Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Russian Hackers Exploit Critical Zimbra Zero-Day to Steal Emails
July 24, 2026
Decathlon Investigates Alleged Breach of 160 Million Customer Records
July 24, 2026
Critical RubyGems Vulnerabilities Let Attackers Mine Monero and Spread via SSH
July 24, 2026
Home/CyberSecurity News/Decathlon Investigates Alleged Breach of 160 Million Customer Records
CyberSecurity News

Decathlon Investigates Alleged Breach of 160 Million Customer Records

Key Takeaways A threat actor is advertising a database containing 160 million alleged Decathlon customer records on a cybercrime forum. The purported data includes customer IDs, email addresses,...

Jennifer sherman
Jennifer sherman
July 24, 2026 3 Min Read
3 0

Key Takeaways

  • A threat actor is advertising a database containing 160 million alleged Decathlon customer records on a cybercrime forum.
  • The purported data includes customer IDs, email addresses, password hashes, and extensive PII.
  • Decathlon has not yet confirmed the authenticity of the breach claim or the compromise of its systems.
  • If legitimate, the data could enable credential stuffing, sophisticated phishing, and identity theft.

A significant cybersecurity alert has emerged concerning Decathlon, the global sports retailer, following claims by a threat actor to possess and offer for sale a vast database of customer information. The alleged dataset, advertised on a prominent cybercrime forum, reportedly contains approximately 160 million customer records.

Table Of Content

  • Key Takeaways
  • Details of the Alleged Data Exposure
  • Potential Risks to Customers
  • What You Should Do

The individual behind the forum post is seeking payment exclusively in cryptocurrency for the purported data. As of this report, Decathlon has not publicly acknowledged or confirmed that its systems have been compromised or that customer data has been exposed. Independent verification of the threat actor’s claims remains pending.

Details of the Alleged Data Exposure

According to the forum post, the database encompasses a wide array of personally identifiable information (PII) and account-related details. The seller also provided what appears to be a sample of the records. However, the exact scope, recency, and origin of this information cannot be definitively confirmed based solely on the forum advertisement.

The threat actor asserts that the Decathlon database includes:

  • Customer IDs
  • Email addresses
  • Password hashes
  • First and last names
  • Dates of birth
  • Phone numbers
  • Street addresses, cities, postal codes, regions, and countries
  • Account status information
  • Email-verification status
  • Preferred store and store-preference data
  • Favorite sports and purchase-related fields

Should these claims prove accurate, a dataset of this magnitude could pose substantial privacy and security risks to Decathlon customers across numerous regions. It is important to note, however, that claims made on underground forums are frequently exaggerated, fabricated, or compiled from previously leaked data. Therefore, independent validation is crucial before confirming this as a legitimate Decathlon data breach.

The alleged inclusion of password hashes is particularly concerning. While these are cryptographic representations rather than plaintext passwords, weak or reused passwords can often be cracked by attackers. Successful decryption could lead to significant downstream attacks.

Potential Risks to Customers

If attackers manage to obtain valid email and password combinations, they are likely to initiate credential-stuffing attacks. This technique leverages password reuse by automatically attempting leaked credentials across various online services, including other popular websites, email providers, financial platforms, and social media accounts. Customers who reuse their Decathlon password on other platforms would be particularly vulnerable.

Furthermore, the alleged data could facilitate highly sophisticated phishing campaigns. Threat actors could weaponize customer names, addresses, shopping preferences, and Decathlon branding to craft personalized messages designed to trick recipients into divulging login credentials, payment information, or multi-factor authentication codes. In more severe scenarios, the exposure of such extensive personal information could elevate the risk of identity fraud or account takeover attempts.

What You Should Do

Until Decathlon officially verifies or refutes these claims, customers are advised to implement the following precautionary measures:

  • Immediately change your Decathlon password, especially if it is used for other online accounts.
  • Adopt a unique, strong password for your Decathlon account, ideally generated and securely stored using a reputable password manager.
  • Enable multi-factor authentication (MFA) on your Decathlon account and any other online services where it is available.
  • Regularly review your Decathlon account details, order history, and linked payment methods for any unauthorized or unusual activity.
  • Exercise extreme caution regarding unsolicited emails, SMS messages, or phone calls purporting to be from Decathlon.
  • Never click on links or provide passwords, one-time codes, or banking information in response to unexpected messages.
  • Monitor your email accounts for any password-reset notifications that you did not initiate.

Organizations should also reinforce policies advising employees against reusing corporate credentials on consumer-facing platforms. This practice can inadvertently create a pathway for enterprise credential-stuffing attacks if consumer data breaches occur.

At the time of publication, the alleged Decathlon database breach remains unconfirmed. Decathlon has not issued an official statement validating the threat actor’s claims, and no independent evidence has emerged to substantiate that the advertised records originated from Decathlon’s systems.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachExploitphishingSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Critical RubyGems Vulnerabilities Let Attackers Mine Monero and Spread via SSH

Next Post

Russian Hackers Exploit Critical Zimbra Zero-Day to Steal Emails

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
OPSEC Error Uncovers TriBack Malware in Global Espionage Campaign
July 23, 2026
Next.js Patches 9 Flaws, Including Critical SSRF and Auth Bypass
July 23, 2026
Fake Bahrain Civil Defense App Delivers Android RAT to Steal Credentials
July 23, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us