TL;DR: Ticketmaster 560M ShinyHunters Snowflake breach
- Breached twice, same lesson: Ticketmaster has been breached twice through two very different third parties, and the pattern is the story. When the same brand keeps getting hit, the fault line is your vendor perimeter, not your walls.
- cside covers the browser side: The 2024 leak exposed 560 million records through a third-party Snowflake environment, listed for $500,000 on BreachForums by ShinyHunters, and the 2018 attack was already a client-side Magecart skimmer. cside covers the browser-side half of that perimeter with continuous script monitoring.
- Start with the scripts: If a third party ever handles your customer data, audit both their cloud posture and the JavaScript they inject on your pages. If you can only afford one this quarter, start with the scripts, because that is where the 2018 attack lived.
Short on time? See cside's in-browser Magecart and skimmer blocking. It covers everything below in one deployment.
Yesterday on May 29, 2024, news broke of an alleged data breach involving Ticketmaster, a prominent ticket sales and distribution company. Ticketmaster has confirmed unauthorized activity within a third-party cloud database environment, claiming to have exposed the personal information of over 500 million customers. This breach includes sensitive data such as emails, phone numbers, addresses, and financial details.

ShinyHunters, a notorious attacker, reposted the breach . According to reports, the data from this breach has been put up for sale for a $500.000 asking price on BreachForums, a site previously taken down by the FBI but has since resurfaced. This development is concerning, considering the extensive amount of data allegedly compromised.
The data allegedly includes:
- 560 million full customer details (including names, addresses, emails, phone numbers, and potentially more)
- Ticket sales, event info, and order details
- Credit card details, some including customer name, last 4 digits of the cards, and expiration dates
- Customer fraud details
- ... and more

Snippet of personal details sample data set shared by the attacker/seller:

Another snipper of sample financial data set shared by the attacker/seller:

Legal and official responses
The Australian Home Affairs Department has confirmed a cyber incident impacting Ticketmaster customers. An antitrust complaint was also filed against Ticketmaster and Live Nation in California on May 23, 2024, adding to the company's legal troubles.
Historical context: Magecart attack
This isn't the first time Ticketmaster has faced a significant data breach. Previously, the company was attacked by the Magecart group, a notorious cybercriminal collective known for their innovative and damaging tactics. In the Magecart attack, the group infiltrated Ticketmaster's supply chain by injecting malicious code into third-party software used by the company. This code silently captured payment information entered by customers on Ticketmaster's website, redirecting it to the attackers.
These incidents expose real vulnerabilities in online ticketing systems, particularly in the supply chain and client-side components that attackers often exploit to cause major data breaches.
Attack vector
Ticketmaster confirmed that the breach occurred through unauthorized access to a third-party cloud database provider, Snowflake.
How cside can help
Given the repeated cyber threats facing companies like Ticketmaster, cybersecurity measures need to cover the entire attack surface, including client-side vulnerabilities. Traditional security solutions often overlook what happens in a user's browser, where many attacks, including the alleged Ticketmaster breach, take place.
cside monitors and secures your entire digital environment, including client-side activity. It continuously watches third-party scripts for injection attacks and other client-side threats, catching and mitigating them in real time before they can cause harm.
You can get started for free and protect your site today.
For further inquiries and detailed reports, contact our support team.









