2026 FFR / Ovale — phishing-linked campaign; ~530K licenciés; forum sale of player data (Mar)
Data compromised
Names, licence metadata, contact data, photos, ID images, injury-related fields alleged—confirm via official notices
Technical writeup
The Fédération française de rugby confirmed a major cybersecurity incident in March 2026 after criminal forum posts—attributed in open sources to a persona such as “Cybernox”—offered a large database said to span licensing records from roughly 2003–2026. French and international press summarized exposure affecting on the order of 530,000 licence holders, with actors also claiming roughly one million player photos and hundreds of national ID (CNI) images, plus injury and administrative metadata. The FFR characterized the root issue as phishing affecting members rather than wholesale direct compromise of a single central database, while still urging password resets and vigilance; CNIL and law enforcement were notified. Victims should rely on federation communications for definitive categories.
Root cause
Phishing / credential theft against members and related workflows (per federation); forum extortion layer
References
- https://www.lefigaro.fr/sports/rugby/rugby-la-federation-francaise-victime-d-une-cyberattaque-concernant-ses-530-000-licencies-20260317
- https://frenchbreaches.com/blog/piratage-federation-francaise-de-rugby-530-000-licencies-concernes-photos-de-mineurs-et-cni-exposees
- https://www.ruck.co.uk/france-rugby-federation-hit-by-hackers-data-breach-exposed/