Fanpass Data Breach (2022): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The Fanpass Data Breach (2022) (reported April 30, 2022) exposed Email addresses, Genders, Names and Partial dates of birth belonging to roughly 112K people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
What happened
The incident occurred in April 2022 and involved the exposure of 112,000 customer records from Fanpass, a website that facilitates the buying and selling of soccer tickets. The reported data types include names, email addresses, phone numbers, physical addresses, genders, partial dates of birth, purchases and passwords held as salted hashes. No information has been made public about the method of access, the duration of the exposure or any specific files that were taken.
How a breach like this happens
Incidents involving customer databases at online service providers often begin with unauthorised access to web servers or backend systems that store user account information. Attackers may exploit unpatched software, weak authentication controls or stolen credentials to reach the data. Once inside, they can copy tables containing personal details and login credentials before the activity is detected. In many cases the precise entry point remains undisclosed after the event.
About Fanpass
Fanpass operates as a UK-based platform for the resale of soccer match tickets. Organisations in this sector routinely collect and retain customer contact details, transaction records and account credentials to process purchases and verify ticket ownership. A breach at such a service therefore involves data that directly links individuals to specific events and payment activities.
What was likely exposed
The breach record lists the following data elements as exposed: email addresses, genders, names, partial dates of birth, passwords, phone numbers, physical addresses and purchases. Passwords are described as salted hashes. No further confirmation of the exact contents of the dataset has been released, and the presence of any additional fields remains unconfirmed.
Why it matters
Exposure of names, addresses, phone numbers and purchase histories can enable targeted phishing or unwanted contact. Salty-hashed passwords reduce the immediate risk of account takeover provided the hashes remain unbroken, yet any reuse of those passwords on other sites still creates a pathway for further compromise. For the organisation, the incident adds to the record of known data losses in the ticket-resale sector and may prompt regulatory scrutiny under UK data-protection rules.
If your data was in this breach
Individuals can change passwords on Fanpass and any other accounts that share the same credentials. Enabling multi-factor authentication where available adds a further layer of protection. Checking whether an email address appears in public breach datasets can be done through free exposure-scanning services that search known leak collections.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
GunAuction.com Data Breach (2022)BreachForums Data Breach (2022)Movie Forums Data Breach (2022)Abandonia (2022) Data Breach (2022)Latest breaches
Read GalaxyWarden’s full analysis of the Fanpass Data Breach (2022) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.