Football supporters have been issued a stark warning over a significant rise in ticket fraud, with new data revealing victims are losing an average of £215, as criminals prepare to exploit the upcoming World Cup.
Lloyds Bank’s analysis indicates a staggering 36 per cent surge in football ticket scams during the current Premier League season. The findings, based on thousands of fraud cases between October 2025 and March 2026 compared to the previous year, highlight a growing threat to fans.
Fraudsters are specifically targeting supporters of top-tier clubs like Arsenal, Liverpool, Chelsea, and Manchester United, alongside high-demand fixtures such as the FA Cup and Champions League Finals.
While the average victim loses £215, some have been defrauded of hundreds or even thousands for non-existent “season tickets” or VIP packages.
With the upcoming World Cup, Lloyds anticipates a…
IT & DATA SECURITY (MITIGATING THE “INSIDER THREAT”)
As seen in the TD Bank case, an employee with too much “access” can sell your customer data to syndicates.
- Principle of Least Privilege (PoLP): Employees should only have access to the specific folders and databases required for their current task.
- Access Revocation: Have a “Termination Checklist” that ensures all digital access (Email, VPN, Banking) is revoked within 60 minutes of an employee resigning or being dismissed.
- System Logs & Audit Trails: Enable “Read/Write Logging” on your server. If a customer’s data is leaked, you need to know exactly which login accessed that record and at what time.
- Encryption at Rest: Ensure that sensitive files (like your customer ID numbers or payroll spreadsheets) are encrypted so that if a staff member copies them to a USB, they cannot be read.
