TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ticketmaster breach affects more than half a billion users

223 pointsby RafelMri12 months ago

30 comments

JohnMakin12 months ago
&gt; In 2020 it admitted it hacked into one of its competitors and agreed to pay a $10m fine.<p>Lol, if an individual does this, you&#x27;re going to go to jail. A company does this? Tiny fine. What a world we live in.
评论 #40536978 未加载
评论 #40537791 未加载
评论 #40537594 未加载
评论 #40537111 未加载
JadoJodo12 months ago
I feel sad saying this: I don&#x27;t think it&#x27;s right, but I worry less and less about these as time goes on; Not because I don&#x27;t think it sucks, but because my information has been in so many breaches up to this point that I&#x27;m not sure what value there is left in any data that might appear in subsequent breaches.
评论 #40514295 未加载
评论 #40536702 未加载
评论 #40514190 未加载
skilled12 months ago
vx-underground on Twitter,<p>&gt; Based on data provided to us by the Threat Group responsible for the compromise, we can assert with a high degree of confidence the data is legitimate. Date ranges in the database appear to go as far back as 2011. However, some dates show information from the mid-2000&#x27;s.<p>&gt; NOTE: The data provided to us, even as a &#x27;sample&#x27;, was absurdly large and made it difficult to review in depth. We are unable to verify the authenticity of financial information. Briefly skimming the PII present in the dump, it appears authentic.<p><a href="https:&#x2F;&#x2F;x.com&#x2F;vxunderground&#x2F;status&#x2F;1796063116574314642" rel="nofollow">https:&#x2F;&#x2F;x.com&#x2F;vxunderground&#x2F;status&#x2F;1796063116574314642</a><p>---<p>No official confirmation yet.
评论 #40536331 未加载
aresant12 months ago
Interesting this is marketed for $500k as a &quot;One Time Sale&quot; (1)<p>I find the &quot;honor amongst thieves&quot; part so interesting in these breach stories<p>(1) Troy Hunt, via an &quot;X&quot; user has a screenshot to the actual sale -&gt; <a href="https:&#x2F;&#x2F;x.com&#x2F;troyhunt&#x2F;status&#x2F;1795551650553491870" rel="nofollow">https:&#x2F;&#x2F;x.com&#x2F;troyhunt&#x2F;status&#x2F;1795551650553491870</a>
评论 #40519046 未加载
评论 #40514349 未加载
评论 #40514277 未加载
评论 #40514193 未加载
评论 #40515254 未加载
Bluestein12 months ago
PS. I just wanted to note, this is by the same outfit also responsible for the Santander break. (Both, apparently, due to a successful breach of an upstream storage provider).-
评论 #40536416 未加载
评论 #40536774 未加载
评论 #40537437 未加载
overstay893012 months ago
Surprised it didn&#x27;t happen sooner, their infra guys are getting paid next to nothing and there&#x27;s very little competence left on the team.
bartread12 months ago
On one hand, yes, there&#x27;s a certain amount of schadenfreude here, because I have on multiple occasions been more or less annoyed by Ticketmaster. On the other hand, because I&#x27;ve used them quite a lot (because for many events, what other choice is there?), I can&#x27;t say I&#x27;m terribly happy that my personal information has been so thoroughly exposed via this hack. And I&#x27;m more than a bit frustrated that Ticketmaster&#x2F;Live Nation have been so careless and sloppy with their security - and employee training and vetting - to allow this to happen.
AdmiralAsshat12 months ago
Boy I sure am glad that Ticketmaster <i>refused</i> to let me change my email address some months back when I was trying to clean up my profile and change the registered address from my_handle@gmail.com to my_handle+ticketmaster@gmail.com.
评论 #40536332 未加载
评论 #40536381 未加载
评论 #40538348 未加载
评论 #40537051 未加载
cush12 months ago
I continuously wonder how we keep building multi-billion dollar applications where both basic consumer protections aren’t in place and there’s almost no liability for the companies running them.<p>A kid working at McDonalds requires a safe food handling certificate, and the store will be shut down if an inspector sees their fridge is too warm.<p>Hopefully with E2E encryption, passkeys, and the like, the end of days is near for these massive data leaks, but without real consequences, these companies will never realize holding millions of people’s personal information is both a liability as well as an asset.
评论 #40537380 未加载
ctippett12 months ago
Looks to be officially confirmed. I just received the following email from Ticketek Australia:<p>&gt; Dear Ticketek Customer,<p>&gt; We are writing to let you know that Ticketek has become aware of a cyber incident impacting Ticketek Australia account holder information, which is stored in a cloud-based platform, hosted by a reputable, global third party supplier.<p>&gt; We would like to reassure you that Ticketek has secure encryption methods in place for all passwords and your Ticketek account has not been compromised. In addition, we utilise secure encryption methods to handle credit card information and transactions are processed via a separate payment system which has not been impacted. Ticketek does not hold identity documents for its customers.<p>&gt; Since our third party supplier brought this to our attention, over the past few days we have worked diligently to put every resource into completing an investigation, so that we can communicate with you as quickly as possible. We wanted to notify you early to enable you to take steps to protect your information as a precautionary measure.<p>&gt; We have also notified the Australian Cyber Security Centre (ACSC) and we are liaising with the Office of the Australian Information Commissioner (OAIC) and the National Office of Cyber Security in relation to the incident.<p>Full email: <a href="https:&#x2F;&#x2F;imgur.com&#x2F;a&#x2F;HOwR98C" rel="nofollow">https:&#x2F;&#x2F;imgur.com&#x2F;a&#x2F;HOwR98C</a>
leejo12 months ago
I assume Ticketmaster are fighting fires at the moment, or it could be coincidence, as I logged in to change my [unique to Ticketmaster] password and the 2FA confirmation appears to be broken, as it gave the same code 3 times and wouldn&#x27;t accept it, plus the emails to reset the password aren&#x27;t going out (or are going out slowly).<p>Hope you hashed, salted, peppered those passwords Ticketmaster. And I hope you were following PCI level 1 correctly otherwise if this is true then you&#x27;re a bit fucked really aren&#x27;t you.
adancalderon12 months ago
They should have kept Terry. He would have been vigilant about the three letter agencies as well.
epiccoleman12 months ago
&gt; To its critics, it seems Ticketmaster may be experiencing some karma lately for years of being the bane of concertgoers&#x27; existence.<p>Ah yes, karma, that legendary force which revenges itself upon evil businesses like Ticketmaster by <i>checks notes</i> exposing the personal and financial information of their unwilling customers.
svdr12 months ago
The attackers are demanding only $500,000 as a ransom payment, that&#x27;s cheap!
评论 #40537881 未加载
评论 #40536887 未加载
skilled12 months ago
This is not verified. Mashable pulled a dirty headline by writing on this based on speculation.<p>The initial account that shared the sale had no reputation on the forums. But it was then reposted by one of the admins, and that is the only piece of credibility this story has.
评论 #40514271 未加载
wood_spirit12 months ago
Hopefully we get details on _how_ the snowflake employee was hacked.<p>It makes us wonder how things could be tightened up and what can be applied to our own organisations.<p>If the hackers got passwords then how come there wasn’t 2FA?<p>Or did they get a Trojan onto an employee computer and surf onto it the corporate vpn?<p>Or did they corrupt an employee?<p>Or did the evil maid or something?<p>And how long did they have access?<p>Or another approach?
flerchin12 months ago
Seems like a big deal, but pretty much the only data ticketmaster would have is a stored credit card, address, name, and purchase history. Right? Perhaps passwords are valuable because many folks reuse them across sites.<p>I don&#x27;t see appreciable movement in their stock at all.
评论 #40539431 未加载
olliej12 months ago
Can’t wait for my 6 months of Free Credit Monitoring (tm)
评论 #40515949 未加载
rasz12 months ago
&gt; from<p>OF, stolen data _of_ 560M Ticketmaster Users. Mitchell &amp; Webb - Identity Theft all over again.
WalterBright12 months ago
As usual, organizations with giant databases do not compartmentalize the data.
ivirshup12 months ago
Guess they shoulda spent some of those ticket fees on a security team.
评论 #40514174 未加载
spdustin12 months ago
I despise this company with a white hot fury that outshines J059-4351.
评论 #40536996 未加载
Carrok12 months ago
US Only: This is your regular data breach reminder to freeze your credit with all 3 credit bureaus, as well as with NCTUE. It&#x27;s free to do, easy to lift when you need to, and helps prevent credit fraud (also known, incorrectly, as identity theft).
评论 #40514449 未加载
评论 #40514239 未加载
评论 #40514750 未加载
评论 #40514565 未加载
sneak12 months ago
Good thing you can use fake data with Ticketmaster purchases and aren’t forced to display matching government ID for access to venues.<p>Oh, wait.<p>There should be real, criminal penalties for leaking authentic, government-ID PII these days.
评论 #40537522 未加载
评论 #40537251 未加载
评论 #40537403 未加载
aszantu12 months ago
Damn, i missed the dip
namanyayg12 months ago
Now let&#x27;s take this opportunity and shut down this predatory website
throwmeaball12 months ago
That would not happen if Ticketmaster still had the best programmer that ever lived.
评论 #40514150 未加载
评论 #40514182 未加载
评论 #40514304 未加载
throwaway595912 months ago
If there wasn’t one company responsible for all of concert ticketing in the US maybe there would be fewer victims.
s_dev12 months ago
I wonder if GDPR fines will get issued. If so hopefully the EU slaps on some processing fees and digital delivery fees and some admin fees and some notification fees on top of the fines.
评论 #40514377 未加载
renewiltord12 months ago
It wasn’t stolen. They still have a copy of it. More accurate to say “Data allegedly copied”. And it seems natural. Information wants to be free.
评论 #40536504 未加载
评论 #40536496 未加载
评论 #40536624 未加载
评论 #40536592 未加载
评论 #40536843 未加载
评论 #40537443 未加载