[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1d1e2yctds789":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":32,"seoTitle":15,"seoTitleEn":33,"seoDescription":15,"seoDescriptionEn":34,"logoUrl":35,"isVerified":4,"isSensitive":4,"isSpamList":36,"isMalware":36,"company":37},"68e3266eda11adda488251d4","fanpass","Fanpass Data Breach","fanpass.co.uk","2022-04-30T00:00:00.000Z","2022-05-24T03:55:30.000Z","2026-07-02T12:26:55.059Z","2026-07-18T23:50:42.445Z","Football ticket marketplace customer data breach","",[],112251,"known",null,"unknown","High",[23,24,25,26,27,28,29,30,31],"Email addresses","Genders","Names","Partial dates of birth","Passwords","Phone numbers","Physical addresses","Purchases","Social media profiles","\u003Cp>The Fanpass data breach is a verified incident affecting the UK-based football ticket buying and selling service on April 30, 2022. The record covers 112,251 customer accounts. Verified data types include email addresses, gender information, names, partial birth date information, passwords, phone numbers, physical addresses, purchase history, and social media profile information. Although passwords are stored in salted hash format, the risk of account takeover continues for users who reuse passwords. Due to the ticketing and fan context, attackers may craft fake match tickets, fake refunds, fake deliveries, fake account verifications, and fake sales messages. This record should not be presented as a payment card, bank account, or full identity document leak.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The data types listed in this record are Email addresses, Genders, Names, Partial dates of birth, Passwords, Phone numbers, Physical addresses, Purchases, and Social media profiles. When email, name, phone number, and address are found together, it becomes easier to contact the user directly and give the impression of a genuine customer. Purchase history indicates which event or ticket transaction it may be associated with, making fake refund, fake transfer, fake shipment, or fake resale messages more convincing. Social media profile information carries the risk of matching with fan identity and online visibility. Password hashes do not mean plain text passwords; however, the risk is high for people who use the same password on other accounts. Partial date of birth information can also provide helpful context in account recovery or social engineering messages.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified main measure is 112,251 customer records. Data classes are limited to contact information, partial date of birth, social profile, purchase history, and salted password hashes. Full payment card number, card security code, bank account, official identification document, full date of birth, ticket barcode, or private message content are not among the verified fields in this record. Purchase history indicates that a user's past ticket transactions may be associated; it does not mean that the payment card has been exposed. Since Fanpass is a football ticket buying and selling service, the risk is more on counterfeit tickets, fraudulent refunds, account takeover, and social profile matching. These boundaries should be maintained, and it should be clearly communicated to the user what is verified and what is not.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The main group at risk are customers who purchase, sell, or create accounts for football tickets through Fanpass. Users with phone numbers and physical addresses can be targeted with fake delivery, fake ticket transfer, or fake refund requests. People with a purchase history may receive personalized messages based on matches, teams, or events they were interested in previously. Individuals who reuse the same password across email, social media, ticketing, payment, or fan forum accounts carry a higher risk. Users with social media profiles can be more easily matched through fan groups or public profiles. High-demand matches, derby tickets, or last-minute events can help attackers create a sense of urgency. Accounts that purchase tickets for small businesses or corporate purposes can also be exposed to fake invoice and ticket transfer messages.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>If your email address appears in this record, no longer consider the password you use on your Fanpass account as secure. Set a unique password for email, social media, ticketing, payment, and shopping accounts where you use the same or similar password. Enable multi-factor authentication on services that offer it. Before clicking on links in unexpected ticket transfer, refund, resale, delivery, account verification, or event change messages, access your account directly from a known web address. Even if the caller knows your name, address, or previous ticket transaction, do not share card information, bank details, one-time codes, or account passwords. Also verify ticket offers received through social media and check the seller's identity before making a payment.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>Ticketing accounts are susceptible to fraud due to high demand and urgency pressure. Users should use unique passwords for each ticketing and social media account, prefer a password manager, and close old accounts. Privacy settings should be regularly checked on services that have purchase history and social profile connections. Not keeping phone numbers and physical addresses on unnecessary accounts reduces long-term risk. On the platform side, password hashes should be protected with strong and up-to-date methods, retention periods should be managed for old purchase records, and ticket transfer and refund messages should be provided with clear verification steps. User training should particularly emphasize scenarios of fake tickets, fake refunds, fake transfers, and payment fraud via social media.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>LeakData check shows whether your email address appears in the Fanpass leak. A positive result does not indicate the presence of payment card, bank account, or official ID within verified data classes; the verified risk involves misuse of email, name, phone, address, partial date of birth, purchase history, social profile, and salted password hashes. User actions include changing reused passwords, prioritizing ticketing and email accounts, verifying fake refund and ticket transfer messages, and reducing social media profile matching risk. If the same email appears in other ticketing, e-commerce, or social media leaks, the risk increases; attackers can create more convincing messages by combining fan interest, purchase history, and contact information.\u003C\u002Fp>","Fanpass Data Breach (112.3 Thousand Reported Records)","Fanpass Data Breach. 112.3 Thousand reported records were reported. Reported data: Email addresses, Genders, Names. Review the scope, risks, and protective…","\u002Fuploads\u002Flogo\u002Ffanpass_co_uk.webp",false,{"name":38,"sector":39,"country":40,"website":9,"websiteArchiveUrl":15,"websiteStatus":15,"websiteCheckedAt":19},"Fanpass","Ticketing","United Kingdom"]