Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Alleged 160-Million-Record Decathlon Customer Database Surfaces on Cybercrime Forum
Alleged 160-Million-Record Decathlon Customer Database Surfaces on Cybercrime Forum
Read Time:3 Minute, 6 Second

A seller on a cybercrime forum is claiming to have obtained a customer database belonging to Decathlon, the French sporting-goods retailer, containing an estimated 160 million records. The listing, which asks for payment in cryptocurrency, has not been verified independently, and Decathlon has not issued a statement confirming that its systems were compromised. As with most underground marketplace claims, the size and authenticity of the dataset should be treated cautiously until proven otherwise.

What the Alleged Dataset Contains

According to the forum post, the database includes a wide range of personal and account information tied to Decathlon shoppers. The seller posted sample records that reportedly include:

  • Customer IDs and account status flags
  • Email addresses and password hashes
  • Full names and dates of birth
  • Phone numbers and complete mailing addresses, including city, postal code, region, and country
  • Preferred store locations and favorite-sport or purchase-history fields

If the claim holds up, a dataset of this scale would touch Decathlon customers across many countries, given the retailer’s global footprint. But buyers and researchers alike should remember that forum listings are frequently inflated, recycled from older incidents, or stitched together from unrelated sources to make a sale look more attractive.

Why Password Hashes Still Matter

Hashes are not plaintext passwords, but that doesn’t make them harmless. Weak hashing algorithms, short passwords, or credentials reused across multiple sites can often be cracked or matched against previously leaked data. If attackers do manage to recover working email-and-password pairs, the most likely follow-on abuse is credential stuffing: automated login attempts against banking sites, email providers, and social media platforms that rely on the common habit of password reuse.

Beyond account takeover, a dataset this rich in personal detail — names, addresses, shopping preferences, and brand affiliation — is also tailor-made for convincing phishing lures. Attackers could craft messages that look like genuine Decathlon order confirmations or loyalty-program notices, aiming to harvest login credentials, payment card numbers, or one-time passcodes.

Decathlon’s Position So Far

At the time of writing, Decathlon has not confirmed or denied that the data originated from its systems. There is no independent technical evidence — such as a matching internal database schema or acknowledgment from the company — tying the sample records definitively back to Decathlon infrastructure. Retailers of this size are frequent targets of both genuine breaches and opportunistic scammers looking to profit from unverifiable claims, so the incident currently sits in an unconfirmed state pending further investigation or an official response.

Recommended Precautions for Customers

Because the claim cannot yet be ruled out, security teams generally advise Decathlon customers to act as though exposure is possible. Useful steps include:

  • Changing Decathlon account passwords immediately, particularly if the same password is used elsewhere
  • Switching to unique, randomly generated passwords stored in a password manager
  • Enabling multi-factor authentication wherever Decathlon offers it
  • Reviewing recent orders, saved payment methods, and account activity for anything unfamiliar
  • Treating unsolicited emails, texts, or calls referencing Decathlon orders or accounts with heightened suspicion
  • Watching for unexpected password-reset emails, which can indicate someone else is trying to access an account

A Broader Lesson for Enterprises

Even when a consumer-facing breach claim remains unverified, it carries knock-on risk for employers. Security teams should remind staff not to reuse personal-account passwords for corporate logins, since a successful credential-stuffing campaign against a retail platform can become a stepping stone into enterprise systems if employees have mirrored their passwords across services.

Until Decathlon or independent researchers confirm the scope of any actual compromise, the safest posture is to assume the worst-case scenario for password reuse while treating the specific record count and contents of the alleged database with appropriate skepticism.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Alleged 160-Million-Record Decathlon Customer Database Surfaces on Cybercrime Forum, use the discussion on Forum.

>> forum community

Comments

Leave a Reply