Blog
Cyber Threat Intelligence

Cineworld Glitch Purportedly Allows Users To See Member Card Details

On 17 September 2026, users on X (formerly Twitter) posted that payment details belonging to other individuals had appeared on the Cineworld app under their personal accounts.

September 18, 2026
15
min read
CYJAX
Table of contents
Share

On 17 September 2026, users on X (formerly Twitter) posted that payment details belonging to other individuals had appeared on the Cineworld app under their personal accounts. The UK-based cinema chain had rolled out a new app and website update just two days previously, with Cineworld Unlimited members appearing to be particularly affected by this issue. Cineworld Unlimited is a scheme which allows users to watch unlimited films and receive exclusive discounts and member rewards. One of the most viewed threads regarding this can be seen in the figures below.

Figure 1 – User dyspraxicdoll posts that they are able to see other users’ data.
Figure 2 – Cineworld’s response.
Figure 3 – User dyspraxicdoll posts proof of seeing card details.
Figure 4 – Cineworld’s statement that it was a bug.

Despite the cinema chain stating that dyspraxicdoll was the only user to report this issue, multiple posts on X showed that other users also had problems with random card details and transactions appearing in their accounts. These are shown in the figures below.

Figure 5 – User lucy_fender posts about seeing random transactions.
Figure 6 – User mowenbutterfly’s post about wrong card details being in their account.
Figure 7 – User limaballslap’s post about wrong card details being in their account.

These posts highlight how the issue appears to be more widespread than Cineworld previously stated in its first response. This is further evidenced as users on other social media platforms such as Reddit also appear to be experiencing the same issue.

Figure 8 – Reddit users post about the same issue.
Figure 9 – Reddit users post about the same issue.

As users can allegedly see card details that do not belong to them, this could constitute the unauthorised exposure of personally identifiable information (PII) and financial data under UK GDPR. Under this legislation, organisations have 72 hours to report a breach to the ICO or face a fine of up to £8.7 million or 4% of global turnover. Whilst Cineworld has stated that the issue is just a glitch, this may still constitute a failure of security. This is because Article 32 of GDPR states that companies must use technical and organisational measures to ensure that data is kept secure. As such, the reported glitch means that users purportedly being able to see random card details is a failure of this and may be classed as an unauthorised personal data breach. Additionally, this may also constitute a failure to comply with the Payment Card Industry Data Security Standard (PCI DSS), a global security framework which ensures that organisations safely accept, process, store, and transmit card data. This framework is managed by the PCI Security Standards Council and applies to all organisations which handle debit or credit cards. If an organisation fails to comply with PCI DSS, it effectively breaches its merchant agreement contract with its payment processor or acquiring bank. This can lead to monthly fines for non-compliance and further financial penalties if card details end up being stolen. Scheme fines can then be passed down and the ICO can also act if customer personal data was exposed under UK law.

There is currently no evidence of this alleged information being misused; however, fraudsters and cybercriminals are known to use stolen card details to conduct malicious activity. This may include making fraudulent online purchases or placing names, numbers, and CVVs into bundles to be sold on cybercriminal marketplaces. Cybercriminals which are financially motivated often use stolen card details to make a profit, making them a lucrative asset to those operating across the landscape. At the time of writing, there has been no observed threat actor discussion regarding this potential leak.

More broadly, this issue will likely cause reputational damage to Cineworld. The app and website appear to have been developed within the UK, with Cineworld plc and digital development agency Can Factory being responsible for managing and publishing the service. What this incident highlights is a lack of safeguarding in the app update, which could potentially lead to financial harm if a user were to attempt to misuse the allegedly exposed details. In addition to this, users on Reddit have been observed negatively commenting on the app update, as shown in the figure below.

Figure 10 – Reddit users negatively discuss the app update.

The mention of UAT is in reference to user acceptance testing, which is the final phase of software development where actual users test an application to see if it meets business requirements and operates as expected. As such, the unintentional exposure of card details combined with a lack of user satisfaction with the app update itself will likely increase the reputational damage caused. This negative rhetoric is likely to continue if Cineworld is deemed to not have adequately addressed user concerns regarding these issues.

Subscribe for weekly updates

Receive our latest cyber intelligence insights delivered directly to your inbox

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Share
Get started

Get Started with CYJAX CTI

Empower Your Team. Strengthen Your Defences.CYJAX gives you the intelligence advantage: clear, validated insights that let your team act fast without being buried in noise.

Link Copied