LmCast :: Stay tuned in

Ajax football club hack exposed fan data, enabled ticket hijack

Recorded: March 26, 2026, 9 p.m.

Original Summarized

Ajax football club hack exposed fan data, enabled ticket hijack

News

Featured
Latest

Popular LiteLLM PyPI package backdoored to steal credentials, auth tokens

HackerOne discloses employee data breach after Navia hack

Firefox now has a free built-in VPN with 50GB monthly data limit

Infinite Campus warns of breach after ShinyHunters claims data theft

Ajax football club hack exposed fan data, enabled ticket hijack

CISA: New Langflow flaw actively exploited to hijack AI workflows

Edit, convert, and sign PDFs without switching apps for just $40

UK sanctions Xinbi marketplace linked to Asian scam centers

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityAjax football club hack exposed fan data, enabled ticket hijack

Ajax football club hack exposed fan data, enabled ticket hijack

By Bill Toulas

March 26, 2026
04:37 PM
0

Dutch professional football club Ajax Amsterdam (AFC Ajax) disclosed that a hacker exploited vulnerabilities in its IT systems and accessed data belonging to a few hundred people.
The security issues also allowed transferring purchased tickets to others and enabled modifications to stadium bans imposed to certain individuals.
The club learned about the security issues and their effect from journalists who were tipped off by the hacker.
AFC Ajax is one of the most successful football clubs, winning the UEFA Champions League four times and with 36 Eredivisie titles, the premier professional football league in the Netherlands.
“We recently discovered that a hacker in the Netherlands unlawfully gained access to parts of our systems. Data was viewed,” AFC Ajax stated.
“What we now know is that only the email addresses of a few hundred people were viewed. In addition, for fewer than 20 people with a stadium ban, their names, email addresses, and dates of birth were accessed.”
RTL journalists who received a tip from the hacker independently verified the vulnerabilities and reported that they were able to transfer season tickets from their holders to arbitrary people, access and modify stadium ban records, and gain broad access to fan data via APIs and shared keys.
In a demonstration, they reassigned a VIP season ticket in seconds. Most worryingly, RTL stated it could manipulate 42,000 season tickets, 538 supporter stadium bans, and view details on over 300,000 accounts.
AFC Ajax says that it has engaged external experts to determine the scope of the incident and identify the root cause, while noting that the exposed data has not been leaked.
Meanwhile, all identified vulnerabilities have been patched, and additional security measures have been introduced.
The Dutch Data Protection authority, as well as the police, have also been notified accordingly.
RTL’s investigation was clearly non-malicious. Likewise, the attacker’s limited access and decision to disclose the flaws via the media, rather than exploit them for profit or extortion, suggest the vulnerabilities were not abused at scale.
However, it remains unclear whether this was the first time these weaknesses in Ajax’s systems were discovered or exploited.
Ajax fans who have registered with the club’s systems or purchased season tickets should remain vigilant for suspicious communications, especially those impersonating or claiming to come from the AFC Ajax club.

Red Report 2026: Why Ransomware Encryption Dropped 38%
Malware is getting smarter. The Red Report 2026 reveals how new threats use math to detect sandboxes and hide in plain sight.Download our analysis of 1.1 million malicious samples to uncover the top 10 techniques and see if your security stack is blinded.
Download The Report

Related Articles:
Odido data breach exposes personal info of 6.2 million customersNavia discloses data breach impacting 2.7 million peopleAura confirms data breach exposing 900,000 marketing contactsCanadian retail giant Loblaw notifies customers of data breachEuropean DYI chain ManoMano data breach impacts 38 million customers

Ajax
Customer Data
Data Breach
Football
Netherlands

Bill Toulas
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

Popular Stories

Popular LiteLLM PyPI package backdoored to steal credentials, auth tokens

New KB5085516 emergency update fixes Microsoft account sign-in

Crunchyroll probes breach after hacker claims to steal 6.8M users' data

Sponsor Posts

Overdue a password health-check? Audit your Active Directory for free

AI is a data-breach time bomb: Read the new report

Synthetic Identities, Proxies & Real Identities for Sale, is yours next?

Cyber resilience without the complexity. Join Zero Networks to stop lateral movement fast.

Are your AI accounts being sold on the dark web? Check for free. 

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

AFC Ajax, a prominent Dutch football club with a rich history of success including four UEFA Champions League titles and 36 Eredivisie championships, recently faced a significant security breach disclosed through investigative reporting by RTL Nederland. The incident, initiated by a hacker who alerted the media rather than exploiting the vulnerabilities for malicious gain, revealed a series of critical weaknesses within the club’s IT infrastructure. The primary outcome of the breach involved the unauthorized access to data pertaining to approximately 600 registered fans, alongside sensitive details of less than 20 individuals subject to stadium bans, including name, email address, and date of birth.

The hacker’s actions demonstrated the potential to manipulate the club’s ticketing system, allowing for the reassignment of season tickets to arbitrary individuals, and to modify stadium ban records. Furthermore, the hacker gained access to over 300,000 accounts, revealing capabilities to examine supporter data on a large scale. The incident highlighted the vulnerability of APIs and shared keys utilized within the club’s systems, providing a pathway for extensive data extraction. RTL's investigation revealed the ability to manipulate 42,000 season tickets, and 538 supporter stadium bans.

Following the discovery, AFC Ajax immediately engaged external cybersecurity experts to conduct a thorough assessment of the situation, determine the precise scope of the breach, and identify the root causes of the vulnerabilities. The club subsequently patched all identified vulnerabilities and implemented additional security measures to mitigate future risks. Notification was made to both the Dutch Data Protection authority and the police. Notably, RTL's investigation appeared to be driven by non-malicious intent, suggesting an initial focus on exposing the flaws rather than exploiting them for personal gain.

While the precise timeline of when these vulnerabilities were first discovered remains unclear, the incident underscores the importance of robust cybersecurity protocols within large organizations, particularly those handling sensitive personal data. The incident serves as a cautionary tale regarding API security and the potential for attackers to leverage access to gain substantial control over systems and data. AFC Ajax fans who registered with the club or purchased season tickets are advised to remain vigilant for suspicious communications. The response by AFC Ajax highlights the critical need for proactive threat monitoring, rapid incident response, and continuous security assessment within the sports and entertainment sectors, particularly concerning the protection of fan data.