Skip to main content

Levante UD reports a security incident that may have affected the data of members, players and customers

The Valencian club detected external access to its servers on 30 September while updating its monitoring system. It has reported that personal data of members, season ticket holders, players and online shop customers could be affected.

CybersecuritySeintec team2-3 min read
Levante UD reports a security incident that may have affected the data of members, players and customers

News summary

Levante UD has reported on its official website that on 30 September 2023, while updating its monitoring systems, it detected a security incident related to an external attack that had illegally accessed its servers.

According to the club, the data that could be affected include name, DNI or NIE, date of birth, contact details, financial data excluding payment methods, data on minors, health data and biometric templates. The club states that, as of the date of its communication, it was not aware of any fraudulent use or exfiltration.

Among the measures announced are the immediate blocking of the affected servers and closing remote access to those servers from the internet. The investigation is ongoing.

This case offers two lessons for any Spanish organisation that manages customer or member data: monitoring is what allows an intrusion to be discovered, and exposed remote internet access is one of the first things that must be secured. When health data, data on minors, or biometric data are involved, the obligation to protect and notify is even stricter.

Source: Levante UD — 9 October 2026

Frequently Asked Questions

When must a data breach be notified?
The GDPR requires notification to the supervisory authority within 72 hours of becoming aware of the breach, unless it is unlikely to pose a risk, and to the affected data subjects if the risk is high.
Why is monitoring important?
Because many intrusions go undetected for weeks. Active monitoring enables their detection and limits the potential damage.

Concepts mentioned in this article: Monitoring · Ticket

Detecting an intrusion in time requires constant vigilance. At Seintec, we monitor your systems, close exposed access points and guide you through the incident response. Talk to our team.

Contact Seintec

Related service

Managed SOC and MDR

Continuous monitoring, detection and response to security incidents across endpoints, servers, network and identities.

Next step

Would you like to implement these improvements in your company?

Speak with a Seintec expert and we will review how this applies to your infrastructure together.