September 28, 2024

Aston Villa is aware of recent news stories about a publicly available AWS S3 bucket that allegedly holds fan membership information.

First and foremost, Aston Villa values the privacy and security of its fans’ personal data and is conducting a thorough investigation into these complaints, led by its Data Protection Officer and supported by the Club’s incident response team.

The Club thinks the claims are about a vulnerability on one of its service provider’s systems, which the Club understands has been resolved. Our service provider notified us that no passwords or payment information had been compromised. The Club continues to cooperate closely with the service provider, who is conducting its own forensic investigation.

The Club would like to reassure its fans that it is taking all necessary steps to protect personal data, including reporting the incident to the Information Commissioner’s Office (ICO). The Club will continue to provide updates from the ongoing inquiry.

Updated May 28, 2024.

 

Leave a Reply

Your email address will not be published. Required fields are marked *