The Seattle Mariners arrived at Dodger Stadium on July 28 for a three-game interleague series against MLB's best team — and millions of fans immediately reached for their phones to check the MLB Ballpark app. That reflex carries a risk most fans never see coming. A class action lawsuit filed against MLB Advanced Media in September 2025 exposed a pattern of credential stuffing attacks that left hundreds of fans watching their digital tickets vanish minutes before first pitch — and the structural weaknesses that enabled those thefts have not been fully closed heading into the 2026 stretch run.
What the 2025 MLB App Breach Revealed
In August and September 2025, fans across the country began reporting the same alarming experience: tickets stored in the MLB Ballpark app disappeared from their accounts — or were silently transferred to anonymous users — without any authorization or warning. MLB acknowledged publicly that "bad actors" had used leaked credentials harvested from unrelated data breaches to log into fan accounts through a method security professionals call credential stuffing.
A class action lawsuit followed, alleging that MLB Advanced Media had allowed "systemic cybersecurity breaches" by failing to implement protections that other digital ticketing platforms treat as baseline: mandatory two-factor authentication (2FA), enforced delays on ticket transfers, and a fallback option to print physical tickets. The complaint described the app's security posture as "woefully insufficient" compared to industry norms for digital wallet platforms.
Verizon's Data Breach Investigations Report found that 88% of web application attacks involve stolen or reused credentials — the exact mechanism MLB acknowledged in its breach response. That figure explains why attackers target sports apps during high-profile games: demand is highest, attention is divided, and most fans don't check their ticket wallet until they are already in the parking structure.
Why Sports Apps Are Prime Credential Stuffing Targets
IT security experts describe sports ticketing platforms as structurally attractive targets — not because they hold more sensitive data than banks, but because the assets they hold convert to cash faster than almost any other credential-stuffed account.
Three factors concentrate the risk:
High-value, time-sensitive assets. A Dodger Stadium lower-deck ticket for a marquee interleague series can command $200 to $800 on the secondary market the day of the game. A ticket stolen and transferred at 9 a.m. can be resold by noon, before the victim has any meaningful recourse.
Low-friction resale. Peer-to-peer ticket marketplaces have limited buyer verification at the point of listing. A bad actor who successfully transfers a ticket can list it simultaneously on multiple platforms within minutes of the transfer completing, making recovery nearly impossible once the transfer is confirmed.
Credential reuse at scale. The Cybersecurity and Infrastructure Security Agency (CISA) emphasizes that enabling multi-factor authentication is the single most effective step individuals can take to block automated account takeover attempts. Yet a large share of sports app users still rely on the same email and password combination they use across retail, streaming, and social media — a pattern that attackers exploit automatically after any breach involving those credentials. Security intelligence teams documented 2.8 billion passwords posted on criminal forums in 2024 alone, meaning the credential lists available to even low-skill operators are enormous and regularly refreshed.
The $390 Scenario: A Concrete Look at How Fans Lose Tickets
Here is a specific scenario grounded in the pattern documented in the MLB app class action.
A Mariners fan living in Los Angeles buys two field-level tickets to the July 28 game at Dodger Stadium in May 2026, paying $195 each — $390 before fees. He stores both tickets in his MLB Ballpark app account using the same email and password he has used since 2021 for an online home goods retailer.
In June 2026, that retailer suffers a credential breach. His email and password appear in a harvested list sold on a criminal forum within 72 hours of the breach. On July 25 — three days before the game — an automated credential stuffing bot runs his credentials against the MLB Ballpark app. The login succeeds on the first attempt. Within four minutes, both tickets are transferred to an account tied to a disposable email address. No mandatory transfer delay triggers. No 2FA prompt appears. No email alert reaches the fan's inbox.
He opens the app on the morning of July 28 to find an empty ticket wallet. He contacts MLB support: the transferred tickets already show as valid scans from a secondary buyer. His credit card chargeback is disputed by the third-party ticketing processor. With face value at $390 and market resale value approaching $700 on game day, he absorbs a real financial loss with no effective consumer protection mechanism specifically designed for stolen digital tickets under current terms of service.
The if-then logic is direct: if mandatory 2FA had been in place, the credential stuffing attempt would have been stopped at the login screen, regardless of the leaked password. If a 24-hour transfer delay had been enforced, the fan would have received an alert before the tickets left his account. If a unique, randomly generated password had been in use for the MLB app, the credentials from the retailer breach would have been useless against it. Each protection is technically available today. None are currently mandatory in the MLB Ballpark app.
What an IT Security Expert Recommends Before the Next Game
For individual fans, the corrective steps are straightforward to understand but require deliberate action. For businesses — corporate suite holders, hospitality firms, and companies that manage shared season ticket accounts for client entertainment — the exposure is more complex and typically warrants a professional audit.
IT security consultants recommend three immediate steps for any fan holding digital sports tickets:
Enable 2FA now on your MLB account and the email address linked to it. Following pressure from the 2025 class action, the MLB Ballpark app added optional 2FA. Go to account settings, navigate to security, and activate authenticator-app-based 2FA rather than SMS verification — SMS 2FA is vulnerable to SIM-swapping attacks, which represent a separate but related threat vector.
Generate a unique password specifically for your MLB account. A password manager creates and stores a random credential per platform, breaking the credential reuse chain that makes stuffing attacks possible. Most password managers also actively flag if a stored password appears in known breach databases, giving you a heads-up before an attack occurs.
Review all linked payment data and set a fraud alert. An attacker who logged into your MLB account saw your saved card's last four digits and billing address. Placing a free fraud alert with your credit bureau costs nothing and triggers additional verification for new credit inquiries for 12 months — closing a secondary window that exists regardless of whether tickets were taken.
For organizations managing ticket inventories — law firms, financial advisory practices, real estate companies — a credential exposure audit identifies which corporate email accounts appear in known breach databases and documents what shared access exists across season ticket platforms. Firms in regulated industries should treat this the same as any other data access review. Connecting with a verified IT security specialist through ExpertZoom gives businesses access to professionals who specialize in consumer account security and digital asset protection without the commitment of a full-retainer engagement.
Security Follows the Audience — and Attackers Know It
The Dodgers entered this series at 67-39, MLB's best record — built in part on a rigorous data infrastructure that applies analytical precision to every roster decision. The irony is that the platform fans rely on to enter Dodger Stadium operates with materially less rigor when it comes to protecting those same fans' accounts.
Security researchers consistently document that high-profile sporting events correlate with spikes in automated credential stuffing attempts. The pattern holds across sports: attackers time their campaigns to coincide with peak app traffic because suspicious login patterns are harder to detect against a spike baseline, and distracted, excited fans are less likely to notice unusual account activity until it is too late.
The Mariners-Dodgers series at a sold-out Dodger Stadium is precisely the kind of event that drives that traffic — and those targeting windows. The 15 minutes required to enable 2FA, set a unique password, and review linked payment data is the most useful security investment a fan can make before opening the app on game day.
This article addresses digital account security practices. For specific legal advice regarding a disputed ticket loss or a data breach claim, consult a qualified attorney or IT security specialist. Individual circumstances vary.

Daniel Miller