Data breach
Le Coq Sportif Columbia
- Records
- 82,599
- Breach date
- 1 May 2023Estimated
- Added
- 5 February 2025
What was exposed
1 type of data · 7 more reported
- Email addresses82,599
- PasswordsReported, not counted
- NamesReported, not counted
- Home addressesReported, not counted
- IP addressesReported, not counted
- Dates of birthReported, not counted
- GenderReported, not counted
- Purchase historyReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
A data breach affecting the Colombian e-commerce operation of French sportswear brand Le Coq Sportif has surfaced online. According to our investigation team, the dataset tied to lecoqsportif.com.co contains 82,599 rows and dates back to May 1, 2023. The breach drew public attention in January 2025, when the data was posted to a popular hacking forum. Independent reporting put the number of unique exposed email addresses at nearly 80,000. No hacking group has publicly claimed responsibility for the attack.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
May 1, 2023: The estimated date of the breach, cited by Mozilla Monitor and reflected in reporting by RedPacket Security, which described the breach as dating back to May 2023.
January 2025: The leaked dataset was posted to a popular hacking forum, according to RedPacket Security.
January 16, 2025: The breach was added to Mozilla Monitor after being discovered and verified.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses.
Independent reporting describes a broader set of exposed fields. According to RedPacket Security and Mozilla Monitor, the leaked data included names, physical addresses, IP addresses, dates of birth, genders, purchase records, device information, and bcrypt password hashes. Password hashes are not readable passwords, but attackers can attempt to crack them offline.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The combination of email addresses, names, physical addresses, and birth dates gives criminals the raw material for targeted phishing. A message that references your real name, city, or birthday is far more convincing than a generic scam, which raises the odds that a recipient clicks a malicious link or hands over payment details.
Exposed password hashes carry their own risk. If attackers crack weak or common passwords, they can try those credentials on other sites, a technique known as credential stuffing. Anyone who reused the same password on other accounts faces the greatest exposure. Purchase records and addresses can also support fraudulent delivery scams or attempts to impersonate a retailer's customer service.
What Should You Do If You Were Affected?
Change your password on lecoqsportif.com.co and anywhere else you used the same password. Make each one long, unique, and unrelated to your other passwords.
Turn on two-factor authentication wherever it is offered, especially on your email account. An authentication app is generally stronger than a text message code.
Watch for phishing. Be skeptical of emails or texts referencing an order, a delivery, or your account, particularly if they ask you to log in or pay through a link. Go to the site directly instead of clicking links.
Check your financial accounts for unfamiliar charges, and consider reviewing your credit reports for activity you did not authorize.
Consider a password manager to generate and store unique passwords for every account.
Because no public notice from the company has been located in the sources reviewed as of September 25, 2026, affected individuals may not receive direct notification. Checking whether your email appears in this breach is a reasonable first step.
