Hackers Allegedly Claim 160 Million Decathlon Customer Records
A threat actor has allegedly claimed to possess and sell a Decathlon customer database containing around 160 million records on a cybercrime forum. The seller alleges the database includes sensitive customer information and is accepting cryptocurrency for the dataset. Decathlon has not confirmed the breach, and the claims remain unverified.


According to the threat actor, the leaked database contains customer IDs, email addresses, password hashes, names, phone numbers, dates of birth, addresses, account status, preferred store details, and sports preferences. If authentic, the data could be exploited for credential stuffing, phishing campaigns, identity theft, and account takeover attacks.
Customers are advised to change their Decathlon passwords, use unique credentials, enable multi-factor authentication (MFA), and remain cautious of phishing emails or messages pretending to be from Decathlon. Until independently verified, the alleged breach should be treated as an unconfirmed claim.
Protect your passwords before attackers exploit them — with NPAV Password Vault Manager.