A threat actor operating under the name N0n has posted a listing naming Fanatics, the global sports commerce platform, on its dark web extortion site, according to monitoring by ransomware.live, a research platform that tracks the public leak pages maintained by ransomware groups. The post is dated September 20, 2026. At this stage, the claim comes solely from the group itself, and no independent party, including Fanatics, has verified any part of it.
What the listing says versus what remains unconfirmed
- The claimed date of the posting is September 20, 2026.
- Fanatics operates in the sports merchandise and e-commerce space, a sector that handles large volumes of customer and payment-related information, though this alone says nothing about what, if anything, was actually accessed.
- N0n has not published, and BreachLetter has not been given, any specifics about the type, volume, or sensitivity of data supposedly obtained.
- There is currently no public confirmation from Fanatics, no notification to affected individuals, and no filing with a data protection or financial regulator tied to this listing.
- Claims made on ransomware leak sites are sometimes exaggerated, recycled from older incidents, or entirely fabricated to pressure a victim, so this listing should be treated as an unverified assertion rather than an established fact.
Sensible precautions while this claim remains unresolved
- Anyone who has shopped through Fanatics or an affiliated licensed sports merchandise site may want to update their account password, choosing something unique rather than reused across services.
- Turning on two-factor authentication where it is offered adds a meaningful barrier even if login credentials were somehow exposed elsewhere.
- Be alert for phishing emails or texts that reference orders, shipping, or account issues and try to trick you into clicking a link or handing over payment details — these often spike after a breach claim surfaces, whether or not the claim is genuine.
- Keep an eye on bank and card statements for unfamiliar charges, and consider a service like a service like Aura or LifeLock that offers identity monitoring so you’re alerted if your personal information turns up somewhere it shouldn’t.
- Avoid interacting with the ransomware group’s leak-site post directly, as doing so can expose you to malicious links or further scams.
BreachLetter will revisit and update this page if Fanatics issues a statement addressing the claim, if the incident is reported to relevant regulators, or if further credible details come to light.