-
A cybercriminal claims to have a Decathlon customer database with 160 million records for sale for $400 in crypto.
-
The purported data includes customers’ names, email addresses, phone numbers, mailing addresses, purchasing history, and bcrypt password hashes from different nations.
-
Decathlon has neither confirmed the occurrence of a data breach, nor have security experts ruled out its possibility.
A threat actor is offering what they claim is a database belonging to Decathlon, a global sporting equipment retailer, for sale. The database, which appeared on a popular cybercrime forum post, allegedly contains 160 million customer records and is being offered for $400 in cryptocurrency.
Currently, there’s no word from Decathlon concerning this claim or any recent breach. It is still unclear whether the data is actually authentic or not.
Details of the Listing
The listing was posted on July 23. Apparently, the database holds 160 million Decathlon shopper records. And it spans several countries, of which France, Germany, UK, Italy, Spain, the Netherlands, and Brazil are among.
The seller claims the data includes customer IDs and email addresses, too. It also supposedly has phone numbers, full names, and birth dates. Street addresses, cities, and postal codes are in there as well.
They also claim to have account creation dates and shopping history. Data allegedly contains the number of purchases customers made and amounts of money they spent. Loyalty points and records of the usage of vouchers are also part of the lot.
The seller even mentions favorite sports and preferred stores. Sign-up platform details are part of it as well. The seller shared some sample records to back up their claims. But independent researchers have not verified those samples yet.
Why Exposed Bcrypt Password Hashes Could Be Risky
The listing says passwords are stored as bcrypt hashes, not plain text. That is actually good news if the breach is real.
Bcrypt encryption technique is considered to be very effective in securing passwords since it has a deliberately low speed of operation. This makes it much more difficult for hackers to break many passwords simultaneously.
Using a weak password is also another problem. If someone uses “password123” or their birth year, attackers can crack those over time.
Another risk worth mentioning is the recycling of passwords. A lot of people use the same password on multiple online accounts, even their online banking portal. Such practices are very unsafe.
When there’s a data breach, criminals grab those stolen credentials and test them on other sites, a trick referred to as credential stuffing. The risks are particularly acute for banking customers, as a hacker has claimed a data breach affecting one million Sterling Bank customers in Nigeria. And honestly, it works more often than people expect.
Decathlon is a Huge Target
The first Decathlon store started in France and has become one of the largest retailers of sporting goods around the globe. They operate numerous stores in over 70 different countries, which frequently boast millions of customers. This large number of customers is why cybercriminals love targeting the company.
If the leak does exist, then it could become one of the major retail data leaks of recent times. 160 million records is a massive amount of personal information.
The purchase history and loyalty data could help criminals craft convincing phishing emails. Imagine getting an email that mentions your favorite sport and your last purchase. It would look pretty legitimate, right?
Previous Security Incident Affecting Decathlon
Decathlon has dealt with data issues before. Back in 2020, researchers found a cloud storage misconfiguration that exposed customer and employee information.
That incident affected operations in Spain and the UK. It happened because of a wrong setup of the cloud storage, not because of a cyberattack. There is no evidence linking that older issue to this new claim. The current listing appears to be a separate matter entirely.
Valid or not, this claim is part of a larger trend. Big-box retailers keep huge volumes of data about their customers, which is what the criminals seek to obtain.
These retailers keep personal information, purchasing behavior, and loyalty program membership data, which all can be quite useful to identity thieves. Security experts have identified a trend whereby criminals target customer-facing applications more frequently.
What Customers Should Do
Listings on cybercrime forums tend to exaggerate their claims. The sellers usually bundle up old data or data from several breaches to appear larger.
For now, Decathlon hasn’t made any official statement confirming it experienced a fresh data breach. So, until there is a confirmation either by Decathlon or independent investigators, it remains what it is, an unverified claim.
However, one should be careful anyway. Decathlon users can consider a change of password. Unique and strong password, a mixture of both letters and digits, as well as symbols. That way, it would be harder for malicious actors to guess. Also, avoid using one password for many accounts.
Turn on multi-factor authentication wherever applicable for additional protection. Be alert in case of phishing attacks as well; the scammers can use this news to deceive people.
For now, this alleged database remains just that, an allegation. Whether it is a real breach, recycled information, or a scam will depend on further investigation. And we will have to wait and see if Decathlon says anything about it.