Decathlon confirmed Spanish employee email addresses leaked from third-party app

Organization
Decathlon
Exploit
Third-Party Data Breach
Industry
Retail

Decathlon, the France-based sporting goods retailer, confirmed a limited data incident affecting its Spanish operation after a threat actor using the handle 888 advertised a database said to belong to the company in late May 2024.

The company said its cybersecurity team in Spain became aware on May 27, 2024 that data containing email addresses belonging to Decathlon Spain employees was being offered for sale online. An initial analysis found the data had originated from a third-party application rather than Decathlon's own systems, and that only Spanish employee email addresses were involved. Decathlon said no passwords appeared in the set and that no customer data was affected.

Accounts of the size of the leak varied. The Cyber Express and the Spanish security outlet Cibersafety both put the figure at 6,644 employee records, while the seller's own post described a broader set that also referenced headquarters and transport details. The listing was never independently validated.

Decathlon said it notified the employees concerned, gave them precautionary guidance and put additional security measures in place. It did not identify the third-party application involved, and no ransom demand was reported.

Sources