Data breach
French Sport Federations
- Records
- 3,032,424
- Breach date
- 17 September 2026Estimated
- Added
- 28 November 2025
What was exposed
1 type of data
- Email addresses3,032,424
About this breach
The investigation team has indexed a large dataset tied to French sports federations, containing roughly 3,032,424 records. Our team estimates the attack took place on September 17, 2026, and the listing was added to our index on November 28, 2025. No individual or group has claimed responsibility for this listing, and the number of email addresses in the dataset could not be determined from the indexed fields.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
What we can confirm from independent reporting is that French sports federations as a group have been heavily targeted in 2026. According to reporting by 01net, more than 50 federations had been breached by early 2026, often through a shared third-party licence-management provider rather than through each federation's own systems. Stolen member databases were advertised for sale on criminal forums, and the French data protection authority, the CNIL, was notified in multiple cases. Whether the records in this listing come from that campaign or from a separate incident is not established, as of September 25, 2026.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses. The exact count of email addresses present in the dataset is not known.
Not every individual is affected by every type of data listed here.
Because the full composition of this dataset has not been verified against federation notices, we cannot say which other personal details, if any, accompany the email addresses. Breaches of French federation membership systems described in public reporting typically involved names, birth dates, postal addresses, phone numbers, and licence numbers, but we cannot confirm that such fields appear in this particular listing.
What Are the Potential Risks for Affected Individuals?
Exposed email addresses are most often used for phishing and spam. Criminals can send convincing messages that impersonate a sports federation, a club, or a payment provider, asking recipients to click malicious links or hand over login details and payment information. Because the listing has not been claimed by a known actor, it is not possible to say how the data is being distributed or used. If other personal details are present in the dataset, those could make phishing messages harder to recognize, since attackers can reference real membership details to appear legitimate.
What Should You Do If You Were Affected?
Be cautious with unexpected emails or texts that mention your club, licence, or federation membership, especially any that ask you to log in, pay a fee, or confirm personal details.
Type federation or club website addresses into your browser yourself rather than clicking links in messages.
If you reuse passwords, change them so each important account has a unique one, and turn on two-factor authentication where it is offered.
Watch your bank and payment statements for unfamiliar charges.
If you receive harassing or fraudulent contacts, report them to your local police and, in France, to the CNIL or the cybercrime reporting service cybermalveillance.gouv.fr.
In the news
- 01net: Les fuites de données continuent en France avec le hack de la Fédération Française de Gymnastique01net.com (opens in a new tab)
- Cyber Breaches: Cyberattacks in 2026cyberbreaches.org (opens in a new tab)
- Ouest-France: Depuis le début de l'année, les cyberattaques sont légion en Franceouest-france.fr (opens in a new tab)
