On April 18, 2024, French sporting goods retailer Sport 2000 appeared in a fresh listing on Have I Been Pwned, confirming that attackers had obtained and later sold a database containing 3.2 million unique email addresses and roughly 4.4 million total rows of customer records.
Named in this incident?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
Details Confirmed in the Disclosure
The primary record on Have I Been Pwned states that the breach occurred in early 2024 and that the stolen dataset was subsequently offered for sale on a popular hacking forum. The exposed information includes names, physical addresses, phone numbers, dates of birth, email addresses, salutations, and purchase history tied to specific Sport 2000 store locations. The notification does not specify the initial attack vector, whether ransomware was involved, or the exact sale price demanded by the seller. No ransom note or extortion demand timeline is detailed in the public disclosure.
Why This Matters for You and Your Family
When a retailer like Sport 2000 loses customer records, the information rarely stays isolated. Names paired with current addresses, phone numbers, and dates of birth allow criminals to build convincing profiles that support identity theft, loan fraud, or targeted phishing campaigns against you or members of your household. Purchase history can reveal hobbies, family sizes, or even children’s sports activities, giving attackers contextual details that make social-engineering attempts far more effective. Because the breach includes both contact details and personal identifiers, the risk extends beyond spam to real financial and reputational harm.
Doxxing and Identity-Chain Implications
Once names, emails, phones, and addresses are public, attackers routinely cross-reference them against other leaks to create persistent identity chains. A single exposed email can unlock linked gaming accounts, social-media profiles, or family-shared services. Children’s accounts are especially vulnerable because parents often reuse credentials or link them to the same household address and phone number found in the Sport 2000 data. These chains accelerate doxxing by mapping online handles back to real-world identities, increasing the chance of harassment, swatting, or further extortion. DoxxScan by GalaxyWarden continuously monitors across 13.1 billion+ breach records and more than 100 platforms while using AI-powered identity-chain mapping to surface these connections before they are exploited.