[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f30uyrto9w67sz":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":33,"seoTitle":16,"seoTitleEn":34,"seoDescription":16,"seoDescriptionEn":35,"logoUrl":36,"isVerified":4,"isSensitive":4,"isSpamList":37,"isMalware":37,"company":38},"68e3266eda11adda4882526c","le-coq-sportif","Le Coq Sportif Columbia Data Breach","le-coq-sportif-columbia","lecoqsportif.com.co","2023-05-01T00:00:00.000Z","2025-01-16T01:40:33.000Z","2026-07-03T23:05:21.539Z","2026-07-18T23:53:11.289Z","Third party breach","",[],79712,"known",null,"unknown","Medium",[24,25,26,27,28,29,30,31,32],"Dates of birth","Device information","Email addresses","Genders","IP addresses","Names","Passwords","Physical addresses","Purchases","\u003Cp>The Le Coq Sportif Colombia data breach is related to the exposure of customer account and order data belonging to the brand's Colombia web store in May 2023. The scope includes approximately 79,712 unique email addresses. This record was treated as a retail account breach limited to the Colombia store; to avoid giving users the wrong perception of account, brand, or data type, the company individually verified the fields for country, sector, website, and data class. The record was marked as sensitive data due to the presence of purchase, address, and password fields together.\u003C\u002Fp>\u003Cp>The text was stripped of old template headings and moved to a structure that directly explains risk, scope, and actions to the user. The website domain was kept as lecoqsportif.com.co; since the protocol was not added, the format that would cause https to appear twice in the link was not maintained. The previous social media sector mistake was applied to the context of retail and sportswear; the incident was not presented as a violation of all global brand systems.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data seen in this record are email addresses, names, physical addresses, IP addresses, dates of birth, gender information, device information, purchase records, and passwords. The password field was evaluated as a bcrypt hash; although this is a strong storage format, risks persist with weak or reused passwords. These fields were evaluated individually; unverified payment cards, bank accounts, official IDs, private messages, health records, or additional profile fields were not added to the data class list.\u003C\u002Fp>\u003Cp>Purchase and delivery information, fake cargo, returns, order verification, and campaign messages can be made convincing. While the email address alone poses a risk of spam and phishing, when combined with name, phone, address, IP, date of birth, or professional information, it makes it easier for the attacker to prepare a more personalized message. Therefore, the risk assessment was conducted not only based on the number of records but also on the usability of the fields together.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The scope was limited with the account 79,712 dated May 2023, and the company area was corrected as the Colombia web store. While verified data fields were preserved, unconfirmed fields were left out. Thus, the user is informed about the existing record without being overly alarmed, but without underestimating the actual risk either.\u003C\u002Fp>\u003Cp>Fields such as payment card or official ID were not added because they were not verified; domain information was left directly as lecoqsportif.com.co. If there are other incidents similar to the name in the record, they were not merged into a single large incident. Domain name, company name, and industry information were kept in the narrowest correct context possible; this prevents duplicate or misassociated breaches from being added.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>User groups at risk are customers who open an account, place an order, or share delivery information at the Colombia store. Matching users should consider not only the account in the relevant service but also other accounts where the same email, username, or password pattern is used.\u003C\u002Fp>\u003Cp>If the same password is used on other shopping, email, or social media accounts, the risk can directly turn into account takeover attempts. For those who registered with a corporate email address, the risk can extend beyond the individual account; attackers can use information such as name, role, phone number, address, purchase history, game ID, or professional profile to send more convincing messages. Therefore, users should not see the matching as a problem limited to a single site.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Affected users should change the password on their store account and any other accounts where the same password is used. All accounts using the same password in records with a password field should be updated; in records without a password field, focus should be on the risk of email, phone, and fake notifications. In both cases, the email account should be protected with a strong and unique password.\u003C\u002Fp>\u003Cp>Instead of clicking on the links in the message, the address of the relevant service should be typed manually or the record in a trusted password manager should be used. Messages such as verification codes received by phone, password reset requests, shipment, job offer, support, subscription, or security notifications should not be accepted without being verified through an independent channel.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Unnecessary address and date of birth information should not be kept in retail accounts, and a separate password should be used for each store. Old accounts, unused phone and address fields, duplicate usernames, and identical password patterns should be regularly cleaned. Users should use a unique password for each service and enable two-step verification wherever possible.\u003C\u002Fp>\u003Cp>From the service providers' perspective, minimal data retention, strong password protection, monitoring of access logs, deletion of unnecessary profile fields, and user notification after a breach are basic requirements. On the retail side, order and address data create context as valuable as a password. In such incidents, accurate scope communication is as important as technical correction; exaggerated or incomplete information can mislead the user into taking the wrong action.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>The user should first check this record with their email address. If a match is found, it should be assumed that the address, purchase, and password fields may also be at risk, and messages related to shipping or returns should be carefully verified. The absence of a match does not completely rule out repeated use of old passwords or the use of different emails associated with the same service; therefore, critical accounts should be reviewed separately.\u003C\u002Fp>\u003Cp>This record remained verified; however, the scope was limited to the Colombia store. In this arrangement, the data fields were left as English canonical classes, the description visible to the user was written in Turkish and original, unverified fields were not added, and the sensitivity flag was used only when supported by the risk context.\u003C\u002Fp>","Le Coq Sportif Columbia Data Breach (79.7 Thousand Reported Records)","Le Coq Sportif Columbia Data Breach. 79.7 Thousand reported records were reported. Reported data: Dates of birth, Device information, Email addresses. Review…","\u002Fuploads\u002Flogo\u002Flecoqsportif_com_co.webp",false,{"name":39,"sector":40,"country":41,"website":10,"websiteArchiveUrl":16,"websiteStatus":16,"websiteCheckedAt":20},"Le Coq Sportif Colombia","Retail \u002F Sportswear","Colombia"]