● Data Breaches

Threat Actor Claims Sale of Decathlon Database Containing 160 Million Customer Records

July 24, 2026 · snewle
Threat Actor Claims Sale of Decathlon Database Containing 160 Million Customer Records

A cybercriminal has allegedly offered for sale a Decathlon database breach containing approximately 160 million customer records on an underground forum. The threat actor indicated acceptance of cryptocurrency payments for the purported data, which has not been independently verified. Decathlon has not publicly acknowledged any compromise of its systems or customer information as of this writing.

The forum listing included what appeared to be sample records from the database, though the authenticity, recency, and actual source of the information cannot be confirmed based solely on the advertisement. Claims posted on cybercrime forums are often exaggerated, recycled from previous incidents, or fabricated entirely, making independent validation essential before treating the incident as a confirmed breach.

What Information Was Allegedly Compromised?

According to the threat actor’s claims, the database includes an extensive array of personally identifiable information and account data. The alleged records contain customer IDs, email addresses, password hashes, first and last names, dates of birth, and phone numbers. Geographic information reportedly includes street addresses, cities, postal codes, regions, and countries.

Additional fields allegedly present in the database encompass account status information, email-verification status, preferred store and store-preference data, favorite sports, and purchase-related information. If authentic, a dataset of this magnitude would present substantial privacy and security risks for Decathlon customers across multiple geographic regions.

What Risks Do Password Hashes and Personal Data Pose?

The alleged inclusion of password hashes represents a particular concern. While password hashes are cryptographic representations rather than plaintext passwords, weak or reused passwords can potentially be cracked by attackers. Valid email-password combinations could enable credential-stuffing attacks against both Decathlon and unrelated online services.

This attack method exploits password reuse by automatically testing leaked credentials across popular websites, email services, financial platforms, and social media accounts. The alleged personal information could also facilitate highly convincing phishing campaigns using customer names, addresses, shopping preferences, and Decathlon branding to steal login credentials, payment details, or multi-factor authentication codes. In more severe scenarios, the data could increase risks of identity fraud or account takeover attempts.

What Precautions Should Customers Take?

Until the claim is confirmed or refuted, Decathlon customers should consider several protective measures. Users should change their Decathlon password, particularly if it is reused on other platforms, and employ a unique, lengthy password generated and stored in a password manager. Enabling multi-factor authentication where available adds an additional security layer.

Customers should review Decathlon account details, order history, and linked payment methods for suspicious activity. Vigilance regarding unsolicited emails, SMS messages, or calls claiming to be from Decathlon is essential. Users should never provide passwords, one-time codes, or banking information through links in unexpected messages, and should monitor email accounts for unauthorized password-reset notifications.

Organizations should also caution employees against reusing corporate credentials on consumer platforms, as alleged consumer data breaches can create pathways for enterprise credential-stuffing attacks. The alleged Decathlon database breach remains unconfirmed, with no official company statement validating the threat actor’s claims and no independent evidence establishing that the advertised records originated from Decathlon systems.

Source: Cybersecurity News