A hacker claims to be selling a Decathlon customer database with 160 million records for cryptocurrency; the breach remains unverified by the company.

Threat Actor Claims 160 Million Decathlon Customer Records Up for Sale on Dark Web

The420 Web Correspondent
5 Min Read

A threat actor has surfaced on a cybercrime forum claiming to be selling a Decathlon customer database containing approximately 160 million records, payable in cryptocurrency. As of now, the claim has not been independently verified, and the French sporting goods retailer, which operates one of the largest brick-and-mortar and online footprints in India, has issued no official statement confirming or denying that its systems were compromised.

What the Alleged Database Contains

According to the forum post, the purported database includes a broad range of personally identifiable information and account-related data. The seller displayed what appears to be a sample of records, although the authenticity, scope, freshness, and origin of the information cannot be confirmed from the post alone.

The data allegedly on offer includes customer IDs, email addresses, password hashes, first and last names, dates of birth, phone numbers, full postal addresses, account status information, email verification status, preferred store data, favourite sports, and purchase-related fields. If the dataset is genuine and as comprehensive as claimed, it would provide a detailed consumer profile for each affected individual — the kind of granular information that enables targeted fraud well beyond simple account takeover.

Claims made on underground forums are frequently exaggerated, recycled, fabricated, or assembled from older data leaks. Independent validation is required before the incident can be treated as a confirmed data breach. Security researchers and journalists have not yet independently authenticated the sample data shared by the threat actor.

The Real Dangers Hidden in the Data

Even where passwords are not stored in plain text, the risks from a database of this scale are substantial and varied. Password hashes are cryptographic representations of passwords rather than passwords in plain text, but weak, reused, or poorly protected passwords can sometimes be cracked by attackers. Once cracked or matched, those credentials become the raw material for credential-stuffing attacks — automated campaigns that test the same email-password combinations across banking platforms, e-commerce sites, and social media accounts.

The combination of names, addresses, phone numbers, and shopping preferences creates a separate danger. Threat actors could construct highly personalised phishing messages using Decathlon branding, referencing a customer’s preferred sports or recent purchase categories to build credibility. For Indian consumers, who have in recent years been targeted by increasingly sophisticated impersonation scams across SMS and WhatsApp, the risk of such tailored fraud campaigns is not hypothetical.

This is not the first time Decathlon has featured in data security disclosures. A 2020 incident saw an unsecured Amazon Web Services server expose records associated with employees and customers across Spain and the United Kingdom, underscoring a pattern of data handling vulnerabilities that cybersecurity researchers have flagged with the company before.

What Decathlon Customers Should Do Now

Given the unverified status of the claim, customers need not assume the worst — but they would be prudent to act as though their data may have been exposed. The immediate priority is to change the Decathlon account password, particularly if the same password is used on any other platform. Using a unique, strong password managed through a dedicated password manager closes the credential-stuffing risk regardless of whether this specific breach is real.

Enabling multi-factor authentication wherever it is available adds a second layer of protection that renders stolen passwords alone insufficient for account access. Customers should also review their Decathlon account for unusual activity, treat any unsolicited email or SMS claiming to be from Decathlon with heightened suspicion, and never provide OTPs or payment details through links received in unexpected messages.

Cybersecurity experts note that the scale of a dataset — 160 million records across a global retailer — also makes it a potential intelligence asset for organised fraud networks. Even partial, outdated, or aggregated data can be combined with other leaked databases to build profiles sophisticated enough for identity fraud. Until Decathlon issues an authoritative statement on the status of its systems and customer data, the prudent posture for anyone with a registered account is to treat the threat as live.

Stay Connected