Update on Data Incident
Based on an investigation conducted with the assistance of outside cybersecurity experts, we determined that in November 2025, an unauthorized party obtained certain personal information of some customers that was stored on a single server used for promotional marketing purposes.
The types of personal information affected varied by individual and included email addresses, first names, gender, dates of birth, general location information (such as state, country or postal code) and purchase-related information (such as information about items customers purchased or considered). Importantly, the affected data did not include financial or payment card information, government-issued ID numbers, or customer passwords.
We’ve notified relevant regulators and affected customers in accordance with local laws and regulations.
UA Data Team