Decathlon is facing an alleged data breach after a threat actor claimed to possess and sell a database containing approximately 160 million customer records. The claim, made on a cybercrime forum, has not yet been independently verified. However, the scale and nature of the alleged data exposure highlight significant risks for both Decathlon customers and organisations that may be indirectly affected by the fallout. This article examines what is known about the incident, what data is allegedly at risk, and the potential consequences for individuals and businesses.
Details of the Alleged Decathlon Data Breach
On a prominent underground forum, a threat actor advertised what they claim is a Decathlon customer database for sale. The seller is requesting payment in cryptocurrency. At the time of writing, Decathlon has not confirmed any breach nor publicly acknowledged that its systems or customer data have been compromised. There is also no independent verification of the dataset’s authenticity, scope, or recency.
The forum post included a purported sample of records to support the seller’s claims. However, cybersecurity experts caution that such samples may be fabricated, recycled from past leaks, or only partially representative of the true contents. Without technical analysis and validation, the incident remains unconfirmed.
The alleged breach was reported in early June 2024. It is not clear when the data was obtained, how long it may have been circulating, or whether it is currently being actively exploited. The lack of confirmation from Decathlon leaves many open questions about the extent and impact of the incident.
What Data Is Allegedly Exposed?
The threat actor claims the database includes a comprehensive set of personally identifiable information (PII) and account data. The following fields are reportedly present in the exposed dataset:
- Customer IDs
- Email addresses
- Password hashes
- First and last names
- Dates of birth
- Phone numbers
- Street addresses, cities, postal codes, regions and countries
- Account status information
- Email-verification status
- Preferred store and store-preference data
- Favourite sports and purchase-related fields
If genuine, the breadth of this data could allow criminals to launch a range of targeted attacks. The presence of password hashes is particularly notable. While hashes are cryptographically protected versions of passwords, weak or reused passwords can sometimes be cracked, especially if outdated or poorly implemented hashing algorithms were used.
The scale of the dataset, allegedly covering 160 million records, suggests that Decathlon customers from multiple regions could be affected. However, the true scope will remain uncertain until independent analysis is conducted or Decathlon releases further information.
Potential Risks: Credential Stuffing and Phishing
Should the breach be verified, the most immediate risks relate to credential stuffing and phishing. Credential stuffing involves attackers using automated tools to test stolen email-password pairs across many online services. Because password reuse is common, even hashed passwords can pose a risk if they are cracked and reused elsewhere.
The wide range of personal details in the alleged dataset also raises concerns about targeted phishing. Attackers could craft convincing emails or messages using real names, addresses, and shopping preferences to impersonate Decathlon or related services. Phishing campaigns might seek to harvest further credentials, payment information or multi-factor authentication codes.
- Credential stuffing attacks on Decathlon and other sites
- Highly personalised phishing campaigns
- Account takeover attempts
- Identity fraud using exposed personal details
Even if only a portion of the records are accurate or current, the sheer volume increases the risk of fraudulent activity against individuals whose data is exposed.
Timeline and Current Exploitation Status
The claim surfaced in early June 2024. The timeline of the alleged breach is otherwise unclear. There is no evidence yet of widespread exploitation, but cybercriminals may already be testing or using the data for malicious purposes.
Because the sale is being conducted on a cybercrime forum, access to the full dataset may be limited to a small number of buyers initially. However, if the data is genuine and widely distributed, follow-on attacks could escalate rapidly. Security researchers and affected organisations should monitor for any signs of large-scale credential stuffing or phishing campaigns referencing Decathlon.
Why This Alleged Breach Matters
This alleged breach, if genuine, could impact millions of customers across Europe and beyond. Large datasets containing PII and account credentials frequently become fuel for secondary attacks, including phishing and fraud. For organisations, even unconfirmed breaches can have reputational and regulatory implications, particularly under data protection laws such as the UK GDPR.
Immediate Actions for Organisations
Organisations—especially those with users who may reuse passwords—should:
- Remind staff not to reuse work credentials on external platforms
- Monitor for signs of credential stuffing or suspicious login activity
- Be vigilant for phishing emails referencing Decathlon or similar brands
Given the uncertainty, monitoring and targeted user communication are key until more details emerge or Decathlon issues an official statement.
Originally reported by cybersecuritynews.com.





