Skip to content
NetarxImpact Database
Vishing (Voice Phishing)No AI reportedReported

Adidas customer data stolen through third-party customer service provider

Adidas · Retail · Germany · May 2025

What happened

Adidas disclosed in late May 2025 that an unauthorised external party had obtained consumer data through a third-party customer service provider. The data consisted mainly of contact details of people who had previously contacted the company's help desk; Adidas said no passwords or payment data were affected. Security reporting placed the incident within the ShinyHunters Salesforce campaign.

How the deception worked

Adidas did not publish the entry method, and the social-engineering attribution comes from security reporting on the wider campaign. In that campaign, callers telephoned outsourced help-desk agents, claimed to be the brand's internal IT team or the CRM vendor, and asked the agent to complete an application-authorisation step so a 'support tool' could be installed. The agent read a connection code back to the caller, binding an attacker-controlled OAuth app to the customer-service tenant. The pretext exploited a help desk's habit of being helpful to anyone claiming to be a colleague, and the target had no easy way to verify an inbound caller's identity.

The control that would have caught it· our reading, not a claim from the sources

Outsourced help desks need a documented, enforced callback procedure and should be technically prevented from granting third-party app consent.

Sources (2)

  1. April 2025 Adidas Data Breach: Supply Chain Attack via Third-Party Customer Service Provider
    Rescana·rescana.comOpen ↗
  2. ShinyHunters behind Salesforce data theft attacks at Qantas, Allianz Life, and LVMH
    BleepingComputer·bleepingcomputer.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.