Stade Francais Hit by Ransomware Attack as Player Data Held to Ransom
Key Takeaways
- •Stade Francais has confirmed it is the victim of a cyber attack involving the ransom of players' identity documents.
- •Cybercriminals have already publicly released identifiable documents belonging to 18 players, heightening risks of identity theft and fraud.
- •The club has deployed immediate containment, investigation, and recovery measures while filing a formal complaint with relevant authorities.
- •Reports have attributed the attack to Qilin, a Russian-speaking ransomware group previously linked to the 2024 Synnovis NHS breach.
- •The club's online ticketing, shop, and merchandise websites were not affected by the security breach.

Parisian Top 14 rugby club Stade Francais has confirmed it is the victim of a cyber attack, with reports indicating that players' identity documents are being held to ransom.
Cybercriminals have reportedly threatened to release documents relating to players, having already disclosed identifiable documents belonging to 18 players. The exposure of identity documents such as passports or national ID cards carries significant risk of identity theft and fraud for affected individuals, a concern amplified under France's stringent data protection regime, where organisations are required to notify the CNIL, the national data protection authority, of serious personal data breaches without undue delay.
"Immediate containment, investigation and recovery measures have been implemented to secure the affected systems and ensure business continuity," the French rugby club said in a statement.
Stade Francais is set to face the Vodacom Bulls, Northampton Saints, Bath Rugby, and Cardiff Rugby in this year's Investec Champions Cup. The club is coached in part by former Harlequins boss Paul Gustard and last season featured England centre Joe Marchant, who has since returned to the Premiership ahead of the coming season.
Some reports have alleged the actor behind the attack to be Qilin, a Russian-speaking ransomware group. Qilin has traditionally demanded high ransom payments and was reportedly responsible for hacking NHS medical services provider Synnovis in 2024. Ransomware operators like Qilin commonly employ a "double extortion" model, encrypting victims' systems while simultaneously threatening to publish stolen data to increase pressure to pay, making sports organisations—custodians of sensitive contractual, medical, and personal information—particularly attractive targets.
Online Services Unaffected
Online ticketing sales, the wider club shop, and merchandise websites are not affected by the breach.
The attack is the latest in a series of cyber incidents targeting sports organisations over the past decade. In 2021, the NBA's Houston Rockets received threats of a mass data leak, while football club Ajax had web vulnerabilities exposed by cybercriminals earlier this year.
The Olympic Games were also targeted in both 2018 and 2026, and the French Rugby Federation previously fell victim to an operational lockdown caused by ransomware.
Industry reports in 2023 suggested that Stade Francais, one of two Parisian Top 14 clubs, had inadvertently leaked its server source code, publicly exposing information that could have allowed actors to make changes to the club's website.
Stade Francais has filed a complaint with the relevant authorities ahead of the return of the Top 14 in September, with the club set to host Perpignan.