Data on 1.43 million French Hiking Federation members put up for sale

30.09.2026 3 min 33

A database from the French Hiking Federation (FFRandonnée) went up for sale on a hacking forum on September 29: 1,429,334 member records with names, dates of birth, postal addresses, email addresses and phone numbers. The French outlets ZATAZ and Fuites Infos reported the listing, and according to cyberattaque.org the seller goes by RedStone. The federation has not publicly confirmed the breach.

The archive is 317 MB. It holds 1,008,071 unique email addresses and 663,291 unique phone numbers. About 98,000 records include emergency contacts with phone numbers and the dates of medical certificates clearing the member for the sport. The data also covers about 44,600 subscriptions to the federation's print magazine and 19,400 digital ones. The seller says the records go back to the 1990s, so 1.43 million entries reflect decades of membership rather than the current number of members. No price was given, and buyers are asked to send private messages.

The second database from the same federation this year

In February 2026 Fuites Infos reported the sale of another FFRandonnée database, covering 813,983 members at the time. It contained name, gender, date of birth, email, phone, address, licence number and club role. The breach itself was confirmed then, but the record count and the origin of the data rested on the seller's word. Whether the two sales are connected, and where the new database came from, is unknown. ZATAZ writes that similar leaks have hit dozens of French sports and cultural federations in recent months, though how the data was taken has not been established.

The word "medical" in the listing sounds worse than it is. Going by cyberattaque.org's description, it refers to the dates of the certificates of no contraindication required for a licence, not to diagnoses. For a scammer, other fields matter more: a licence number, club, date of birth and a relative's contact together make any email or call in the federation's name believable.

What members should expect

The most likely scenario is phishing about licence renewal, insurance or updating a member profile, with a request for card details. It is safer to renew and pay through the member account opened by hand rather than through a link in an email or text message. If you listed an emergency contact, warn them: a call "from the club" about an accident on the trail is a classic way to extract money.

If an email address from the database is also a login elsewhere, change that password and turn on two-factor authentication. If the federation confirms the breach, GDPR requires it to notify the French regulator CNIL within 72 hours, and to inform members directly when the risk is high.

francedata breachffrandonnéepersonal dataphishingmedical datadarknetfraudtwo-factor authentication

Read also