SYS::ONLINE
Wasteland.
Briefs1532
Issues20
SinceFeb 2026
LIVE
▣ Breach DECATHLON-DATA-BRE 2026-07-25

Decathlon: Alleged Threat Actor Breach Exposing 160 Million Records

"A threat actor is reportedly advertising a database allegedly tied to global sporting goods retailer Decathlon, claiming to hold roughly 160 million customer records. The claim was surfaced by the threat intelligence…"

A threat actor is reportedly advertising a database allegedly tied to global sporting goods retailer Decathlon, claiming to hold roughly 160 million customer records. The claim was surfaced by the threat intelligence account CyberWatch on X, and as of reporting the origin, scale, and authenticity of the dataset remain independently unverified. Decathlon has not publicly confirmed any incident or validated that the records belong to its customers.

What Happened

According to the listing highlighted by CyberWatch, an actor is attempting to sell a customer database attributed to Decathlon on an underground forum. The seller frames it as a fresh, large-scale trove of customer and account data. No independent researcher has yet confirmed the sample against known Decathlon customers, and the company has issued no statement acknowledging a compromise. At this stage the incident carries the hallmarks of an unverified sale claim: a large advertised volume, no confirmed intrusion vector, and no vendor confirmation. That uncertainty does not neutralize the risk, since even recycled or partially fabricated datasets are routinely weaponized for fraud once they circulate.

What Was Taken

The advertised dataset reportedly contains a broad mix of personal and account fields: customer IDs, email addresses, password hashes, full names, dates of birth, telephone numbers, physical addresses, account status details, and store preferences. If authentic, this is a high-value combination. Names, birth dates, and addresses enable identity fraud and account recovery abuse, while store preferences and account status add the personal context that makes social engineering convincing. Password hashes, though not plaintext, are far from harmless: weak or outdated hashing schemes can be cracked offline with modern wordlists and GPU tooling, exposing the underlying credentials. The advertised scale of 160 million records, if real, would rank among the larger retail exposures of the year.

Why It Matters

Retail loyalty and account databases are prime raw material for downstream crime. A confirmed leak of this size would fuel credential stuffing campaigns, as criminals replay email and password pairs against banking, email, and social platforms where customers reused credentials. The rich identity fields also lower the barrier for targeted phishing, letting fraudsters impersonate Decathlon and cite a victim's preferred store or account status to build trust before harvesting payment data or new passwords. For defenders, the strategic lesson is that unverified sale claims still move the threat needle: they seed phishing pretexts and credential-stuffing lists well before any official confirmation arrives.

The Attack Technique

No intrusion method has been disclosed. The actor has not detailed how the data was obtained, and there is no confirmed vulnerability, misconfiguration, or third-party vendor compromise attached to the claim. Large retail datasets of this kind typically originate from exposed databases, compromised APIs, credential-stuffed administrative access, or supply-chain partners handling customer data, but none of these has been established here. Until a sample is validated, the vector should be treated as unknown rather than assumed.

What Organizations Should Do

Sources: Threat Actor Allegedly Claims Decathlon Data Breach Exposing 160 Million Customer Records