rugby
Image: Ahmet Kurt via Unsplash+/Photomosh

French rugby club Stade Français restores systems after cyberattack, probes data leak

French rugby club Stade Français Paris confirmed that it had been hit by a cyberattack that disrupted part of its information systems.

The club said Thursday that it had already restored its IT environment from clean backups, allowing operations to continue normally. It added that its ticketing platform and online store were not affected and remain fully operational.

Stade Français also acknowledged that a sample of data allegedly stolen in the attack had been published online, adding that it was investigating the scope of the breach and working to identify anyone whose information may have been compromised.

"To protect the interests of the club and all its stakeholders, and to avoid interfering with the ongoing investigation and response, the club will not comment on communications from the attackers or on information circulated by third parties," the club said in a statement.

Stade Français said it had notified the relevant authorities and filed a criminal complaint after discovering the incident. It did not attribute the attack to any specific threat actor or say whether it had received a ransom demand or was engaged in negotiations with the attackers.

Earlier this week, the ransomware group Qilin claimed responsibility for the attack on its darknet leak site. French media reported that the hackers published documents belonging to 18 players as proof of the breach and threatened to release additional files unless a ransom was paid by the end of next week. Recorded Future News could not independently verify the authenticity of the leaked documents.

Qilin is one of the most active ransomware-as-a-service operations, leasing its malware to affiliates that carry out attacks in exchange for a share of ransom payments. The group typically uses so-called double extortion tactics, stealing data before encrypting victims' systems and threatening to publish the information if payment is not made. Cybersecurity researchers have previously linked the operation to Russian-speaking cybercriminals.

Sports organizations have increasingly become targets for financially motivated hackers.

Earlier this year, Dutch soccer club Ajax disclosed that hackers exploited an unpatched vulnerability to access internal systems, exposing the email addresses of several hundred people and limited personal data related to individuals subject to stadium bans.

Italian soccer club Bologna FC also suffered a ransomware attack in 2024 that exposed financial documents, players' medical records, and confidential employee information. Other recent victims include Paris Saint-Germain football club, which reported a cyberattack targeting its online ticketing service in 2024; Manchester United, which experienced a ransomware incident in 2020; the Royal Dutch Football Association in 2023; and the French Football Federation in 2025.

Get more insights with the
Recorded Future
Intelligence Cloud.
Learn more.
Recorded Future
No previous article
No new articles
Daryna Antoniuk

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.