We understand the mass sanctions email campaign is complete for Season Ticket holders at least.
Just sharing this info as we know there are STHs feeling anxious.
As per our statements, including joint statements across all fans groups, we absolutely reject this approach
Gathered views from multiple MUFC season ticket holders who received an email from the club restricting their accounts - causing anxiety to many.
Spoke to MUFC about why this is happening.
For @TheAthleticFC
https://t.co/FokkDkJGrE
The Latest MUFC Ticketing Sweeps: A Practical Guide for Match-Going Groups
Many more supporters have received emails from the club today. While the tone has been softened compared to previous compliance sweeps, the objective is clear: the club is targeting "super-users" who log into multiple accounts from the same network or device to submit away applications, handle renewals, check ballot results, etc.
My first response to United would be: understand your supporters and how they actually behave. Fans operate in communities, helping each other out and working together. Instead, you've looked at the data without fully understanding the behaviour behind it. Perhaps that's because you've relied on the customer journey SeatGeek provided, but supporters simply don't use the platform in the way it was designed. Yes, there are touts, but it is not clear from the negative responses you're receiving that you've taken the completely wrong approach.
The data analysis strategy makes sense in principle to stop possible touts, but the execution is deeply flawed. For decades, match-going fans have formed close-knit communities. We share logins to manage group away applications, support elderly/vulnerable/non-tech savvy friends and relatives, or, in one instance, I assisted a mate who was travelling abroad and could not bypass credit card 2FA checks; he relied on me to renew his Season Ticket for him. Others handle group renewals purely to consolidate Credit Card loyalty points. That’s clever thinking by the end user, not trying to get around a system.
If United wanted to find actual ticket touting, their analysis should have focused strictly on data linked to logins on the official MUFC Mobile App where ticket access is. That is where ticket touting could matter. Instead, they have cast an overly broad net, likely because app authentication jumps out to a standard mobile browser, making it difficult for their systems to separate standard web portal activity from app usage. I would advise United to focus their efforts in this area; this is likely to be an area of ‘suspicious activity’ which they claim to have on many accounts.
Crucially, there is absolutely nothing in the official Season Ticket T&Cs that prohibits you from sharing your online login details with someone you trust. Unless the club can definitively prove that a third party logged into your account, downloaded your digital ticket, and used it to enter the stadium and not you, they have incredibly weak grounds. This should be robustly challenged.
Furthermore, the Manchester United website is notorious for technical glitches. The Ticket Office itself has routinely advised fans to use manual workarounds, including logging into each other's accounts, to bypass issues that the SeatGeek platform simply wasn't built to handle. You can even manage a friend's account over the phone if permission is granted. Fans are stepping in to help each other because the club lacks the necessary staff to provide real-time support. It is entirely unfair to weaponise these practical workarounds against loyal supporters. I’m not even going to get started on the Queue-it software, which can block you on anything from first access to the site, to multiple refreshes for away tickets.
If you've received one of these review emails, my first advice is not to respond immediately. I know there are ongoing discussions with the club about their recent demands, and the situation could look very different by the end of the week – although it may not.
So, don't rush into anything. Instead, use the time to think about how you want to structure your individual response to best protect your rights. If I hear of any updates, I will, of course, post on the back of that.
What you should start to think about is the following, to be prepared:
- The Multi-Account Access: Explain that you act as the administrator for a genuine, non-commercial match-going group to coordinate away applications and renewals so you can travel together. Explicitly state that this is done manually with permission, and you have never logged in to download, use, or resell another person's match ticket.
- Third-Party Data Protection: The club will ask why you accessed a specific number of accounts. Do not volunteer a list of your friends' names or membership numbers. Under UK GDPR, you must protect their third-party data. Simply explain why you do it collectively.
- Devices and Locations: Keep your device list broad (e.g., personal phone, work phone, laptop). For locations, keep it standard (e.g., residential home, workplace network). Do not provide specific addresses. Crucially, the club's data analysis likely fails to account for how modern UK internet works. For example, Sky Broadband utilises MAP-T technology, meaning up to 16 separate households can share the exact same external IP address at the same time. A single IP flag could incorrectly link completely unrelated households; however, Device IDs would be different, and I have no idea what thresholds United has applied in what seems to be a poor analysis of the data.
- The Photo ID Demand: The club claims they will delete your ID after verification, but sending unencrypted scans of a passport or driving license via standard email is highly insecure in transit. Refusing to email the ID and demanding a secure upload method is a logical use of GDPR principles. If they insist on identity verification, they must provide a secure, encrypted upload function directly to the MUFC servers. Let’s also remember they used ID verification on us last summer, so why not now? I’ll tell you why: down to cost.
I know United read my posts, so I suggest they read the following statement:
“Sending unencrypted passport or driving license scans via standard email is explicitly advised against by the UK National Cyber Security Centre (NCSC) due to interception and storage risks. Under ICO guidance on Article 32 of the UK GDPR, organisations should provide secure, encrypted upload channels for sensitive identity verification."
(Link: https://t.co/C8MNh2Ut41)“
- Hold Them to Account: Throughout this review, ensure the club strictly adheres to the contractually promised 14-day turnaround timelines for both Stage 1 and Stage 2 of the appeals process.
If they uphold your restriction without providing specific evidence, you should immediately file a Subject Access Request (SAR) to force them to hand over your full system logs. See my post here: https://t.co/KhLav1ihBC
If you wish to start to look at a response, below is an email template you can use to frame your formal email reply to [email protected]. Please note that this is just a template, and you should ensure it is updated and adjusted to suit your specific individual circumstances and group setup before sending.
Email Response Template
Dear Appeals Team,
Re: Ticketing Account Review – Membership Number: [Your Number]
I am writing in response to your email regarding the review of my ticketing account activity between March 1 and July 12. I appreciate the opportunity to clarify my account activity, which is entirely legitimate, manual, and non-commercial.
Explanation of Multi-Account Access:
I act as the administrative lead for an established group of match-going friends and family members. Because we travel to fixtures together, I log in to their profiles solely to coordinate linked away match applications and to assist with season ticket renewals. This is done entirely manually with their explicit permission for administrative ease and to navigate known website limitations. I do not access these accounts to download, transfer, or use digital match tickets, nor do I engage in ticket resale or automated bot activity. This should be clear in your telemetry data.
Device and Location Confirmation:
Devices regularly used: [e.g., My personal mobile phone, work tablet, and personal laptop].
Locations:
My account is primarily accessed from my residential home network, and occasionally from my place of work during standard application windows.
Account Management Explanation:
As stated above, my account is managed manually by myself, or by a trusted coordinator within my match-going group whom I have authorised to submit joint applications on my behalf. When submitting group applications, we log in sequentially to our group's profiles to ensure our applications are linked for travel logistics.
Identity Verification:
While I am fully willing to verify my identity, sending raw, unencrypted scans of official government identification via standard email is highly insecure and creates an unnecessary data protection risk in transit. Please provide a secure, encrypted upload mechanism directly to the Manchester United servers so I can safely submit this data.
Given that this activity represents standard, manual group coordination by a loyal supporter, I look forward to your swift confirmation that my account is in full order.
Yours sincerely,
[Your Name]
[Your Membership/Season Ticket Number]
[Your Phone Number]
@MichaelLCrick The 1st Blair cabinet was northern based, many prominent cabinet members holding seats in Scotland and NE England in particular, eg., Blair, Brown, Cook, Straw, Cunningham, Prescott, Hoon, Beckett, Blunkett, Robertson, Milburn, Nick Brown, Cunningham, Taylor, Dewar, Mandelson
What awful news to hear that Kevin Keegan has passed away. A true English football hero from a bygone age. I remember his debut for Liverpool being on match of the day. England captain and a double European footballer of the year. Very sad. RIP Kevin. 😔
Like many others, my heart is heavy at the passing of the great Sir Garfield St Aubrun Sobers. He was always generous with his time and advice to me. He elevated Barbados and the West Indian Islands to a place of great and unprecedented standing in the world through his performance and leadership on the field. Sad he is no longer with us, but very happy that he came. We have memories of him than stand this game in good stead. RIP😥
It was with huge sadness that news of the death of the great Sir Garfield Sobers reached us here at Lord's today. His stature within the game is unmatched: he set the standard by which every player is measured. Our thoughts are with his family and the West Indies cricket community at this time.
There seem to be a lot of people whose account restrictions are being upheld. I’ve only seen one that hasn’t been so far. All this comes with no real direction or confirmation on what the supporter has actually done.
For anyone who can’t understand the reasoning due to insufficient information from the club and received an email telling them their sanction is being upheld, one of the next steps may be to raise a Subject Access Request (SAR).
Under UK law, any organisation holding your personal data must provide a copy of that data upon request, free of charge, and usually within one calendar month.
Crucially, "personal data" includes automated system logs, internal notes, telemetry data, and audit trails tied to your account. By forcing Manchester United to hand this over, you can bypass their vague customer service language and see the exact technical metrics (IP addresses, click rates, device IDs) that triggered their security flag.
When filing a SAR during a ticketing dispute, you should not just ask for "all data." Be highly specific so they cannot delay their response by claiming the request is too broad. You should demand:
- Ticketing Portal System Logs: All automated telemetry, access logs, user-agent data, and click-rate timestamps associated with your membership number between the specific investigation dates (March to July 12).
- IP Address and Geolocation History: The complete list of IP addresses recorded by their servers logging into your account, alongside any internal flags raised regarding multiple locations.
- Internal Communications and Notes: All internal emails, memos, CRM notes, or compliance review documentation mentioning your name or membership number.
- The Specific Fraud/Bot Detection Criteria Applied: The exact technical reason your account was flagged (e.g., exceeding a certain number of page refreshes per minute, or concurrent logins from distinct IPs).
Here is a template you can use for a Subject Access Request. You can email this directly to the club's Data Protection Officer or compliance team (usually [email protected] or via their main customer service channel).
------
Subject: Formal Subject Access Request (UK GDPR) – Account Restriction Inquiry
Dear Data Protection Officer,
Re: Subject Access Request
Name: [Your Name]
Membership / Season Ticket Number: [Your Number]
Email Associated with Account: [Your Email]
I am writing to make a formal Subject Access Request pursuant to the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
I recently received an email from the club’s ticketing compliance team stating that "sustained activity" on my account indicated a potential breach of terms, resulting in the temporary restriction of my account. The email failed to provide any specific technical data or evidence detailing what this activity entails.
To ensure my right to fairness and transparency under the law, and to properly formulate my appeal, please provide me with copies of the following personal data held by the club regarding my account between March 1 and July 12:
All digital access logs, telemetry data, server timestamps, page-refresh metrics, and user-agent records associated with logins to my account profile.
The complete list of captured IP addresses and inferred geolocations used to access my account during this period.
All internal communications, correspondence, memos, or system notes compiled by the ticketing, security, or compliance teams regarding my account or membership number.
Any automated profiling or automated decision-making logic logs that directly triggered the flag and subsequent restriction on my account.
As per ICO guidelines, I expect to receive this information without delay and at the latest within one calendar month of this request. If you require any standard identity verification to process this request, please contact me immediately via this email address.
Yours sincerely,
[Your Name]
[Your Phone Number]
------
How to Leverage This in Your Appeal
In your actual appeal email to [email protected] (due by July 27), you should explicitly mention that you have submitted a SAR:
"As the club has failed to outline the specific technical evidence behind these allegations, I have formally submitted a Subject Access Request (SAR) to the Data Protection Officer to obtain my account logs. Because the club’s deadline forces me to appeal before my legal data rights can be fulfilled, I expect the club to fully review my account profile manually and transparently provide the metrics they are relying on to justify this restriction."
@R_o_M On the other hand, a £35m profit on a 29-year old is a decent result, particularly for a team struggling to keep within FFP rules. A win-win transfer, I'd say, although the proof of that will be in how well Tielemans does in the next few seasons.
“If you’re not doing it, I’ll start singing Sweet Caroline!” 😂
@BumbleCricket has an important message about #BlueForBob 💙
To donate, simply text TEN to 70843 📲