Alta Resources Corp. — a Neenah, Wisconsin business-process outsourcer that runs customer-service work for big brands — sued Ace American Insurance Co., a Chubb unit, in the Eastern District of Wisconsin. Bloomberg Law (September 15, 2026) and USA Herald report that Alta says it paid Adidas more than $5 million after Adidas alleged customer personal information was reached through credentials issued to Alta, then Ace refused to pick up that bill.
This is not Alta’s separate November 17–18, 2023 server incident (consumer notices went out in December 2024). That older event is a different story.
The new hook is coverage. Adidas Group’s May 23, 2025 notice already confirmed that an unauthorized party obtained consumer contact data through a third-party customer service provider. Passwords and payment data were not in that set, Adidas said. Alta’s new complaint is how that vendor fight moved into insurance court.

Snapshot
| Field | Detail |
|---|---|
| Coverage suit | Alta Resources v. ACE American · E.D. Wis. 1:26-cv-01664 · filed Sept 14, 2026 · Judge Byron B. Conway |
| Consumer suit | Khowaja v. Adidas America · N.D. Ill. 1:25-cv-06154 · filed June 2, 2025 |
| Adidas notice | May 23, 2025 — vendor help-desk contact data |
| Ace denial (complaint) | Contract exclusion + not a covered professional incident |
| Policy (complaint) | Ace professional ERM · June 1, 2024 – June 1, 2025 · cyber / privacy / network |
| Texas OAG | No Adidas 2025 row found; Alta’s 2023 incident is separate |
What is confirmed versus alleged
Confirmed by Adidas (May 23, 2025): an unauthorized external party obtained certain consumer data through a third-party customer-service provider. The company said the set mainly was contact information for people who had used the help desk, and that it did not include passwords, credit cards, or other payment data. Adidas said it was notifying consumers and authorities.
Alleged in Alta’s coverage complaint (as reported): Adidas told Alta in May 2025 that third parties used credentials issued to Alta in incidents in June 2024 and January 2025. Adidas then demanded that Alta cover damages, including exposure from two putative class actions. Alta says it paid more than $5 million and is asking Ace for the $5 million policy limit.
Ace / Chubb had not commented in the press pieces we used. A coverage denial is not a finding that no incident happened. It is a fight over who pays.
Why Ace denied the claim
The complaint PDF is not on RECAP yet. What follows is Alta’s account of Ace’s denial, as reported by USA Herald and Bloomberg Law. Ace has not answered in court.
Alta says it put Ace on notice promptly. Ace treated Adidas’ demand as a timely claim, then refused third-party coverage on two grounds:
| Ace’s ground | What that usually means | Alta’s reply |
|---|---|---|
| Contract exclusion | No payout if the claim is really a breach of contract with Adidas | The Adidas demand is not that kind of claim as structured |
| Not a professional incident | No error/omission in a listed professional service | Call-center / customer-service work is listed |
Bloomberg Law adds that Ace acknowledged Adidas’ claim involved a covered cyber incident, then still used the contract exclusion. That is Alta’s characterization, not Ace’s brief.
Alta’s complaint (via USA Herald) quotes the policy’s cyber incident definition as a failure to properly handle, store, protect, or otherwise control protected information — names, emails, phone numbers, SSNs, health data, and card numbers among them. Professional incident is an error, omission, negligence, or breach of duty in rendering a professional service. Alta says Ace’s own marketing pitched this policy at BPO / call-center firms for exactly this kind of data claim, and that Ace used “an unreasonably narrow construction” of the contract exclusion. It also alleges bad faith: Ace “knew or recklessly disregarded” that there was no reasonable basis to deny.
None of that is a court finding. It is why Alta filed. The docket is an insurance contract case (28 U.S.C. § 1332), assigned to Judge Byron B. Conway.

The consumer class action in the background
Khowaja v. Adidas America, Inc. (N.D. Ill., 1:25-cv-06154, filed June 2, 2025) is a putative class action. The complaint says Adidas notified the plaintiff around May 30, 2025 that names, emails, phone numbers, genders, and dates of birth were reached through a third-party customer service provider. That is an allegation in a lawsuit, not a verdict.
Do not mix that docket with California tracking-pixel / CIPA cases against Adidas. Those are a different theory.
A different Alta incident — do not merge them
Alta itself notified consumers in December 2024 about unauthorized access to its servers on November 17–18, 2023 (encrypted files; name and Social Security number in sample notices). That filing trail includes multiple state AGs. ClaimDepot / HHS-style write-ups put counts in the tens of thousands for that event. That is not the Adidas help-desk credential story in this week’s Chubb suit.
If you got a 2024 Alta letter about SSNs, treat it as the 2023 incident. If you got an Adidas help-desk contact-data notice in 2025, treat it as the vendor incident Adidas published on May 23, 2025.
What to do
- Type adidas.com and adidas-group.com yourself. Do not click “Adidas support” links in unexpected SMS or email that only know your help-desk contact fields.
- Assume leaked name / email / phone data will be reused for phishing. Adidas said payment cards were not in the May 2025 set — that does not stop a fake “update your card” lure.
- If you sell through a BPO / call center: inventory which vendor logins can see customer PII, require phishing-resistant MFA on those accounts, and read the contract exclusion in your cyber policy before the claim.
- Report suspected identity theft at IC3.
A hardware key on a store login does not rewrite an insurance policy. It does cut the follow-on account-takeover path after contact data leaks.
MFA: YubiKey and Google Authenticator
Contact-data theft does not need the customer’s second factor. Grades match our MFA directory.
| Grade | Meaning |
|---|---|
| Fail | SMS, voice, or email OTP — or no public MFA path |
| Pass | Self-serve Google Authenticator-style open TOTP |
| Strong | FIDO2 / YubiKey-class security key for sign-in |
| Platform | Grade | YubiKey | Authenticator |
|---|---|---|---|
| Adidas adiClub | Fail | No | No |
| Alta Resources | Fail | No | No |
| Chubb / @chubb | Fail | No | No |
Adidas public account help covers password and email changes. We found no YubiKey or Google Authenticator enrollment path. Privacy pages describe token-based adidas Log-In — that is not a documented authenticator-app or security-key setup.
Alta’s marketing site names NIST / SOC 2 / PCI / HITRUST. It does not publish a self-serve YubiKey or Google Authenticator enrollment page for clients or consumers.
Chubb’s consumer MFA article recommends Google Authenticator on other websites. @chubb login FAQs are user ID and password. Chubb’s Coupa supplier portal documents authenticator-app MFA — that is Coupa, not Ace policyholder login, so the Chubb row stays Fail.
Directory: MFA support directory · Business Apps.
Recommended MFA tools
| Product | Best for | Get it |
|---|---|---|
| YubiKey 5C NFC | USB-C laptops + NFC phones | Amazon |
| YubiKey 5 NFC | USB-A desktops + NFC phones | Amazon |
| Proton Pass | Passkeys + authenticator-style TOTP | Proton Pass |
We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Independent cybersecurity audits
We audited Adidas, Adidas Group, Chubb, and Alta hosts on September 16, 2026. 100% is the ideal — none reach it. These scores are public email / transport / website posture. They do not score the coverage complaint.
| Organization | Domain | Overall | vs 100% |
|---|---|---|---|
| Adidas | adidas.com | 68% | −32 |
| Adidas Group | adidas-group.com | 59% | −41 |
| Chubb | chubb.com | 58% | −42 |
| Alta Resources | altaresources.com | 37% | −63 |
| Domain | Identity | Transport | Website |
|---|---|---|---|
| adidas.com | 90% | 15% | 37% |
| adidas-group.com | 65% | 15% | 40% |
| chubb.com | 65% | 15% | 37% |
| altaresources.com | 10% | 15% | 40% |
Audit links: adidas.com · adidas-group.com · chubb.com · altaresources.com
adidas.com at 68% is still −32 from the ideal. Transport 15% on every row is a mail-transport gap — not a reason to trust a “claim status” email. Alta at 37% with Identity 10% is the weakest of the four.

Website stack note
Passive website-tech probes on September 16, 2026:
| Domain | Stack signal |
|---|---|
| adidas.com | Stack undetected; DigiCert TLS expires 2027-03-29 |
| adidas-group.com | Stack undetected; Sectigo TLS expires 2027-02-20 |
| chubb.com | Stack undetected; DigiCert TLS expires 2027-01-05 |
| altaresources.com | Stack undetected; DigiCert TLS expires 2026-11-25; HTTP→HTTPS redirect not confirmed |
Point-in-time only. An undetected marketing stack is not a finding that call-center credentials were (or were not) phished.
Blacklist and lookalike domains
Email blacklist checks (public DoH, September 16, 2026): adidas.com, adidas-group.com, and chubb.com were clear on mail/domain lists we can query. altaresources.com showed SPFBL hits on Mimecast shared MX IPs plus an informational UCEPROTECT L2 web note. That is provider noise. Do not lead as “Alta is blacklisted.”
DNS lookalike scans (BEC profile, registered signals only):
| Brand scanned | To review | Likely owned | BEC staging |
|---|---|---|---|
| adidas.com | 38 | 7 | 0 |
| chubb.com | 40 | 1 | 6 |
| altaresources.com | 2 | 1 | 0 |
High-interest registered names (investigate; not proof this coverage suit used them):
| Lookalike | Technique | Note |
|---|---|---|
| chrubb.com | insertion | BEC staging (NS + MX) |
| chubb.cloud | tld-swap | BEC staging (NS + MX) |
| aadidas.com | insertion | Registered — not Adidas |
| altairesources.com | insertion | Registered — not Alta |
adidas.net, adidas.org, addidas.com, and altaresources.org looked brand-owned. Type adidas.com, the May 23 notice, and chubb.com yourself. Continuous monitoring: Cybersquat Domain Monitoring.
Related coverage
- Heights Finance breach — call-center activation codes
- McKesson vishing lawsuits
- MFA support directory
Run a free audit at audit.emailmenow.com or contact EmailMeNow for vendor-access MFA, BPO contract reviews, and phishing-resistant sign-in aimed at the 100% ideal.
Sources: Bloomberg Law (Sept 15) · USA Herald · Adidas Group Data Security Information (May 23, 2025) · Alta v. ACE E.D. Wis. 1:26-cv-01664 · Khowaja v. Adidas America N.D. Ill. 1:25-cv-06154 · Adidas account settings help · Chubb @chubb FAQs · Alta cybersecurity. Independent EmailMeNow audits, website-tech, blacklist, cybersquat, and CourtListener searches September 16, 2026. Domain scores: audit.emailmenow.com only. Coverage and class-action claims are unproven. No exploit samples.