Quick Summary
AllegedExecutive Summary
Fanatics, a prominent US-based sports merchandise and e-commerce platform operating under the domain fanatics[.]com, was listed by the N0n extortion group on September 20, 2026. Given Fanatics’ vast customer base, the listing of this organization poses a significant risk of public exposure. The N0n group specializes in data extortion, employing threats of public data disclosure rather than ransomware encryption. Over the past 60 days, N0n has claimed 11 victims across the United States, Vietnam, and Brazil. The Retail & E-Commerce sector is among the group’s top three most frequently targeted industries. Fanatics represents the most high-profile addition to N0n’s victimology within this recent campaign period, aligning with the group’s pattern of targeting prominent entities in the retail sector.
Technical Analysis
Stealer-log analysis revealed 25 customer records associated with fanatics[.]com. These records were specifically linked to id[.]fanatics[.]com, which serves as the consumer account authentication portal. The observed activity is classified as Customer Account Takeover (ATO), with all identified actions occurring in September 2026, concurrently with the date of the listing. This tight timeframe between the harvesting of credentials and the group’s listing suggests that the intelligence is active and not derived from aged marketplace data. The id[.]fanatics[.]com portal is crucial for Fanatics’ consumer-facing operations, managing access to purchase history, payment methods, shipping addresses, and loyalty accounts. The discovery of 25 stealer records at this authentication portal indicates a partial signal, suggesting that the actual number of exposed accounts could be larger. N0n’s operational model focuses on threatening data disclosure over ransomware deployment, implying that data staging may have already been completed. Organizations should conduct an immediate audit of authentication logs for id[.]fanatics[.]com, specifically focusing on September 2026 activity. It is also recommended to assess the scope of data accessible through any potentially compromised accounts and to evaluate any applicable consumer notification obligations under FTC and state regulations. Continued dark web monitoring and proactive credential hygiene checks are advised.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.