AFC Ajax disclosed a breach after an unknown hacker exploited vulnerabilities in the club’s app and website, including exposed APIs and shared access keys, to access parts of its IT systems. Ajax said the incident exposed email addresses belonging to a few hundred people, while records for fewer than 20 individuals subject to stadium bans included names, email addresses, and dates of birth. The club said it patched the flaws, engaged external experts to investigate, filed a police report, and notified the Dutch Data Protection Authority.
Reporting on the incident indicated the weaknesses could have allowed access to private data tied to more than 300,000 registered Ajax fans, as well as tampering with stadium-ban records and the theft or disabling of more than 42,000 season tickets. Ajax said the breach was brought to its attention by an RTL journalist who had been contacted by the hacker, and added that it had no indication the data had been further distributed, while warning supporters to watch for spam and phishing emails.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
The Dutch National Police arrested a 35-year-old man from the municipality of Buren on suspicion of hacking AFC Ajax multiple times earlier in 2026. The arrest took place on May 26 as part of the investigation into the previously disclosed breach.
Ajax disclosed that email addresses of a few hundred people were exposed and that, for fewer than 20 individuals subject to stadium bans, names, email addresses, and dates of birth were accessed. The club said it had no indication the data had been further disseminated.
Ajax said it fixed the vulnerabilities, strengthened security measures, began an investigation with external experts, filed a police report, and notified the Dutch Data Protection Authority. The club also warned users to stay alert for spam and phishing following the breach.
The breach came to Ajax's attention after an RTL journalist was contacted by the hacker and informed the club. This disclosure prompted Ajax to investigate the reported vulnerabilities and unauthorized access.
An unknown attacker gained access to parts of AFC Ajax's IT systems by exploiting vulnerabilities in the club's app and website, including exposed APIs and shared access keys. The flaws reportedly could expose private data of more than 300,000 registered fans and enable tampering with stadium bans and season tickets.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
7 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourcepolitie.nl
Open sourcehelpnetsecurity.com
Open sourcecybernews.com
Open sourcebitdefender.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.