
The French Football Federation detected unauthorized access to its club management software on November 20, disrupting systems used nationwide to register and administer millions of players. The intrusion originated from a compromised user account and exposed a wide set of personal data belonging to individuals licensed through the federation’s platform.
The federation, which serves as the governing body for professional and amateur football in France and oversees licensing, competitions, coaching programs, and regulatory functions, isolated the breach after identifying the rogue login. Technical teams disabled the affected account, reset passwords for all platform users, and secured the software environment to prevent further access. The response temporarily interrupted services but contained the incident before additional systems were affected.
The compromised database contained names, genders, dates and places of birth, nationalities, postal addresses, email addresses, phone numbers, and football license identification numbers. No banking details or national identity numbers were involved. The scale of the exposure remains unconfirmed, though the federation counts more than 2.3 million license holders across the country based on its most recent season data.
A criminal complaint has been filed, and notifications have been issued to France’s national cybersecurity agency ANSSI and the data protection authority CNIL. The federation intends to alert every individual whose email address appeared in the accessed dataset.
Officials urged license holders to exercise heightened caution with emails or text messages referencing the federation or their clubs, warning that the stolen information could be used to craft phishing attempts that request credentials, attachments, or personal details.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543