Levante UD, the Valencian club that returned to Spain’s top flight for the 2025–26 season, told members and customers in early October 2026 that an external intruder reached its data servers and may have compromised personal information tied to season-ticket holders, players, and its online store. The club says it spotted the problem on 30 September 2026 while upgrading how it monitors its IT environment — not because a fan reported fraud first. That timeline and the field list come from Levante’s own notice published around 9–10 October 2026 on levanteud.com, which remains the verified anchor for this Levante UD data breach record.
Canonical BreachHistory entry: https://breachhistory.com/levante-ud/levante-ud2026 (/levante-ud/levante-ud2026). The catalog uses recordsAffected: 0 because Levante has not published how many people are involved. Treat zero as “no census yet,” not as proof that nobody was touched.
What Levante has not confirmed: a stolen-data dump for sale, a named ransomware brand on a leak site, or evidence that attackers already used the information for fraud. The club’s wording is explicit on that gap — investigation continues, and as of the communication date there was no known fraudulent use and no confirmed exfiltration. Secondary reporting from MARCA (10 October 2026) and Levante-EMV (11 October 2026) restates the club statement; neither outlet supplies an affected-person count.
Who Levante UD is — and why member data matters
Levante Unión Deportiva is a professional football club based in the Orriols neighborhood of Valencia, playing home matches at the Ciutat de València stadium. Like every La Liga side, it runs a membership economy: socios (members), abonados (season-ticket holders), academy and first-team players, and a tienda online for merchandise. Those relationships require identity and contact data under Spanish law — often including national ID numbers (DNI for citizens, NIE for foreign residents), addresses, and billing-related fields.
Sports clubs are not banks, but their CRM and ticketing stacks can still hold sensitive categories when youth programs, medical clearance, or biometric access systems sit on the same estate. Levante’s notice acknowledges that possibility by listing, alongside names and contact details, datos de menores (minors’ data), datos de salud (health data), and datos de plantillas biométricas (biometric template data). Those lines appear in the primary club communication in Spanish and Valencian; do not treat them as rumor from forum posts.
For anyone asking “was I affected” after a Levante UD breach 2026 headline, the honest answer today is: if you are or were a member, season-ticket holder, player under contract, or online-store customer with an account, assume you could be in scope until Levante sends a narrower notice. The club promises further updates when it has them.
What happened — timeline from detection to public notice
Levante’s narrative starts with infrastructure work, not match-day chaos. On 30 September 2026, while updating the monitoring method for its systems, staff detected a security incident. Despite existing controls, the club says, some personal data processed for its relationships with members, ticket holders, players, and e-commerce clients may have been impacted.
Follow-on investigation attributed the event to an external attack that illegally infiltrated Levante’s environment and may have compromised confidentiality of that data. The club did not, in the public notice, describe malware families, initial access vectors (phished employee, exposed VPN, stolen API key), or dwell time before discovery. Those are normal gaps in a first-wave fan communication; they may appear later in an AEPD file summary or an updated FAQ.
Public-facing timing:
- 30 September 2026 — Incident detected during monitoring-system update (club-stated detection date).
- Early October 2026 — Internal security protocol activated; technical and organizational remediation steps listed below applied.
- ~9 October 2026 — Levante publishes “plan de blindaje digital” notice on its website (dated 9 Oct 2026 on the Spanish page).
- 10 October 2026 — MARCA publishes sports-desk coverage summarizing the club alert.
- 11 October 2026 — Levante-EMV publishes a local news piece noting the club has not detailed how many people are affected.
Between detection and the website post sits roughly a week and a half — inside the window many European organizations use to understand scope before mass email, but long enough that members may wonder why they heard nothing on social media first. Levante chose a formal notice on levanteud.com rather than a terse tweet; that matches how several Spanish clubs communicate compliance-heavy topics.
What data Levante says may be involved
The club’s inventory of potentially affected personal data includes:
- Name and surnames (nombre y apellidos)
- DNI/NIE — Spanish national or foreign-resident identity numbers
- Date of birth (fecha de nacimiento)
- Contact data — address, email, telephone
- Economic or financial data without payment methods (datos económicos o financieros sin medios de pago) — think invoicing or account metadata, not full card numbers in this description
- Minors’ data (datos de menores)
- Health data (datos de salud)
- Biometric template data (datos de plantillas biométricas)
Levante-EMV’s recap emphasizes names, DNI, address, email, phone, and financial fields without payment instruments — a subset of the full club list — which is why this article leads with the official levanteud.com text for health, minor, and biometric categories.
Interpreting “may contain” language: the club is not asserting every field for every person. It is flagging the union of data classes that lived in the affected server context. Forensics may later shrink or expand that list per individual notifications required under the EU General Data Protection Regulation (RGPD) and Spain’s implementing law (LOPDGDD).
What Levante has not said was exposed
The notice does not claim that payment cards, passwords to the online store, or match-ticket QR secrets were taken. It explicitly separates economic/financial information from medios de pago (payment methods). Until a follow-up letter says otherwise, do not assume full card PANs or CVVs from this communication alone.
There is also no club confirmation of:
- A public leak archive or torrent
- Demands for cryptocurrency ransom
- Operational disruption to La Liga fixtures or ticketing turnstiles
- A definitive count of members, players, or customers impacted
External attack — what “infiltration” implies technically
Levante labels the incident an illegal external infiltration that compromised confidentiality. That phrasing usually means unauthorized access to systems holding personal data, not merely a defaced homepage. The club tied discovery to a monitoring upgrade, which suggests either new telemetry surfaced an anomaly or the change window coincided with attacker activity — the notice does not distinguish those scenarios.
Without vendor names or CVEs, analysts should avoid pinning this on a specific ransomware affiliate. Spanish sports organizations have faced credential theft, exposed admin panels, and supplier-chain incidents in recent years; Levante’s described response — cutting remote administration from the internet, forcing MFA, and locking down backups — fits a playbook for “someone had network reach they should not have had.”
Levante also mentions preserving evidence and reviewing logs, including records requested from its hosting provider. That hint points to at least partly outsourced infrastructure, but the club has not named the host or whether data residency stayed in the EU.
Immediate technical and organizational response
According to the club notice, Levante activated its security protocol and took overlapping technical measures:
- Immediate blocking on all affected servers
- Closing remote access to those servers from the internet — administration only from internal club network and the systems team VPN
- Password changes across systems and mandatory two-factor authentication
- Closing internet access to backup storage and previously exposed administration services
- Rotating credentials for backup storage and affected services
- Encrypting backups
- Applying least privilege on backup access and removing unnecessary credentials from servers
- Preserving evidence and analyzing logs, including materials requested from the hosting provider
- Reviewing internal security policies
On the organizational side, Levante says it updated its data-protection management system and brought in specialized third parties, including an outsourced data protection officer (DPD), to support the upgrade.
That list reads like a post-incident hardening sprint: shrink the attack surface (no more internet-facing admin), break stale credentials, protect backups from being encrypted or stolen during follow-on moves, and prepare for regulator questions. Members should expect intermittent IT maintenance as those controls bed in.
AEPD notification and regulatory context
Levante states it notified the Agencia Española de Protección de Datos (AEPD), Spain’s supervisory authority, as required by applicable law, without prejudice to other legal steps. Under the RGPD, controllers typically must report a personal-data breach to the lead supervisory authority within 72 hours of becoming aware, when the breach is likely to pose a risk to individuals — unless the data was encrypted to a standard that renders it unintelligible without keys.
The public club page is not the same document as an AEPD registry entry. When the authority publishes a summary — sometimes months later — it may include approximate numbers or categories not present in the fan-facing FAQ. Until then, journalists and supporters should not invent a headcount.
Because minors’ and health data appear in Levante’s own list, regulatory scrutiny may focus on lawful basis, retention, and whether special-category data shared the same server segmentation as e-commerce names and addresses. That is speculation about process, not an allegation of wrongdoing; the club asserts it is improving its compliance framework.
Who is most at risk — by audience
Socios and abonados
Members and season-ticket holders routinely submit ID numbers for identity checks, youth linkage, or subsidized pricing. Combined with email and phone, that trio powers phishing that references your seat block, renewal deadline, or “exclusive socio survey.” If you hold a carnet, treat inbound messages mentioning Levante and asking for passwords or bank details as untrusted until verified through official channels.
Players and staff
Professional squads generate contracts, medical files, and sometimes biometric access data for training grounds. Levante explicitly names jugadores in scope. Player agents and family members should watch for impersonation attempts using leaked contact details — not necessarily full contract PDFs, which the club has not confirmed as exfiltrated.
Online store customers
E-commerce buyers may have shipping addresses and order history metadata in the same ecosystem as membership CRM. Even without payment methods, shipping fraud and refund scams remain plausible if email accounts reuse weak passwords elsewhere.
Minors and health-related records
Where the club processes youth academy enrollment or medical questionnaires, special-category data raises the stakes for targeted social engineering and reputational harm. Levante’s inclusion of these categories in its official list triggers heightened care for guardians — monitor youth email forwards and club-app notifications closely.
Phishing and fraud — what Levante warns about
Levante cautions that, given the nature of the data, people might see limited inconvenience such as phishing — emails asking for personal information — or similar deception. The notice repeats standard hygiene: scrutinize senders, ignore suspicious WhatsApp or SMS threads, do not click unknown links, do not download untrusted attachments, rotate passwords at least annually, and remember that Levante UD will never ask for passwords or confidential information by phone or email.
Concrete scenarios tied to this incident:
- Fake “socio renewal” portals cloning levanteud.com styling, harvesting DNI and card data the real club says was not in the compromised payment-method set — criminals may still ask for it.
- Messages claiming “your Levante account was locked due to the cyberattack” with a malicious reset link.
- WhatsApp groups offering discounted tickets “because of the server problem,” a common lure after sports-brand news cycles.
Contact the club’s data protection delegate at [email protected] for incident-specific questions — use that address from the official notice, not from an unsolicited message.
Sports-sector context — clubs as identity hubs
Football clubs aggregate fan identity at scale: membership cards, youth academies, retail, and sometimes stadium biometrics for access control. They are softer targets than tier-one banks but still hold document numbers attackers can pivot into broader identity theft, especially in countries where DNI/NIE numbers anchor many services.
La Liga clubs also operate under intense media scrutiny; a cyber incident during a return-to-top-flight season guarantees headlines even without a public dump. Levante’s transparency about an external attacker and AEPD notification aligns with how several Spanish organizations have handled 2025–2026 incidents — confirm intrusion, describe categories, defer counts.
This episode is distinct from unrelated ransomware claims against other brands you may see on leak trackers. BreachHistory catalogs Levante under a verified club notice, not an unverified leak-site listing.
What MARCA and Levante-EMV add
MARCA reported on 10 October 2026 that Levante disclosed the 30 September detection during monitoring upgrades, attributed the event to an external agent, and summarized containment steps plus AEPD notification. The piece does not advance technical forensics beyond the club text.
Levante-EMV on 11 October 2026 highlights local impact for Valencian supporters and repeats the club’s statement that no fraudulent use or exfiltration had been verified at communication time. Reporter María Bas notes explicitly that Levante has not detailed the possible number of affected people — reinforcing why BreachHistory keeps recordsAffected at zero until a census exists.
Primary sources — club notices in Spanish and Valencian
Read the full statements directly:
- Spanish: El Levante UD activa un plan de blindaje digital ante una anomalía detectada en sus servidores de datos
- Valencian: El Levante UD activa un plan de blindaje digital (versió valenciana)
Those pages host the authoritative field list, remediation bullets, DPD contact, and apology to supporters.
What you should do — action items
- Check official channels only. Look for direct email or postal notice from Levante UD rather than relying on social posts alone. Save any letter — it may list your specific data categories later.
- Email the DPD with questions. Use [email protected] from the club site; do not reply to unexpected threads asking for DNI scans or passwords.
- Rotate reused passwords. If your Levante tienda or socio portal password matches Gmail, banking, or other clubs, change those immediately and enable MFA where available.
- Watch for phishing in Spanish and Valencian. Attackers localize lures. Grammar errors and mismatched sender domains remain red flags.
- Guard minors’ inboxes. If a child is in Levante’s academy or youth programs, supervise account recovery flows and explain that the club will not ask for secrets by chat apps.
- Consider identity monitoring proportionally. Spain lacks a single U.S.-style credit freeze framework, but you can alert your bank to social-engineering attempts referencing leaked DNI/NIE and address pairs.
- Document suspicious contact. Forward phishing attempts to the DPD and, if financial loss occurs, report to police and your bank promptly — even though Levante has not confirmed active fraud from this incident yet.
- Re-read the canonical record. BreachHistory will update /levante-ud/levante-ud2026 if Levante publishes counts, sample notices, or new forensic detail.
Open questions investigators and fans still have
Reasonable unknowns after the first notice include: entry vector, whether encryption limited readable exposure, exact server roles (CRM vs. medical vs. biometrics), whether third-party processors were involved beyond hosting, and whether individual notification letters will cite Article 34 RGPD thresholds. Levante promises more communication when additional information is available.
Until then, describing the event as a confirmed “mass leak of every socio” overstates what the club admitted. The verified formulation is narrower: external attack, potential confidentiality breach across several data classes, no confirmed exfiltration or misuse at the time of writing, regulator notified, remediation underway.
How this fits BreachHistory’s verified standard
This row qualifies because Levante UD — the data controller — published a detailed incident communication on its official domain, notified the AEPD, and named affected relationship types (members, ticket holders, players, online customers). Trade press amplified without inventing numbers. BreachHistory does not fabricate records exposed figures; when Levante or the AEPD publishes a census, the catalog entry should be updated accordingly.
For related reading on how sports and entertainment brands handle identity incidents, see our coverage of other 2026 verified events linked from the blog index — each with its own primary sources and scope limits.
Bottom line for supporters
The Levante UD cyberattack is a controller-confirmed security incident with serious data-class implications — identity documents, contact paths, financial metadata without payment instruments, and special categories including minors, health, and biometrics per the club’s own list. It is not, on the evidence released through 11 October 2026, a confirmed public data dump or proven fraud campaign. Members should operate in a middle posture: take phishing and password reuse seriously, use [email protected] for verified guidance, and watch the official notice pages for the next update rather than rumor channels.
Last updated to reflect Levante’s October 2026 communications and MARCA / Levante-EMV reporting through 11 October 2026. No affected-person count is available; do not treat social-media estimates as fact.