Decathlon Investigates Alleged Breach of 160 Million Customer Records
Key Takeaways A threat actor is advertising a database containing 160 million alleged Decathlon customer records on a cybercrime forum. The purported data includes customer IDs, email addresses,...
Key Takeaways
- A threat actor is advertising a database containing 160 million alleged Decathlon customer records on a cybercrime forum.
- The purported data includes customer IDs, email addresses, password hashes, and extensive PII.
- Decathlon has not yet confirmed the authenticity of the breach claim or the compromise of its systems.
- If legitimate, the data could enable credential stuffing, sophisticated phishing, and identity theft.
A significant cybersecurity alert has emerged concerning Decathlon, the global sports retailer, following claims by a threat actor to possess and offer for sale a vast database of customer information. The alleged dataset, advertised on a prominent cybercrime forum, reportedly contains approximately 160 million customer records.
Table Of Content
The individual behind the forum post is seeking payment exclusively in cryptocurrency for the purported data. As of this report, Decathlon has not publicly acknowledged or confirmed that its systems have been compromised or that customer data has been exposed. Independent verification of the threat actor’s claims remains pending.
Details of the Alleged Data Exposure
According to the forum post, the database encompasses a wide array of personally identifiable information (PII) and account-related details. The seller also provided what appears to be a sample of the records. However, the exact scope, recency, and origin of this information cannot be definitively confirmed based solely on the forum advertisement.
The threat actor asserts that the Decathlon database includes:
- Customer IDs
- Email addresses
- Password hashes
- First and last names
- Dates of birth
- Phone numbers
- Street addresses, cities, postal codes, regions, and countries
- Account status information
- Email-verification status
- Preferred store and store-preference data
- Favorite sports and purchase-related fields
Should these claims prove accurate, a dataset of this magnitude could pose substantial privacy and security risks to Decathlon customers across numerous regions. It is important to note, however, that claims made on underground forums are frequently exaggerated, fabricated, or compiled from previously leaked data. Therefore, independent validation is crucial before confirming this as a legitimate Decathlon data breach.
The alleged inclusion of password hashes is particularly concerning. While these are cryptographic representations rather than plaintext passwords, weak or reused passwords can often be cracked by attackers. Successful decryption could lead to significant downstream attacks.
Potential Risks to Customers
If attackers manage to obtain valid email and password combinations, they are likely to initiate credential-stuffing attacks. This technique leverages password reuse by automatically attempting leaked credentials across various online services, including other popular websites, email providers, financial platforms, and social media accounts. Customers who reuse their Decathlon password on other platforms would be particularly vulnerable.
Furthermore, the alleged data could facilitate highly sophisticated phishing campaigns. Threat actors could weaponize customer names, addresses, shopping preferences, and Decathlon branding to craft personalized messages designed to trick recipients into divulging login credentials, payment information, or multi-factor authentication codes. In more severe scenarios, the exposure of such extensive personal information could elevate the risk of identity fraud or account takeover attempts.
What You Should Do
Until Decathlon officially verifies or refutes these claims, customers are advised to implement the following precautionary measures:
- Immediately change your Decathlon password, especially if it is used for other online accounts.
- Adopt a unique, strong password for your Decathlon account, ideally generated and securely stored using a reputable password manager.
- Enable multi-factor authentication (MFA) on your Decathlon account and any other online services where it is available.
- Regularly review your Decathlon account details, order history, and linked payment methods for any unauthorized or unusual activity.
- Exercise extreme caution regarding unsolicited emails, SMS messages, or phone calls purporting to be from Decathlon.
- Never click on links or provide passwords, one-time codes, or banking information in response to unexpected messages.
- Monitor your email accounts for any password-reset notifications that you did not initiate.
Organizations should also reinforce policies advising employees against reusing corporate credentials on consumer-facing platforms. This practice can inadvertently create a pathway for enterprise credential-stuffing attacks if consumer data breaches occur.
At the time of publication, the alleged Decathlon database breach remains unconfirmed. Decathlon has not issued an official statement validating the threat actor’s claims, and no independent evidence has emerged to substantiate that the advertised records originated from Decathlon’s systems.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.