Decathlon Customer Database Allegedly Offered for Sale With 160 Million Records
A threat actor claims to be selling a Decathlon customer database containing 160 million records, including PII and password hashes, on a cybercrime forum.

A threat actor has surfaced on a cybercrime forum, claiming to possess and offer for sale a substantial Decathlon customer database. The alleged dataset reportedly contains approximately 160 million records, with the seller specifying that payment should be made in cryptocurrency. At present, this claim remains unverified, and Decathlon has not issued any official statement confirming a breach of its systems or customer data.
The purported database, as advertised by the threat actor, allegedly includes a wide array of personally identifiable information (PII) and account-related details. While the seller provided a sample of records, the authenticity, completeness, and origin of this data are unconfirmed. Such claims made on underground forums are often subject to exaggeration, recycling of old data, or outright fabrication, underscoring the need for independent verification.
If the claims prove true, the dataset could pose significant privacy and security risks to Decathlon customers globally. The alleged inclusion of password hashes is a particular concern. While hashes are not plain text passwords, weak hashing algorithms or reused passwords can be cracked by attackers, potentially leading to credential stuffing attacks. This technique involves using compromised credentials to gain access to other online accounts, including email, financial services, and social media.
Beyond credential stuffing, the alleged data could also fuel sophisticated phishing campaigns. Threat actors could leverage customer names, addresses, shopping preferences, and Decathlon's branding to craft highly convincing phishing messages. These tailored attacks aim to trick individuals into revealing login credentials, payment information, or multi-factor authentication codes. In more severe scenarios, the exposure of personal details could increase the risk of identity theft and account takeover.
In light of the unconfirmed claims, Decathlon customers are advised to take proactive security measures. This includes changing their Decathlon password, especially if it is reused on other platforms, and opting for strong, unique passwords managed via a password manager. Enabling multi-factor authentication (MFA) wherever available is also a critical step. Customers should also review their Decathlon account activity for any suspicious transactions or changes.
Furthermore, vigilance against unsolicited communications is paramount. Customers should be wary of emails, SMS messages, or phone calls impersonating Decathlon and avoid sharing sensitive information or clicking on suspicious links. Monitoring email accounts for unexpected password reset notifications can also help detect unauthorized access attempts.
Organizations are also reminded of the broader implications, as consumer data breaches can serve as an entry point for attacks against corporate networks. Employees should be cautioned against reusing corporate credentials on personal accounts to mitigate the risk of credential stuffing attacks that could compromise enterprise systems.
As of this report, the alleged Decathlon data breach remains unconfirmed, with no independent evidence corroborating the threat actor's claims. Decathlon has yet to release an official statement regarding the incident.