LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Fanpass Data Breach (2022)

HIGH severityConfirmedHow we verify

Fanpass Data Breach (2022): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·April 30, 2022

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Fanpass Data Breach (2022)

Reported April 30, 2022. Approximately 112K people affected.

HIGH
Severity
112K
People affected
9
Data types exposed
April 30, 2022
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Fanpass Data Breach (2022) (reported April 30, 2022) exposed Email addresses, Genders, Names and Partial dates of birth belonging to roughly 112K people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityConfirmed
Account credentials exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Fanpass Data Breach (2022) breach?
112K accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

A data breach at the UK-based soccer ticket marketplace Fanpass was reported on April 30, 2022. Records for 112,000 customers were exposed, containing names, email addresses, phone numbers, physical addresses, genders, partial dates of birth, purchase histories and passwords stored as salted hashes.

What happened

The incident occurred in April 2022 and involved the exposure of 112,000 customer records from Fanpass, a website that facilitates the buying and selling of soccer tickets. The reported data types include names, email addresses, phone numbers, physical addresses, genders, partial dates of birth, purchases and passwords held as salted hashes. No information has been made public about the method of access, the duration of the exposure or any specific files that were taken.

How a breach like this happens

Incidents involving customer databases at online service providers often begin with unauthorised access to web servers or backend systems that store user account information. Attackers may exploit unpatched software, weak authentication controls or stolen credentials to reach the data. Once inside, they can copy tables containing personal details and login credentials before the activity is detected. In many cases the precise entry point remains undisclosed after the event.

About Fanpass

Fanpass operates as a UK-based platform for the resale of soccer match tickets. Organisations in this sector routinely collect and retain customer contact details, transaction records and account credentials to process purchases and verify ticket ownership. A breach at such a service therefore involves data that directly links individuals to specific events and payment activities.

What was likely exposed

The breach record lists the following data elements as exposed: email addresses, genders, names, partial dates of birth, passwords, phone numbers, physical addresses and purchases. Passwords are described as salted hashes. No further confirmation of the exact contents of the dataset has been released, and the presence of any additional fields remains unconfirmed.

Why it matters

Exposure of names, addresses, phone numbers and purchase histories can enable targeted phishing or unwanted contact. Salty-hashed passwords reduce the immediate risk of account takeover provided the hashes remain unbroken, yet any reuse of those passwords on other sites still creates a pathway for further compromise. For the organisation, the incident adds to the record of known data losses in the ticket-resale sector and may prompt regulatory scrutiny under UK data-protection rules.

If your data was in this breach

Individuals can change passwords on Fanpass and any other accounts that share the same credentials. Enabling multi-factor authentication where available adds a further layer of protection. Checking whether an email address appears in public breach datasets can be done through free exposure-scanning services that search known leak collections.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyFanpass security record
74/100
DoxxScan™ · Moderate doxx risk
B- 78Above-average record

1 reported incident on record.

See Fanpass’s full breach history →

More recent breaches

GunAuction.com Data Breach (2022)December 3, 2022BreachForums Data Breach (2022)November 29, 2022Movie Forums Data Breach (2022)November 24, 2022Abandonia (2022) Data Breach (2022)November 15, 2022

Latest breaches

Read GalaxyWarden’s full analysis of the Fanpass Data Breach (2022) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram