No encryption required: the fortnight of the mega-leak
72 million Under Armour records surface online, an extortion crew dumps SoundCloud, Crunchbase and Betterment data after failed negotiations, and 1.4 TB of Nike R&D walks out the door. Not one headline incident used encryption, and a state actor weaponised an Office zero-day in days.
Executive summary
- Leak-based extortion owned the fortnight. Everest, WorldLeaks and a mass-leak crew monetised months-old intrusions at Under Armour, Nike, SoundCloud, Crunchbase and Betterment by publishing data after failed negotiations. No encryptor was deployed in any headline incident.
- Speed-to-weaponisation kept collapsing. A SmarterMail authentication bypass was exploited roughly 48 hours after its patch, and Russia's APT28 weaponised a Microsoft Office zero-day within three days of disclosure, with attack infrastructure registered a fortnight before the CVE was public.
- Stolen R&D is the quiet story. The Nike leak was not customer PII but 188,000 files of design workflows, bills of materials and factory audits: intellectual property and supply-chain exposure that outlives any credit-monitoring offer.
Key findings
72 million Under Armour records surface from a November intrusion
A dataset of 72 million email addresses with names, dates of birth and purchase information was posted to a hacking forum, stemming from a November 2025 intrusion claimed by the Everest group. Under Armour said payment systems and password stores were unaffected. Exfiltrated data is a liability with a long fuse: the crisis arrived months after the breach.
Mass-leak spree hits SoundCloud, Crunchbase and Betterment
After failed pay-or-leak extortion, one crew dumped data from three platforms in a week: 29.8 million SoundCloud accounts (about 20% of its user base) obtained via an internal service dashboard, plus alleged datasets from Crunchbase and Betterment. Emails and profile data were exposed rather than passwords, exactly the raw material for downstream phishing.
1.4 TB of Nike design and manufacturing data published
The WorldLeaks extortion group published roughly 188,000 files pointing to design and manufacturing workflows: technical packs, bills of materials, prototypes, schematics, factory audits and partner information. When the loot is R&D rather than PII, the damage is competitive and contractual, and it cannot be rotated like a password.
APT28 weaponises an Office zero-day within days of disclosure
Microsoft disclosed an Office security-feature bypass with in-the-wild exploitation on 26 January; by 29 January Russia's APT28 was exploiting it against more than 60 addresses at Ukrainian government authorities, with malicious documents triggering WebDAV chains that deploy stealers and implants. Researchers found the group's infrastructure was registered two weeks before public disclosure.
SmarterMail bypass goes from patch to ransomware staging in days
An authentication bypass in SmarterMail's password-reset API lets unauthenticated attackers seize the administrator account with one crafted request, then reach system-level code execution. Exploitation began roughly 48 hours after the patch, and a China-based actor was later observed using it to stage Warlock ransomware behind legitimate remote-access tooling.
The broader pattern
- Exfiltrated data detonates on the attacker's schedule. Every mega-leak this fortnight monetised an old intrusion; incident response has to treat stolen data as a live liability, not a closed ticket.
- Internet-facing mail and admin planes are the front door. SmarterMail joins the pattern of edge services exploited within hours of disclosure: patch SLAs for these systems are now measured in days, not cycles.
- Brussels moved to match the threat. The European Commission proposed the biggest overhaul of EU cybersecurity law since 2019: a revised Cybersecurity Act, NIS2 amendments, a unified incident-notification platform and a sharply expanded ENISA.
Sector lens
Suggested priorities to consider
Based on this fortnight's public reporting, these are the areas we would review first. Weigh each against your own environment and risk profile.
Patch the Office zero-day and the SmarterMail bypass immediately. Both are on KEV with confirmed exploitation; for SmarterMail, audit administrator accounts for unexplained password resets.
Hunt for WebDAV connections spawned by Office processes. The APT28 chain opens attacker WebDAV shares from document lures; that behaviour is rare and highly detectable.
Reassess where product IP and factory documentation live. Design systems, PLM and supplier portals need the same monitoring as customer databases; the Nike leak was all R&D.
Prepare a mega-leak response play distinct from ransomware. No encryptor means no outage, but customer notification, credential-stuffing defence and phishing surges still land on you.
Track the EU Cybersecurity Package if you operate in Europe. Certification presumption, supply-chain obligations and a unified notification platform will reshape compliance workloads from this year.
These suggestions are general commentary based on publicly reported events, provided for information only. They are not tailored security advice and may not suit your environment; validate against your own risk assessment and change-control processes before acting.
Every headline this fortnight was data leaving quietly, not systems going down. Blacklight baselines data movement per identity and per application across SaaS, cloud and on-premise estates, so a dashboard account pulling twenty times its normal volume or an R&D share streaming outbound is investigated and contained autonomously, before the negotiation email arrives, with the full reasoning trail preserved for regulators and counsel.
Sources & methodology
Primary public sources this issue: CISA Known Exploited Vulnerabilities catalog (entries of 23 and 26 January 2026) · Microsoft advisory for CVE-2026-21509 · vendor research on SmarterMail CVE-2026-23760 exploitation (Huntress, Censys, ReliaQuest) · CERT-UA and security-press reporting on APT28 activity · public breach disclosures and leak-site monitoring (Have I Been Pwned, security press), 19 January – 1 February 2026 · European Commission EU Cybersecurity Package (20 January 2026) · Breachsense ransomware leak-site statistics, January 2026 · MITRE ATT&CK v15.