On May 1, 2023, the Colombian website of French sportswear brand Le Coq Sportif appeared in a breach notification on Have I Been Pwned, exposing data tied to nearly 80,000 unique email addresses. The incident itself dates back to January 2025 when the dataset first surfaced on a popular hacking forum, though the underlying compromise occurred earlier. Anyone who shopped on the Colombian site, created an account, or made a purchase may have had personal details taken.
Named in this incident?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
What's Publicly Reported from the Disclosure
The primary listing on Have I Been Pwned states that the breach contained almost 80,000 unique email addresses along with names, physical addresses, IP addresses, dates of birth, genders, device information, purchase records, and bcrypt password hashes. The disclosure indicates the data was posted to a hacking forum in January 2025 but references the original compromise window as May 2023. Exact timing of initial access, the attack vector used, and whether the company was notified in advance remain undisclosed in the listing. The notification does not specify whether payment card details were present.
Why This Matters for You and Your Family
If you or anyone in your household ever created an account on the Colombian Le Coq Sportif site, your real name, home address, date of birth, gender, email, IP address, and purchase history are now in circulation. The presence of bcrypt password hashes means determined attackers can attempt to crack them offline, especially if you chose a weak or reused password. Once those credentials are unlocked, attackers can access any other account sharing the same email and password combination. Children or teenagers who used a parent’s email to register for sports gear or team apparel are also at risk, as the same data set links family members together.
Doxxing and Identity-Chain Implications
Physical addresses combined with dates of birth and names create immediate doxxing value. Attackers can cross-reference this information with public records, social-media profiles, or other breaches to build a complete picture of your household. IP addresses and device information further tie your online activity to a physical location, making it easier to impersonate you or target family members with phishing campaigns that appear legitimate. Credential leaks of this type frequently cascade into gaming-account takeovers; a cracked password used for both shopping and a child’s Fortnite, Roblox, or console account can lead to virtual-item theft and further personal details being extracted. The chain often ends with extortion demands or identity theft that affects credit, taxes, or employment background checks.