lets unauthenticated attackers seize the administrator account with one crafted request, then reach system-level code execution. Exploitation began roughly 48 hours after the patch, and a China-based actor was later observed using it to stage Warlock ransomware behind legitimate remote-access tooling.

The broader pattern

  • Exfiltrated data detonates on the attacker's schedule. Every mega-leak this fortnight monetised an old intrusion; incident response has to treat stolen data as a live liability, not a closed ticket.
  • Internet-facing mail and admin planes are the front door. SmarterMail joins the pattern of edge services exploited within hours of disclosure: patch SLAs for these systems are now measured in days, not cycles.
  • Brussels moved to match the threat. The European Commission proposed the biggest overhaul of EU cybersecurity law since 2019: a revised Cybersecurity Act, NIS2 amendments, a unified incident-notification platform and a sharply expanded ENISA.

Sector lens

Retail & luxury
Under Armour and Nike in one fortnight: consumer brands are being monetised for both customer data and product IP. Assume your design and supplier documents are as targeted as your CRM.
Manufacturing
The Nike leak exposed factory audits and bills of materials, a supply-chain reconnaissance gift. Partner and factory data deserves crown-jewel handling.
Financial services
The Betterment claim and the SoundCloud-scale leaks feed credential-stuffing and phishing waves; watch for reused-password attacks against customer logins in the weeks after any mega-leak.
Government
APT28's three-day weaponisation of an Office zero-day against ministry inboxes shows patch cadence for productivity software is now a national-security control.

Suggested priorities to consider

Based on this fortnight's public reporting, these are the areas we would review first. Weigh each against your own environment and risk profile.

01

Patch the Office zero-day and the SmarterMail bypass immediately. Both are on KEV with confirmed exploitation; for SmarterMail, audit administrator accounts for unexplained password resets.

02

Hunt for WebDAV connections spawned by Office processes. The APT28 chain opens attacker WebDAV shares from document lures; that behaviour is rare and highly detectable.

03

Reassess where product IP and factory documentation live. Design systems, PLM and supplier portals need the same monitoring as customer databases; the Nike leak was all R&D.

04

Prepare a mega-leak response play distinct from ransomware. No encryptor means no outage, but customer notification, credential-stuffing defence and phishing surges still land on you.

05

Track the EU Cybersecurity Package if you operate in Europe. Certification presumption, supply-chain obligations and a unified notification platform will reshape compliance workloads from this year.

These suggestions are general commentary based on publicly reported events, provided for information only. They are not tailored security advice and may not suit your environment; validate against your own risk assessment and change-control processes before acting.

How Blacklight handles this

Every headline this fortnight was data leaving quietly, not systems going down. Blacklight baselines data movement per identity and per application across SaaS, cloud and on-premise estates, so a dashboard account pulling twenty times its normal volume or an R&D share streaming outbound is investigated and contained autonomously, before the negotiation email arrives, with the full reasoning trail preserved for regulators and counsel.

Book a Demo

Sources & methodology

Primary public sources this issue: CISA Known Exploited Vulnerabilities catalog (entries of 23 and 26 January 2026) · Microsoft advisory for CVE-2026-21509 · vendor research on SmarterMail CVE-2026-23760 exploitation (Huntress, Censys, ReliaQuest) · CERT-UA and security-press reporting on APT28 activity · public breach disclosures and leak-site monitoring (Have I Been Pwned, security press), 19 January – 1 February 2026 · European Commission EU Cybersecurity Package (20 January 2026) · Breachsense ransomware leak-site statistics, January 2026 · MITRE ATT&CK v15.

Methodology. Findings are compiled from public reporting and Blacklight Threat Intelligence monitoring for the stated window, mapped to MITRE ATT&CK where applicable. Aggregate platform observations, where cited, are anonymised across the Blacklight customer base and never identify a customer environment. Corrections: intel@blacklightai.com.

Related reading

Blacklight AI · Cybersecurity Intel · № 02 TLP:CLEAR
Get started

See what truly predictive
security looks like.

Sixty minutes, under your control. See the platform run on a pre-loaded, anonymised environment, watch one real incident handled end to end, and map it to your sector, without connecting a single data source.

A typical demo
  • 01 A live tour on a pre-loaded, anonymised environment, running from minute one, not slides.
  • 02 One real incident, detected, investigated and contained, written up as a regulator-ready report.
  • 03 Mapped to your world: your sources, your sector's threats and your regulators.
  • 04 The questions your board will ask: deployment, residency, security, integrations and TCO.

No connectors or data required from you. A proof-of-value on your own telemetry is the next step, never the ask on a first call.