Pass'Sport Breach: 6.4M Accounts Exposed
In December 2025, data from France's Pass'Sport program was posted to a popular hacking forum . Initially misattributed to CAF (the French family allowance fund), the data contained 6.5M unique email addresses affecting 3.5M households. The data also included names, phone numbers, genders and physic...
Overview
In December 2025, a significant data breach impacted France’s Pass’Sport program, a government initiative to help fund youth sports activities. A database containing the sensitive information of millions of applicants was leaked and posted to a public hacking forum. The French Ministry of Sports has since acknowledged the incident. This breach is severe due to the highly personal nature of the exposed data, which can be used for targeted scams and identity theft.
What Was Exposed
The leaked database contains detailed personal information for over 6.3 million individual accounts, affecting approximately 3.5 million households. The specific data types exposed include:
- Email Addresses
- Full Names
- Phone Numbers
- Physical Addresses
- Genders
This combination creates a comprehensive profile of an individual and their household.
Potential Impact
The exposure of this data poses a HIGH risk to affected individuals. With an email, name, and physical address, attackers can craft highly convincing phishing emails and smishing (SMS) texts that appear legitimate, increasing the chance you might click a malicious link. The inclusion of a phone number and home address dramatically raises the risk of targeted scams, including impersonation of government officials or financial institutions. Furthermore, this information is a treasure trove for identity theft, as it provides key details often used in security verification processes for other accounts.
Recommendations
If you applied for the Pass’Sport subsidy, you should take the following steps immediately:
- Be Extremely Vigilant with Communications: Treat any unsolicited email, text message, or phone call with heightened suspicion, especially if it references sports, government subsidies, or your personal details. Do not click on links or provide any further information. Verify communications directly through official government websites.
- Enable Strong Account Security: Use a unique, strong password for your email account associated with Pass’Sport. If you reuse this password elsewhere, change it on those other sites immediately. Enable two-factor authentication (2FA) on your email and any other important accounts (like banking) to add a critical extra layer of security.
- Monitor for Identity Fraud: Keep a close eye on your bank and credit card statements for any unauthorized transactions. Be cautious of unexpected mail regarding new accounts or credit checks, which could indicate attempted identity theft.
How to Check If You’re Affected
The breach has been added to the reputable data breach notification service “Have I Been Pwned.” To check if your email address was compromised in this incident:
- Go to https://haveibeenpwned.com
- Enter your email address in the search bar.
- Review the results. If your data was part of the Pass’Sport breach, it will be listed among any other breaches your email appears in.
If you are affected, follow the recommendations above to protect yourself.
Investigate Breaches Safely with NordVPN
Researching exposed data, paste sites, or threat actor infrastructure? Route your OSINT traffic through a VPN to avoid attribution and keep your investigation IP separate from your corporate network.
Get NordVPN for ResearchAffiliate link — we may earn a commission at no extra cost to you.
Never miss a data breach report
Get real-time security alerts delivered to your preferred platform.
Related Breach Reports
In April 2026, the hacking group ShinyHunters claimed they had breached Amtrak . The group typically compromises organisations' Salesforce instances before demanding a ransom and later, if not paid, dumping the data publicly. They subsequently published the alleged data which contained over 2M uniqu...
In March 2026, Hallmark suffered an alleged breach and subsequent extortion after attackers gained access to data stored within Salesforce. The data was later published after the extortion deadline passed, exposing 1.7M unique email addresses across both Hallmark and the Hallmark+ streaming service,...
In March 2026, the anime streaming service Crunchyroll suffered a data breach alleged to have impacted 6.8M users . The exposed data is reported to have originated from the company's Zendesk support system where "name, login name, email address, IP address, general geographic location and the conten...
In February, the AI-powered comic generation platform KomikoAI suffered a data breach . The incident exposed 1M unique email addresses along with names, user posts and the AI prompts used to generate content. The exposed data enables the mapping of individual AI prompts to specific email addresses.