Skip to main content
Blog
Blog

Ticketmaster Data Breach Déjà Vu: What You Need to Know

Yesterday on May 29, 2024, news broke of an alleged data breach involving Ticketmaster, a prominent ticket sales and distribution company. Ticketmaster has confirmed unauthorized activity within a third-party cloud database environment, claiming to have exposed the personal information of over 500 million customers. This breach includes sensitive data such as emails, phone numbers, addresses, and financial details. ShinyHunters, a notorious attacker, reposted the breach . According to reports,

May 30, 2024 4 min read
Ticketmaster Data Breach Déjà Vu: What You Need to Know cover image

TL;DR: Ticketmaster 560M ShinyHunters Snowflake breach

  • Breached twice, same lesson: Ticketmaster has been breached twice through two very different third parties, and the pattern is the story. When the same brand keeps getting hit, the fault line is your vendor perimeter, not your walls.
  • cside covers the browser side: The 2024 leak exposed 560 million records through a third-party Snowflake environment, listed for $500,000 on BreachForums by ShinyHunters, and the 2018 attack was already a client-side Magecart skimmer. cside covers the browser-side half of that perimeter with continuous script monitoring.
  • Start with the scripts: If a third party ever handles your customer data, audit both their cloud posture and the JavaScript they inject on your pages. If you can only afford one this quarter, start with the scripts, because that is where the 2018 attack lived.

Short on time? See cside's in-browser Magecart and skimmer blocking. It covers everything below in one deployment.

Yesterday on May 29, 2024, news broke of an alleged data breach involving Ticketmaster, a prominent ticket sales and distribution company. Ticketmaster has confirmed unauthorized activity within a third-party cloud database environment, claiming to have exposed the personal information of over 500 million customers. This breach includes sensitive data such as emails, phone numbers, addresses, and financial details.

Dark-web forum post advertising the stolen Ticketmaster customer data for sale

ShinyHunters, a notorious attacker, reposted the breach . According to reports, the data from this breach has been put up for sale for a $500.000 asking price on BreachForums, a site previously taken down by the FBI but has since resurfaced. This development is concerning, considering the extensive amount of data allegedly compromised.

The data allegedly includes:

  • 560 million full customer details (including names, addresses, emails, phone numbers, and potentially more)
  • Ticket sales, event info, and order details
  • Credit card details, some including customer name, last 4 digits of the cards, and expiration dates
  • Customer fraud details
  • ... and more
Screenshot of a sample of stolen Ticketmaster personal details shared by the attacker/seller

Snippet of personal details sample data set shared by the attacker/seller:

Screenshot of a sample of stolen financial data shared by the attacker/seller

Another snipper of sample financial data set shared by the attacker/seller:

Another screenshot of the sample stolen Ticketmaster data shared by the attacker/seller

The Australian Home Affairs Department has confirmed a cyber incident impacting Ticketmaster customers. An antitrust complaint was also filed against Ticketmaster and Live Nation in California on May 23, 2024, adding to the company's legal troubles.

Historical context: Magecart attack

This isn't the first time Ticketmaster has faced a significant data breach. Previously, the company was attacked by the Magecart group, a notorious cybercriminal collective known for their innovative and damaging tactics. In the Magecart attack, the group infiltrated Ticketmaster's supply chain by injecting malicious code into third-party software used by the company. This code silently captured payment information entered by customers on Ticketmaster's website, redirecting it to the attackers.

These incidents expose real vulnerabilities in online ticketing systems, particularly in the supply chain and client-side components that attackers often exploit to cause major data breaches.

Attack vector

Ticketmaster confirmed that the breach occurred through unauthorized access to a third-party cloud database provider, Snowflake.

How cside can help

Given the repeated cyber threats facing companies like Ticketmaster, cybersecurity measures need to cover the entire attack surface, including client-side vulnerabilities. Traditional security solutions often overlook what happens in a user's browser, where many attacks, including the alleged Ticketmaster breach, take place.

cside monitors and secures your entire digital environment, including client-side activity. It continuously watches third-party scripts for injection attacks and other client-side threats, catching and mitigating them in real time before they can cause harm.

You can get started for free and protect your site today.

For further inquiries and detailed reports, contact our support team.

Simon Wijckmans
Founder & CEO

Founder and CEO of cside. Previously a product manager on Cloudflare Page Shield (now Cloudflare Client-Side Security). Co-chair of the W3C Anti-Fraud Community Group and a Forbes 30 Under 30 honoree. Building accessible security against client-side attacks, web security is not an enterprise-only problem.

Monitor and Secure Your Third-Party Scripts

Gain full visibility and control over every script delivered to your users to enhance site security and performance.

Start free, or try Business with a 14-day trial.

cside dashboard interface showing script monitoring and security analytics
Related Articles
Book a demo

Want to walk through this with an engineer?

Thirty minutes, on your own site. Not a slide deck.

We'll show you:

Which third-party scripts are running on your site right now
Where you stand on PCI DSS 6.4.3 and 11.6.1
How much of your traffic is bots and AI agents

Rather just send a question?

Finding open slots…

Real humans only. We'd know.

Having trouble booking? Open scheduler in a new tab

What are you trying to solve?

Tell us in a line and we'll come back with something useful, not a generic pitch.

We usually help with:

Seeing which third-party scripts run on your site
PCI DSS 6.4.3 and 11.6.1 evidence
Bots, AI agents and account takeover

Prefer to just book a time? Pick a slot instead