Stade Français confirmed on Thursday that it had suffered a cyberattack affecting part of its IT system. The club has filed a complaint and informed the authorities. On the other side, the Qilin group started a countdown on 5 August and published eighteen photographs of passports and identity cards belonging to players, as proof of its intrusion. It is demanding a ransom before 15 August. Beyond the club itself, what stands out is the method: it runs like clockwork.

What Qilin really is

Qilin is not a gang of lone hackers who picked a rugby club at random. It is what is known as ransomware as a service. A technical core develops and maintains the encryption tool, the negotiation infrastructure and the site where data is published. Affiliates then rent this arsenal and carry out the intrusions, handing back a share of whatever they collect.

This set-up explains two things. First, the volume: these groups hit dozens of victims a month, in every sector, with no sector-specific logic. Second, the apparent professionalism: the deadlines, the negotiation pages and the published proof follow the same script from one victim to the next.

Double extortion, the real shift

For a long time, ransomware simply encrypted files. The victim paid to get the decryption key, or restored its backups and paid nothing. Once companies started backing up properly, the business model collapsed.

The attackers’ response is called double extortion, and that is exactly what is happening here. Before encrypting anything, they exfiltrate the data. Encryption paralyses operations, but it is the threat of publication that drives the blackmail. Restoring a backup no longer helps: the data is already gone.

That is why Stade Français finds itself in an uncomfortable position even if it has managed to get its systems running again. Paying guarantees nothing either, since nothing forces a criminal group to destroy what it has copied.

Why publish eighteen identity documents

It is not gratuitous cruelty, it is a negotiating tool. Publishing a sample serves three purposes: proving that the intrusion is real and not a bluff, showing how sensitive the stolen material is, and building pressure by showing the victim what awaits it when the deadline passes.

The publicly displayed countdown works the same way. It turns a private negotiation into a visible event, adding reputational risk to operational risk.

The real loser is not the club

A club can buy new servers. A player cannot buy back his identity.

This is the part the word “cyberattack” hides, because it suggests computers rather than people. An unredacted passport photo is not abstract data. Today, it is all someone needs to open an online bank account in your name, take out a consumer loan, sign up for a phone contract or turn up at a government office in your place.

And unlike a bank card, a passport cannot simply be cancelled. You cannot call a number to block it and receive a new one within a week. The document stays valid for years, and the number stays yours. A player affected today could see a fraudulent loan application appear in two years’ time without ever connecting it to the summer of 2026.

That is why paying or not paying does not settle the matter. Even if the club paid, nobody could guarantee the copies had been destroyed. Once the file is out, it does not come back.

In practice, who does what now

For the club, there are two obligations separate from filing a complaint. It must notify the CNIL (France’s data protection authority) within seventy-two hours, and inform each affected player individually, because a leak of identity documents puts people at high risk.

For the players, the defence is less spectacular but real: keep an eye on bank statements, be wary of calls and messages claiming to come from a bank or a government body, and, if in doubt, have the incident officially recorded. Identity thieves rarely start with the big hit; they test the water first.

A blind spot in professional sport

A Top 14 club holds data that many companies of a similar size do not: contracts, salary details, identity documents, medical information, contact details of minors in the academy. Its IT resources, meanwhile, are those of a small business.

That gap is what this kind of attack exploits. Stade Français is the first club in France’s top flight to find itself publicly in this situation. There is little reason to think it will be the last.