Fédération Française de Football
Incident posture
Linked entities
- Victim
- Fédération Française de Football
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
The French Football Federation disclosed that attackers gained access to its membership management system through a compromised user account, exfiltrating personal information including names, birth details, nationality, addresses, phone numbers, email addresses, photographs and copies of identity documents. After detecting the intrusion, the federation revoked the compromised account, filed a police report and notified the ANSSI and CNIL, while warning members about possible phishing attempts. Shortly afterward, an advertisement appeared on BreachForums offering to sell the stolen database, which the poster claimed was obtained by exploiting a misconfigured Swagger UI API on the federation’s website; similar data‑theft posts have been seen for other French sports organisations.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On 17 February 2025 the Fédération Française de Football’s information systems director detected an intrusion into the federation’s licensed members, employees and volunteers management software. The intrusion was traced to a compromised account that the attackers had used to gain access. Following detection, the FFF revoked the compromised account and launched an internal investigation. On 21 February 2025 the federation sent an email to its members informing them that it had been the victim of a cyber‑malicious act and a data theft. The email stated that personal data including name, first name, date and place of birth, nationality, postal address, telephone number, e‑mail address, photograph and a copy of an identity document could have been accessed. The FFF did not disclose the number of individuals affected by the breach.
In parallel with the notification, an individual posted an advertisement on the BreachForums marketplace offering to sell a database allegedly stolen from the FFF, claiming to have obtained the data by exploiting a misconfigured Swagger UI API on the federation’s website. The same actor had previously offered for sale a database said to contain data taken from Chronopost. The FFF filed a complaint with the authorities and reported the incident to ANSSI and the CNIL, and advised recipients to be vigilant against possible phishing attempts. The notice also noted that several other French sports federations, including those for boxing, archery, motorcycling, mountain and climbing, had experienced similar data‑theft incidents in recent weeks, with analogous offers appearing on BreachForums.
Sources
Sources available to members: 1 source.