A threat actor is allegedly claiming to possess and sell a Decathlon customer database containing approximately 160 million records. The database was advertised on a cybercrime forum, where the seller stated that payment would be accepted through cryptocurrency.
The alleged breach has not been independently verified, and Decathlon has not publicly confirmed that its systems or customer data were compromised.
According to the forum post, the purported database includes a broad range of personally identifiable information (PII) and account-related data. The seller also displayed what appears to be a sample of records, although the authenticity, scope, freshness, and origin of the information cannot be confirmed from the post alone.
Allegedly Exposed Decathlon Data
The actor claims the Decathlon database includes:
- Customer IDs
- Email addresses
- Password hashes
- First and last names
- Dates of birth
- Phone numbers
- Street addresses, cities, postal codes, regions, and countries
- Account status information
- Email-verification status
- Preferred store and store-preference data
- Favorite sports and purchase-related fields
If genuine, a dataset of this size could create significant privacy and security concerns for Decathlon customers across multiple regions. However, claims made on underground forums are frequently exaggerated, recycled, fabricated, or assembled from older data leaks. Independent validation is required before the incident can be treated as a confirmed Decathlon data breach.
The alleged presence of password hashes is particularly important. Password hashes are cryptographic representations of passwords rather than passwords in plain text, but weak, reused, or poorly protected passwords can sometimes be cracked by attackers.
If attackers obtain valid email-password combinations, they may attempt credential-stuffing attacks against Decathlon and unrelated services. This technique exploits password reuse by automatically testing leaked credentials across popular websites, email services, financial platforms, and social-media accounts.
The alleged data could also support highly convincing phishing campaigns. Threat actors could use customer names, addresses, shopping preferences, and Decathlon branding to create tailored messages that attempt to steal login credentials, payment details, or multi-factor authentication codes. In more serious cases, personal information may increase the risk of identity fraud or account takeover attempts.
What Decathlon Customers Should Do
Until the claim is verified or denied, customers should take precautionary steps:
- Change their Decathlon password, especially if it is reused elsewhere.
- Use a unique, long password generated and stored in a password manager.
- Enable multi-factor authentication where it is available.
- Review Decathlon account details, order history, and linked payment methods for unusual activity.
- Be cautious of unsolicited emails, SMS messages, or calls claiming to be from Decathlon.
- Never provide passwords, one-time codes, or banking information through links received in unexpected messages.
- Monitor email accounts for password-reset notifications that were not initiated by the user.
Organizations should also remind employees not to reuse corporate credentials on consumer platforms, as alleged consumer-data breaches can become a pathway for enterprise credential-stuffing attacks.
At the time of writing, the alleged Decathlon database breach remains unconfirmed. Decathlon has not issued an official statement validating the threat actor’s claims, and there is no independent evidence establishing that the advertised records originated from Decathlon systems.