Fanatics, a global sports commerce/e-commerce platform in the United States, reported that threat actor N0n gained destructive control over its cloud data estate, initiating deletion of 46,902 order files (108 GB) containing customer personal data, accounts-payable invoices, customer balances, bank transaction archives, tax exemption certificates, and fraud-prevention datasets. The incident is active with a deadline of 2026-09-23 01:01 UTC, threatening availability and exposure of sports commerce information. #UnitedStates
Incident Details
- Victim: Fanatics (global sports commerce platform)
- Sector: Retail & E-Commerce
- Country: US
- Actor: N0n
- Source: http://nongzecboljwv3yfndkggsybsglfrkffw7bvk2zemuteoxe6etpusnad.onion#v-fanatics
- Discovered: 2026-09-20T02:51:07.611792+00:00
- Published: 2026-09-20T02:50:48.609533+00:00
Information
- Complete order history: 46,902 order files (108 GB) with customer personal data
- Accounts-payable invoices for league and brand partners
- Customer balances, bank transaction archive, and customer tax exemption certificates
- Fraud-prevention data set
- Their cloud data estate is under destructive control; deletion has begun
- Deadline: 2026-09-23 01:01 UTC

Disclaimer: This post is based on public claims made by the ransomware group "N0n". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.