On April 27, 2026, Moroccan online sports retailer Planet Sport appeared on the LockBit 5 ransomware group’s leak site after its internal files were allegedly exfiltrated in an attack whose victim count remains unknown.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch planetsport.ma
Get alerted the next time planetsport.ma files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about planetsport.ma’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates the attackers gained access to Planet Sport’s systems and removed a volume of internal documents before encrypting data and demanding payment. The company, which sells sports equipment and apparel to customers across Morocco, has not yet issued a public statement detailing the exact number of customer records involved. Available reporting describes the exposed material as internal files; specific categories such as customer names, addresses, payment details or order histories have not been independently verified in open sources. The listing on the LockBit leak site carries the typical countdown timer used by the group to pressure victims into paying.
Why This Matters for You and Your Family
When a retailer like Planet Sport suffers a breach, anyone who has ever placed an order, created an account, or entered an email address becomes potentially exposed. That single record can contain your name, delivery address, phone number and order details. Once those pieces leave the company’s control they can be combined with other leaks to build a profile that reveals far more than you realise. For families this often means children’s information appears alongside parental data, especially when shared accounts or family shipping addresses are used. The breach therefore touches not just the person who bought the football boots or yoga mat, but everyone linked to that household.
The Doxxing and Identity-Chain Implications
Credential leaks and internal documents rarely stay isolated. A phone number or email taken from one retailer can be tested across gaming platforms, social media, and other shopping sites. Attackers follow these identity chains to locate usernames, linked accounts and eventually physical addresses. Gaming accounts belonging to children are particularly vulnerable because they often reuse passwords or security questions derived from family information. Once an attacker controls one account they can harvest further details, pivot to extortion, or sell the full chain on underground markets. Public reporting shows this pattern repeats after retail breaches: initial data theft quickly escalates into doxxing attempts and account takeovers.