Data breach
dfb.de
- Records
- 2,700,518
- Breach date
- 1 January 2020Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 1 puts you at serious risk
- Email addresses2,700,518
- Passwords2,669,838
About this breach
Data from roughly 2.7 million accounts tied to dfb.de, the online domain of the German Football Association (Deutscher Fußball-Bund), appears in a breach indexed by the investigation team. According to our investigation team, the dataset contains about 2,700,518 rows, most of them email addresses paired with passwords. The estimated attack date is January 1, 2020. No individual or group has publicly claimed responsibility for the leak, and the entry is indexed as a credential dataset rather than a confirmed single-company hack.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Email addresses: approximately 2,700,518
Passwords: approximately 2,669,838
Not every individual is affected by every type of data listed here.
The dataset is made up almost entirely of login credentials. Because the vast majority of rows include both an email address and a password, the practical danger is less about the emails themselves and more about what those passwords protect.
What Are the Potential Risks for Affected Individuals?
An email address and password combination is valuable to criminals mainly because of reuse. Many people use the same password, or a close variation of it, across several services. If your dfb.de credentials leaked, attackers can test those combinations against email inboxes, banking sites, shopping accounts, and social media. This technique, known as credential stuffing, works whenever a password was reused on another site that has not been breached.
Additional risks include targeted phishing. A criminal who knows an email address tied to a German football fan account can craft convincing messages that appear to come from the association, a ticketing service, or a sports retailer. Stolen credentials can also be sold in bulk on underground marketplaces, meaning the exposure does not end with a single publication of the data.
If you reused a dfb.de password anywhere else, treat that other account as compromised until you change the password.
What Should You Do If You Were Affected?
There is no confirmed notice from the association tied to this specific dataset, so the steps below are general precautions for anyone whose credentials appear in it:
Change your dfb.de password immediately, if you still use the account. Choose a unique password that you have never used on another site.
Update any other account that shared the same or a similar password. Prioritize your primary email account, banking, and payment services.
Turn on two-factor authentication wherever the option exists, especially for email and financial accounts. Even a stolen password is far less useful against a second login step.
Watch for phishing. Be skeptical of unexpected emails about account problems, prize winnings, tickets, or membership renewals, and never log in through links in such messages. Navigate to sites directly instead.
The records in this listing may also include addresses from people who interacted with the association's online services long ago. If you are unsure whether your details were affected, the safest course is to change any password that matches this dataset, regardless of when the account was last active.
