The Ajax 2026 data breach is an incident in which Dutch football club AFC Ajax confirmed that an attacker gained unauthorized access to parts of its systems and viewed supporter data. According to the club's March 25, 2026 statement, email addresses belonging to a few hundred people were viewed; names, email addresses, and dates of birth were also accessed for fewer than 20 people subject to stadium bans.
The incident was not merely a theoretical weakness: Ajax explicitly acknowledged that data was viewed. However, the club published no exact person total, intrusion start date, or volume of downloaded material. LeakData therefore keeps pwnCount and totalRecords at zero to represent an unknown total and does not turn the phrase “a few hundred” into a fabricated precise number.
How Did the Ajax Breach Come to Light?
Ajax's statement says an attacker in the Netherlands unlawfully accessed parts of its systems and viewed data. A journalist then demonstrated vulnerabilities in the systems to the club. The club's direct acknowledgment distinguishes this event from a security flaw discovered by a researcher but never used, and confirms that the incident qualifies as an actual personal-data breach.
RTL Nieuws independently examined the weaknesses after receiving information from the attacker. Its journalists demonstrated that supporter records could be reached through APIs and shared keys, that a VIP season ticket could be transferred to another account, and that stadium-ban records could be changed. This controlled journalistic verification proves the broader technical risk but does not replace Ajax's stated scope of data actually viewed.
What Personal Information Was Viewed?
The principal class confirmed by the club is email addresses belonging to a few hundred people. For fewer than 20 people with stadium bans, names, email addresses, and dates of birth were also viewed. LeakData lists email addresses, names, dates of birth, and stadium-ban records to explain the incident context; it does not add passwords, payment cards, or identity documents.
Stadium-ban information creates sensitive context about a person's relationship with the club and its security measures. The official statement does not say that every file for each banned person was copied or that all 538 bans were viewed by the attacker. Data classes should be read with the distinction between the broader system that could be reached and the access known to have occurred.
What Do 300,000 Accounts and 42,000 Tickets Mean?
RTL's test showed that the flaws could permit access to private details across more than 300,000 registered supporter accounts and could allow more than 42,000 season tickets to be transferred or made unusable. The same investigation reported that 538 active stadium-ban records could be viewed, altered, or removed. These figures describe the vulnerability's reachable upper boundary and potential for misuse.
Ajax limited the scope known to have been actually viewed at that stage to a few hundred email addresses and additional fields for fewer than 20 people. LeakData therefore does not use 300,000 accounts, 42,000 tickets, or 538 bans as the breach-victim total. Reachable records, records actually opened, and unique affected people are separate measurements.
Ticket Transfers and Stadium Bans
The weaknesses created more than a confidentiality risk: they allowed a season ticket to be transferred away from its holder and stadium-ban records to be modified. RTL demonstrated a controlled transfer using a VIP season ticket belonging to an Ajax executive. The test exposed an authorization failure that could affect supporters' stadium access and the integrity of the club's safety controls.
The journalists' controlled demonstration does not establish that the attacker stole 42,000 tickets or removed hundreds of bans. Ajax did not confirm abuse at that scale in its public statement. The LeakData record centers on the completed access to personal information and presents ticket and ban manipulation as technical impact context, not as a mass action known to have occurred.
Ajax's Response and Steps for Supporters
Ajax opened an investigation with external experts into the incident's cause and scope, patched the identified vulnerabilities, and introduced additional security measures. The club notified the Dutch Data Protection Authority and filed a police report. It said there was no indication at that time that the data had been spread further; this means onward distribution was unconfirmed, not that access never occurred.
Supporters registered with Ajax should be alert to phishing messages that impersonate the club or its ticket service. Links should be checked through the official site or application, and unexpected ticket transfers should be reported to support. People notified in relation to stadium-ban records may also contact Ajax or the competent authority about correction and access rights.
How Should This LeakData Record Be Read?
This record represents unauthorized access and actual data viewing in Ajax systems disclosed publicly on March 25, 2026. Because the exact intrusion date is unknown, breachDate uses the disclosure date as its documented anchor. A few hundred email addresses and the names, emails, and birth dates of fewer than 20 people were confirmed, while no exact numeric total was published.
RTL's demonstrated reach across more than 300,000 accounts, more than 42,000 season tickets, and 538 ban records is important security context but not a confirmed victim count. Ajax confirmed data viewing, remediation of the flaws, and notification to the authorities. LeakData records the real breach without presenting technical upper bounds as completed mass data loss.