AFC Ajax drops ball as flaws let hackers play admin with tickets and bans
ID: 7a819166-b663-5716-b8da-351adf879f18
STIX ID: report--7a819166-b663-5716-b8da-351adf879f18
Feed Name: The Register (Security)
AFC Ajax suffered a security incident where flaws in exposed APIs and shared digital keys allowed unauthorized parties to impersonate users, transfer season tickets, and view or change stadium bans. RTL's investigation showed an attacker could access data tied to hundreds of thousands of supporters and manipulate as many as 42,000 season tickets, while Ajax says confirmed exposures were much smaller; a journalist successfully demonstrated the exploit before the issues were patched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
