What Happens When Cybercriminals Compromise A Sportswear Giant?
KnowBe4, Wednesday, November 26th, 2025
Between 1:48pm ET on October 29 and 6:53pm ET on October 30, 2025, KnowBe4 threat analysts observed a high volume of phishing emails detected by KnowBe4 Defend that were sent from the legitimate domain of one of the world's largest sportswear brands.
The phishing campaign showed how quickly attackers can leverage a compromised business email account to send further phishing emails in the hope of finding more victims. With phishing kits, templates and AI at their disposal, attackers have demonstrated how easy it is to develop and spread large phishing campaigns that use polymorphic elements to not only deceive the recipient but also slip past traditional email defenses.
This campaign used a wide variety of social engineering tactics, particularly impersonation, to manipulate its targets, as well as constantly changing the payload itself to bypass signature-based detection.