Data breach
Ticketek
- Records
- 29,223,035
- Breach date
- 31 May 2024Estimated
- Added
- 24 January 2025
What was exposed
4 types of data
- Names29,167,332
- Email addresses23,700,107
- Employment187,470
- Employers187,470
About this breach
Australian ticketing company Ticketek disclosed a data breach in late May 2024 that exposed the personal details of account holders stored on a cloud-based platform operated by a third party. The company, owned by live entertainment firm TEG, told customers and the government that names, dates of birth and email addresses may have been taken. Ticketek said credit card details and passwords were encrypted and stored separately and were not affected. Our investigation team estimates the breach covers about 29.2 million records, including more than 23.7 million email addresses and nearly 29.2 million names.
Breach Timeline
May 31, 2024: Ticketek published a statement confirming a cyber incident affecting account holder information held on a third-party cloud platform, and notified the Australian Cyber Security Centre, the Office of the Australian Information Commissioner and the National Office of Cyber Security. Federal Home Affairs Minister Clare O'Neil said data belonging to customers had been stolen.
June 21, 2024: TechCrunch reported that a hacker was advertising the data for sale on a hacking forum, claiming records for 30 million users. TechCrunch verified that some of the sample email addresses matched real Ticketek accounts. The report noted evidence suggesting the third-party platform was Snowflake, though the company declined to confirm whether Ticketek was a customer.
September 13, 2024: The Australian Information Commissioner accepted a representative complaint against Ticketek lodged by law firm XD Law & Advocacy, alleging the company interfered with customers' privacy under the Privacy Act.
May 28, 2025: Ticketek closed the dedicated incident response hotline it had operated since May 2024, according to a statement from TEG.
What Information Was Compromised?
Our analysis found the following data types in this breach: names, email addresses, job titles and employer company information for a smaller subset of records, per the indexed fields. The company's own customer notice said names, dates of birth and email addresses may have been impacted. The hacker's sales listing, as reported by TechCrunch, also advertised genders, usernames and hashed passwords.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Names, dates of birth and email addresses may seem modest, but together they are useful raw material for phishing. Scammers can send convincing emails that reference a person's real name and birth date, pretending to be Ticketek, a bank, or a government agency, to extract passwords or payment details. If hashed passwords were indeed part of the stolen set, attackers could attempt to crack weak ones and reuse them against other sites. The job and employer fields could also support targeted workplace scams. The breach itself did not expose credit card numbers, which lowers the risk of direct financial fraud from this data alone.
What Is Ticketek Doing in Response?
Ticketek notified affected customers by email, reported the incident to the Australian Cyber Security Centre, the Office of the Australian Information Commissioner and the National Office of Cyber Security, and operated a 24-hour incident hotline from May 2024 until May 28, 2025. The company maintains that its password encryption prevented any customer accounts from being compromised, and that payment details were stored in a separate, unaffected system. According to TEG's statement, Ticketek also obtained an injunction to prevent any access, dissemination or publication of the impacted data by third parties.
What Should You Do If You Were Affected?
Be wary of unsolicited emails, texts or calls claiming to come from Ticketek, especially ones asking you to log in, reset a password, or confirm personal details. Check sender addresses carefully and go to the website directly rather than through links. If you reused your Ticketek password elsewhere, change those passwords now and enable two-factor authentication where available. Watch your accounts for unexpected activity. If you want to pursue the privacy complaint route, the Office of the Australian Information Commissioner has information on the representative complaint brought by XD Law & Advocacy.
In the news
- TEG statement regarding Ticketek cyber incidentteg.com.au (opens in a new tab)
- TechCrunch: Hacker claims to have 30 million customer records from TEGtechcrunch.com (opens in a new tab)
- The Sydney Morning Herald: Customer data exposed after Ticketek cyber incidentsmh.com.au (opens in a new tab)
- OAIC: Representative complaint about Ticketekoaic.gov.au (opens in a new tab)
