Alleged Decathlon Data Breach Exposes 160 Million Customer Records
A threat actor claims to be selling a Decathlon customer database containing approximately 160 million records on a cybercrime forum, with payment accepted in cryptocurrency. The alleged breach has not been independently verified, and Decathlon has not confirmed any compromise of its systems or customer data.
The seller provided a sample of records, though their authenticity, origin, and freshness remain unverified. If legitimate, the database reportedly includes:
- Customer IDs, email addresses, and password hashes
- Personal details (names, dates of birth, phone numbers, addresses)
- Account information (status, email verification, preferred stores)
- Purchase-related data (favorite sports, shopping preferences)
The presence of password hashes while not plaintext poses a risk if weak or reused credentials are cracked, enabling credential-stuffing attacks across other platforms. The exposed data could also fuel phishing campaigns, leveraging personal details to trick users into revealing login credentials, payment information, or multi-factor authentication codes. In severe cases, the breach may heighten risks of identity fraud or account takeovers.
As of now, the incident remains unconfirmed, with no official statement from Decathlon or independent validation of the threat actor’s claims. The advertised records may be exaggerated, recycled, or fabricated a common tactic in underground forums. Further investigation is needed to determine the legitimacy of the breach.
Source: https://cybersecuritynews.com/decathlon-alleged-breach/
Decathlon TPRM report: https://www.rankiteo.com/company/decathlon-group
"id": "dec1784867017",
"linkid": "decathlon-group",
"type": "Breach",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '160 million',
'industry': 'Sporting Goods',
'name': 'Decathlon',
'type': 'Retail'}],
'data_breach': {'data_encryption': 'Password hashes (not plaintext)',
'number_of_records_exposed': '160 million',
'personally_identifiable_information': ['Names',
'Dates of birth',
'Phone numbers',
'Addresses'],
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Customer IDs',
'Email addresses',
'Password hashes',
'Personal details',
'Account information',
'Purchase-related data']},
'description': 'A threat actor claims to be selling a Decathlon customer '
'database containing approximately 160 million records on a '
'cybercrime forum, with payment accepted in cryptocurrency. '
'The alleged breach has not been independently verified, and '
'Decathlon has not confirmed any compromise of its systems or '
'customer data. The seller provided a sample of records, '
'though their authenticity, origin, and freshness remain '
'unverified. If legitimate, the database reportedly includes '
'customer IDs, email addresses, password hashes, personal '
'details (names, dates of birth, phone numbers, addresses), '
'account information (status, email verification, preferred '
'stores), and purchase-related data (favorite sports, shopping '
'preferences).',
'impact': {'brand_reputation_impact': 'Potential',
'data_compromised': '160 million records',
'identity_theft_risk': 'High',
'legal_liabilities': 'Potential'},
'initial_access_broker': {'data_sold_on_dark_web': 'Yes'},
'investigation_status': 'Unconfirmed',
'motivation': 'Financial Gain',
'references': [{'source': 'Cybercrime forum'}],
'title': 'Alleged Decathlon Data Breach Exposes 160 Million Customer Records',
'type': 'Data Breach'}