French football club Olympique de Marseille (OM) confirmed it was targeted by an attempted cyberattack after a threat actor claimed to have breached club systems and leaked a sample of allegedly stolen data on a hacking forum. The actor claims access to servers containing data on roughly 400,000 individuals, including names, addresses, email addresses, and phone numbers, and also alleges theft of information tied to ~2,050 Drupal CMS accounts (including staff and contributor/moderator accounts).
OM said its technical teams and external specialist providers contained the incident quickly and that operations continue normally. The club stated no banking details or passwords were compromised, reported the matter to France’s data protection authority CNIL, and warned supporters to be alert for phishing attempts leveraging the incident. Reporting also noted the event in the context of a broader uptick in attacks against large organizations and referenced a prior breach affecting the French Football Federation.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
Following the incident, the club reported the matter to France’s data protection authority, CNIL, and filed a complaint. It also warned supporters to remain vigilant for possible phishing attempts using exposed personal or contact information.
Olympique de Marseille said it was recently targeted in a cyberattack, quickly brought the incident under control with internal teams and specialized service providers, and kept operations running normally. The club stated that no banking details or passwords were compromised while the scope of the incident remained under investigation.
Earlier in February 2026, a threat actor claimed to have breached Olympique de Marseille servers and posted a sample of allegedly stolen data on a hacking forum. The actor said it held staff and supporter information and thousands of Drupal CMS accounts, with one report citing data on roughly 400,000 individuals and more than 2,050 accounts.
In November, the French Football Federation disclosed a separate data breach involving compromised access to administrative management software used by football clubs. The incident was cited as a similar earlier breach affecting the French football ecosystem.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.