← Levante UD

2026 Levante UD — external cyberattack; member/player/store data may be affected

2026 Unknown records affected Share on X

Data compromised

Per Levante UD 9 Oct 2026 notice (no headcount published): names; DNI/NIE; DOB; contact (address, email, phone); economic/financial data without payment methods; minors’ data; health data; biometric templates. Affects socios/abonados, players, online-store customers. No confirmed fraudulent use or exfiltration at disclosure.

Technical writeup

Verified Levante UD club notice (9 Oct 2026). On 30 Sep 2026, during a monitoring-method update, the club detected a security incident tied to an external attack that illegally infiltrated systems and may have affected personal data of members/season-ticket holders, players, and online-store customers. Listed categories include names, DNI/NIE, DOB, contact details, economic/financial data without payment methods, minors’ data, health data, and biometric templates. Club states no confirmed fraudulent use or exfiltration at notice time. Remediation: blocked affected servers, closed internet remote admin (internal/VPN only), credential resets + MFA, backup encryption/least privilege, evidence preservation, AEPD notification; DPO [email protected]. No published census — recordsAffected 0. companyConfirmed true.

Root cause

External attack detected 30 Sep 2026 during monitoring-system update; illegal infiltration compromising confidentiality of some personal data (exfiltration not confirmed at notice)

References