An Ajax data breach from 2017 has resurfaced after years of silence. The case shows how a serious security issue stayed hidden due to legal pressure on an ethical hacker. It also raises broader concerns about transparency and responsible disclosure.


2017 breach exposed sensitive ticketing data

The Ajax data breach began in 2017 when an ethical hacker discovered a vulnerability in systems linked to AFC Ajax.

The flaw provided access to the club’s ticketing environment. Through that access, the researcher could view sensitive information tied to fans, employees, and high-profile individuals.

Ticketing systems often store personal data such as names, contact details, and purchase history. Because of that, even limited access can expose valuable datasets.


Hacker silenced through NDA agreement

The breach remained undisclosed for years because the hacker, Abdoul Rasnab, signed a non-disclosure agreement.

The agreement prevented him from sharing details about the vulnerability. It also restricted further testing without permission.

Rasnab later stated that he felt pressured to accept these terms. As a result, the incident stayed hidden despite the potential impact.


New findings triggered public disclosure

The story resurfaced after Rasnab identified another vulnerability years later. This newer issue reportedly exposed data linked to hundreds of thousands of fans.

He contacted the organization again before taking further steps. However, he faced legal threats instead of a collaborative response.

This situation led him to disclose both the new vulnerability and the earlier Ajax data breach.


Ticket system weaknesses increased risk

The original issue involved a ticketing system connected to a third-party provider. This setup expanded the attack surface and introduced additional risk.

By exploiting the vulnerability, the hacker could:

  • Access personal data of fans and staff
  • View records tied to high-profile individuals
  • Interact with ticketing-related information

Such access could enable fraud or unauthorized use of tickets if exploited maliciously.


Disclosure practices under scrutiny

The Ajax data breach highlights ongoing tensions around ethical hacking. Researchers often report vulnerabilities to help organizations improve security.

However, legal pressure can discourage open disclosure. In this case, the NDA delayed awareness for several years.

Modern security practices increasingly support coordinated disclosure. Many organizations now work with researchers instead of restricting them.


Conclusion

The Ajax data breach shows how critical vulnerabilities can remain hidden for years. Legal agreements and pressure prevented early disclosure. While the case is now public, it raises concerns about accountability. Without transparent handling of security issues, similar incidents may continue to stay undisclosed.


0 responses to “Ajax data breach hidden since 2017”