Jobe Sports Allegedly Breached, 130,000 Customer Records Offered for Sale

A threat actor is selling an alleged Jobe Sports database containing 130,337 customer records, with sample data timestamped as recently as Sept. 30.
Screenshot of a forum post offering an alleged Jobe Sports International database containing 130,337 customer records for sale.
A threat actor claims to be selling a Jobe Sports International database containing 130,337 customer records. BreachNews redacted personal information and contact details shown in the samples.

Jobe Sports International is the subject of a new data breach claim after a threat actor offered a database allegedly containing more than 130,000 customer records from the watersports equipment manufacturer and retailer.

The database was advertised for sale on Oct. 2, with the threat actor claiming it contains 130,337 Jobe Sports customer records. Samples accompanying the listing contain customer account information, contact details, billing and delivery information, and password hashes.

BreachNews reviewed portions of the sample and found records with timestamps as recent as Sept. 30, 2026, just 2 days before the database was advertised for sale. The recent timestamps make the claim more notable than cases involving old databases that are simply recirculated years after their original exposure.

The samples alone do not establish that all 130,337 claimed records are authentic or that the threat actor recently compromised Jobe Sports. BreachNews has not independently obtained or reviewed the complete database.

Jobe Sports had not issued any public statement about the alleged breach at time of publication.

Sample includes recent customer records

The database structure shown by the threat actor appears to contain information associated with customer accounts and order-related profiles.

Exposed fields allegedly include email addresses, telephone numbers, customer names, company names, billing addresses, delivery addresses, countries, internal customer identifiers and password hashes.

The sample spans records from multiple countries, consistent with Jobe Sports’ international customer base. BreachNews is not publishing any of the personal information contained in the samples.

Several of the newest records carry creation timestamps from Sept. 30, 2026. Other records included by the threat actor date back several years, suggesting the purported database could contain historical as well as recent customer information.

Password fields are also present in some of the records. Some recent entries appear to contain bcrypt-formatted password hashes, while portions of the older data contain hashes in a different format. Other customer entries have no password value populated.

There is currently no evidence that plaintext customer passwords were exposed.

Internal records also appear in sample

The material posted alongside the customer database claim also contains what appear to be records associated with Jobe Sports personnel.

Those entries use email addresses associated with the company’s domain and contain fields describing internal roles and account information. BreachNews is withholding employee names, email addresses, password hashes and other identifying information included in the material.

The presence of company-domain records provides additional context for the claim, but it does not establish the threat actor’s access method or demonstrate that Jobe Sports’ production systems remain compromised.

No vulnerability, stolen credential, malware infection or other initial access method was disclosed with the sale listing.

Jobe operates internationally from the Netherlands

Jobe Sports International is a Netherlands-based manufacturer and distributor of watersports equipment including paddleboards, wakeboarding equipment, life vests, wetsuits, kayaks, waterskis and other boating products.

The company traces the Jobe brand to 1974 and operates its international business from Heerewaarden, Netherlands. Jobe has been part of France-based Alliance Marine Group since April 2022.

The company’s website also operates as an online store selling directly to consumers across multiple markets.

If the claimed database is authentic, the combination of customer names, email addresses, telephone numbers and physical addresses could increase phishing and social engineering risks for affected customers.

Password hashes could also present an account security risk depending on the hashing method used, password strength and whether customers reused the same credentials elsewhere. The samples reviewed by BreachNews do not establish whether any passwords have been successfully recovered from the hashes.

No evidence yet of payment card exposure

The material reviewed by BreachNews does not establish that payment card numbers or financial account information were included in the purported Jobe Sports database.

The exposed fields shown in the customer sample instead center on account credentials and customer profile information, including contact, billing and delivery details.

The threat actor is attempting to privately sell the alleged database rather than publicly releasing it and did not disclose an asking price.

BreachNews found no public announcement from Jobe Sports confirming a cybersecurity incident and no independently verified evidence establishing the claimed total of 130,337 affected customers.

The unusually recent timestamps in the sample nevertheless distinguish the listing from many breach-forum posts involving databases collected years earlier and later repackaged as new incidents.

BreachNews will update this report if Jobe Sports confirms the incident, disputes the claim or provides additional information about the scope of any unauthorized access.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site →