Le Coq Sportif Columbia Data Breach (2023)
If you are a customer of Le Coq Sportif Columbia, here’s what’s now in circulation.
In January 2025, a data breach from the Columbian website for Le Coq Sportif was posted to a popular hacking forum. The data included almost 80k unique email addresses with the breach dating back to May 2023. Impacted data included physical and IP addresses, names, purchases, genders, dates of birth and bcrypt password hashes.
Le Coq Sportif Columbia customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
On May 1, 2023, the Colombian website of French sportswear brand Le Coq Sportif appeared in a breach notification on Have I Been Pwned, exposing data tied to nearly 80,000 unique email addresses. The incident itself dates back to January 2025 when the dataset first surfaced on a popular hacking forum, though the underlying compromise occurred earlier. Anyone who shopped on the Colombian site, created an account, or made a purchase may have had personal details taken.
What's Publicly Reported from the Disclosure
The primary listing on Have I Been Pwned states that the breach contained almost 80,000 unique email addresses along with names, physical addresses, IP addresses, dates of birth, genders, device information, purchase records, and bcrypt password hashes. The disclosure indicates the data was posted to a hacking forum in January 2025 but references the original compromise window as May 2023. Exact timing of initial access, the attack vector used, and whether the company was notified in advance remain undisclosed in the listing. The notification does not specify whether payment card details were present.
Advertisement
BATECH StudioWe build it.We run it.Web apps, AI pipelines and internal tools — under your brand, not ours.Tell us what you need →
BATECH Studio and GalaxyWarden share common ownership.
Why This Matters for You and Your Family
If you or anyone in your household ever created an account on the Colombian Le Coq Sportif site, your real name, home address, date of birth, gender, email, IP address, and purchase history are now in circulation. The presence of bcrypt password hashes means determined attackers can attempt to crack them offline, especially if you chose a weak or reused password. Once those credentials are unlocked, attackers can access any other account sharing the same email and password combination. Children or teenagers who used a parent’s email to register for sports gear or team apparel are also at risk, as the same data set links family members together.
Doxxing and Identity-Chain Implications
Physical addresses combined with dates of birth and names create immediate doxxing value. Attackers can cross-reference this information with public records, social-media profiles, or other breaches to build a complete picture of your household. IP addresses and device information further tie your online activity to a physical location, making it easier to impersonate you or target family members with phishing campaigns that appear legitimate. Credential leaks of this type frequently cascade into gaming-account takeovers; a cracked password used for both shopping and a child’s Fortnite, Roblox, or console account can lead to virtual-item theft and further personal details being extracted. The chain often ends with extortion demands or identity theft that affects credit, taxes, or employment background checks.
What to Do
- Run a DoxxScan to map every link between your handles, emails, phone numbers, and real identity, then use the cleanup of Warden to remove what you can.
- Rotate the password used on Le Coq Sportif anywhere it is reused and enable 2FA through an authenticator app rather than SMS.
- Enable continuous DoxxScan monitoring across 13.1B+ breach records and 100+ platforms so the next exposure surfaces in hours instead of months.
- Cover the household with DoxxScan family coverage that extends to dependents and children’s gaming accounts that often chain back to the same address or parent email.
- Let remediation specialists handle ongoing takedown requests across data brokers and leak sites on your behalf.
The Le Coq Sportif Columbia breach is a reminder that even mid-sized retail sites can expose enough personal data to fuel long-term identity abuse. Staying ahead requires more than one-time checks; it demands continuous visibility and expert help when new exposures appear. DoxxScan by GalaxyWarden delivers that through continuous monitoring across 13.1 billion+ breach records and over 100 platforms, AI-powered identity-chain mapping, hands-on remediation by specialists, and full household coverage that includes children’s gaming accounts. Start your DoxxScan trial today and close the gaps before the next leak surfaces.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
For security and vendor-risk teams: a staff address in a leak does not mean you were breached — it usually means a third party was. We monitor a domain against 13.1B+ leaked records and tell you when one of your people appears. See what we would check →
Report details & sourcing
Related breaches
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…
149 Million Credential Mega-Exposure — January 2026
Security researchers discovered a publicly exposed 96 GB database with 149 million unique logins cov…
Under Armour 72M Customer Email Dataset Resurfaces — January 2026
72 million user emails from a prior Under Armour breach were reposted publicly in January 2026, ampl…