[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3vwrttg2f8mvy":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":30,"seoTitle":15,"seoTitleEn":31,"seoDescription":15,"seoDescriptionEn":32,"logoUrl":33,"isVerified":4,"isSensitive":4,"isSpamList":34,"isMalware":34,"company":35},"68e3266eda11adda48825383","sport2000","Sport 2000 Data Breach","sport-2000","sport2000.fr","2024-04-18T00:00:00.000Z","2024-08-28T06:56:12.000Z","2026-07-18T23:58:18.795Z","Third party breach","",[],3189643,"known",null,"unknown","Critical",[23,24,25,26,27,28,29],"Dates of birth","Email addresses","Names","Phone numbers","Physical addresses","Purchases","Salutations","\u003Cp>The Sport 2000 data breach is a security incident recorded in April 2024, affecting approximately 3.2 million accounts. In the incident associated with the France-based sports retailer, customer identity, contact, address, and purchase fields were included. This record addresses in a clear manner the number of affected accounts, the scope of the incident, which data fields were listed, and which steps users should prioritize.\u003C\u002Fp>\u003Cp>When combined with retail shopping history, a person's interests, store relationships, and delivery context, targeted fraud messages can become more convincing. Only verifiable types of data have been used in the explanation; additional claims that cannot be verified or that could be confused with a name have not been presented as data points. This way, the user can clearly see both the seriousness of the incident and the applicable security measures for their personal account.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data listed in this incident are as follows: birth dates, email addresses, names, phone numbers, physical addresses, purchase information, and salutation information. The context of purchases and stores, combined with email and phone, facilitates the preparation of fake orders, fake returns, fake warranties, or delivery notifications. The presence of these fields together can pose a higher risk than an email leak alone; because attackers can combine communication, identity, location, shopping, or account access signals belonging to the same person to create more convincing phishing attempts.\u003C\u002Fp>\u003Cp>In this record, the password field is not listed; however, the date of birth, physical address, and purchase information are permanent and targetable personal data. Users should particularly pay attention to fraud attempts that match passwords used on different services with the same email address, phone numbers, and address information. Even if the password is not in the leak, the email, phone, full name, or physical address fields are valuable in terms of targeted advertising, social engineering, fake notifications, and account recovery misuse.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The record covers approximately 3.2 million unique email addresses in the context of the Sport 2000 France domain name and customer data. Therefore, we keep the record limited to the available data fields without expanding it as a definitive company statement. The incident is classified as a verified record. The scope boundary is important: unnecessary alarm is not given to the user for unlisted data types, but the combined effect of the listed fields should not be underestimated.\u003C\u002Fp>\u003Cp>Payment card information has not been included in the description because it is not listed under this record; it arises from the combination of risk, transaction, and communication data. In points where there is a possibility of duplicate or incorrect attribution, title, domain name, country, and sector information have also been checked separately. Different platforms with similar names or different services operating in the same sector have not been merged under this record as a single event.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Sport 2000 customers, people who shop in-store, users who share their delivery address, and people who use the same phone number on other retail accounts are at risk. The most important risk for people in this group is that leaked areas can be associated with daily account security. If a user uses the same email address for different shopping, gaming, community, dating, work, or financial services, attackers can use this information to prepare messages that appear to come from the real service.\u003C\u002Fp>\u003Cp>Shopping history for sports products can help prepare personalized messages with themes such as fake campaigns, returns, warranty, or store notifications. Email addresses with a corporate domain can also become open to business account targeting. For individual users, fields such as phone, address, date of birth, profile photo, purchase, or device information can lead to consequences such as account takeover, phishing, harassment, unauthorized tracking, and reputation risk.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Affected users should review the contact and delivery information in their Sport 2000 account; they should not click directly on links in messages related to orders, returns, or coupons. In records that contain a password or password-like field, users should change the password for all accounts where they use the same or similar password, use a strong and unique password, and enable multi-factor authentication wherever possible. In records where the password is not listed, unexpected verification codes, links, and attachments received via email and phone should be evaluated more carefully.\u003C\u002Fp>\u003Cp>In records containing address, date of birth, official identification, profile photo, or location information, users should update identity verification questions, review account recovery options, and monitor for fake profiles representing themselves. Corporate users should share with the security team whether these fields are being used for employee targeting.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Regularly cleaning the address and phone information registered in retail accounts, turning off unnecessary marketing permissions, and deleting old accounts reduce long-term risk. In the long term, having a unique password for each account, a password manager, multi-factor authentication, regular session checks, and closing old accounts form the basic security line. The fact that the email address has also been involved in different incidents before implies a risk accumulation that is not limited to a single record.\u003C\u002Fp>\u003Cp>After such incidents, it may not be sufficient for users to only change the password on the relevant platform. If the same phone number, the same delivery address, the same username, or the same recovery email is used on other services as well, attackers can try different accounts based on these common points. Therefore, making an inventory of accounts and cleaning up old memberships provides a permanent defense.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>If the user sees a match with this record, they should check where they use the same email and phone combination in their shopping accounts and be cautious of fake delivery messages. This record has been prepared to directly show the user which areas are at risk. If a match is seen, the first step is not to panic; it is to separate passwords, log out of sessions, review security notifications, and check for suspicious logins.\u003C\u002Fp>\u003Cp>Final assessment: Although this record does not contain a password, it carries a risk of sensitive personal data because it combines birth date, physical address, and purchase information. The user should compare the list of fields on this page with their account history and take immediate action on services where the same email-password pair has been reused. Suspicious messages, unexpected calls, or account recovery notifications should be handled with higher priority after the incident.\u003C\u002Fp>","Sport 2000 Data Breach (3.2 Million Reported Records)","Sport 2000 Data Breach. 3.2 Million reported records were reported. Reported data: Dates of birth, Email addresses, Names. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fsport2000_fr.webp",false,{"name":36,"sector":37,"country":38,"website":10,"websiteArchiveUrl":15,"websiteStatus":15,"websiteCheckedAt":19},"Sport 2000","Retail \u002F Sporting Goods","France"]