Le Coq Sportif Columbia Data Breach (2023): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The Le Coq Sportif Columbia Data Breach (2023) (reported May 1, 2023) exposed Dates of birth, Device information, Email addresses and Genders belonging to roughly 80K people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
In early 2025, records tied to the Colombian website of Le Coq Sportif appeared on a popular hacking forum, pointing to a breach that reportedly dates to May 2023 and involves nearly 80,000 unique email addresses. For anyone who shopped, registered, or otherwise interacted with that site, the practical stakes are straightforward: personal details that can be used for phishing, account takeover, or identity misuse may now sit outside the organisation’s control.
Public reporting places the incident’s disclosure around May 2023, with the forum posting surfacing later. Exact technical method and full scope beyond the stated figures remain limited in open sources, so people who may be affected need clear facts rather than speculation.
Breaking down the breach
According to available reporting, a data set from the Colombian Le Coq Sportif website was posted to a popular hacking forum in January 2025. The material was described as containing almost 80,000 unique email addresses, with the underlying breach dated to May 2023. The reported summary lists impacted fields that include physical addresses, IP addresses, names, purchase-related information, genders, dates of birth, and bcrypt password hashes. Device information is also named among the exposed data types in the breach record.
No public detail in the record attributes the incident to a named threat group, describes the initial access path, or confirms whether the full customer base or only a subset was involved. Scale is given as approximately 80,000 people affected. Timing of the original compromise versus the later forum listing is stated as May 2023 for the breach itself and January 2025 for the public posting. Beyond those points, method, dwell time, and any internal detection timeline are undisclosed.
How a breach like this happens
Incidents that end with customer databases appearing on forums often follow familiar patterns, even when the precise path in a given case is unknown. Attackers may obtain credentials through phishing or reused passwords, exploit an unpatched web application or plugin, or abuse misconfigured cloud storage or admin interfaces. Once inside, they commonly export account tables, order histories, and authentication material.
Password data is frequently stored as hashes rather than clear text. Bcrypt is a deliberately slow hashing algorithm designed to slow down offline guessing; its presence does not mean passwords were left in plain form, but weak or reused passwords can still be cracked given enough time and computing power. Stolen email lists and profile fields are then packaged and offered or dumped on criminal forums, where others repurpose them for credential stuffing, targeted scams, or further fraud. None of this assigns a specific technique or actor to the Le Coq Sportif Columbia incident; it only outlines how breaches of this general type typically unfold.
About Le Coq Sportif Columbia
Le Coq Sportif is a long-established sportswear and lifestyle brand. The Colombian website serves local customers with product browsing, accounts, and e-commerce functions typical of apparel retail online. Organisations in this sector routinely hold account identifiers, shipping and billing addresses, contact emails, demographic fields collected at registration or checkout, device and session metadata, and authentication secrets needed to let customers log in.
A breach affecting such a site is consequential because the data mix links real-world identity cues (names, addresses, dates of birth) with digital reachability (emails, IPs, device information) and, where passwords are involved, direct access to the same or other accounts if credentials were reused. Retail brands also process purchase histories, which can reveal habits and contact points useful to social engineers. The impact is therefore not only operational for the company but personal for individuals whose records were included.
What data was at risk
The breach record names the following as exposed: dates of birth, device information, email addresses, genders, IP addresses, names, passwords, and physical addresses. The reported summary further notes purchase-related information and bcrypt password hashes alongside physical and IP addresses, names, genders, and dates of birth. Approximately 80,000 unique email addresses were associated with the set.
Where a field is listed, it should be treated as at risk for those in the affected population. Public detail does not itemise every record or confirm that every field was populated for every person. Organisations of this kind typically also retain order notes, phone numbers, or loyalty identifiers; whether any of those appeared here is unconfirmed and should not be assumed.
The real-world impact
For affected individuals, the combination of email, name, physical address, date of birth, and gender supports convincing phishing and impersonation. IP and device information can add context that makes fraudulent messages appear more legitimate. Bcrypt password hashes, if cracked or if the underlying password was reused elsewhere, raise the risk of account takeover on the retail site and on unrelated services. Purchase data can reveal what someone bought and when, which scammers sometimes reference to build trust.
For the organisation, consequences include customer notification and support burden, possible regulatory scrutiny under applicable privacy rules, and erosion of trust in the online storefront. None of the public facts establish negligence as a legal finding; they only establish that a substantial customer-related data set left the expected environment and later appeared in a criminal forum setting.
If your data was in this breach
If you used the Colombian Le Coq Sportif website, especially around or before May 2023, treat the named data types as potentially exposed and take measured steps:
- Change the password on your Le Coq Sportif account if you still have one, and on any other site where you used the same or a similar password.
- Enable multi-factor authentication wherever it is offered, starting with email and financial accounts.
- Watch for phishing that references orders, addresses, or personal details; verify any request through official channels you initiate yourself.
- Monitor bank and card statements for unexpected charges if you stored payment methods or made purchases on the site.
- Consider a credit or identity-monitoring check if dates of birth and physical addresses were yours and local services make that practical.
- Run a free exposure scan of your email to see whether your address has appeared in known breach data sets.
Public detail on this incident remains bounded by what was reported: roughly 80,000 email addresses, the May 2023 timeframe, the January 2025 forum posting, and the data types listed above. Acting on those concrete points is more useful than waiting for every technical gap to close.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Hathway Data Breach (2023)InflateVids Data Breach (2023)KitchenPal Data Breach (2023)Facebook Marketplace Data Breach (2023)Latest breaches
Read GalaxyWarden’s full analysis of the Le Coq Sportif Columbia Data Breach (2023) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.