2026 Olympique de Marseille — cyberattack; ~400k customer records claimed (Feb)
Data compromised
Customer PII and e-commerce–oriented contact and order metadata per press and actor summaries
Technical writeup
In late February 2026, BleepingComputer, SC Media, and privacy roundups described a cyber incident at French Ligue 1 club Olympique de Marseille after criminal-forum marketing of a database dump. Public narratives cited on the order of 400,000 individuals with fields such as names, postal and email addresses, phones, and order or wishlist-style commerce metadata; the club publicly characterized the event as an attempted attack and, in early statements, often excluded banking credentials and passwords from confirmed exposure. Actor claims and resale chatter should be weighed against any final regulator or CNIL-facing notices.
Root cause
Unauthorized network access and data exfiltration alleged by threat actors; forensic details not fully public