Data breach
Ticketfly
- Records
- 6,151,075
- Breach date
- 31 May 2018Estimated
- Added
- 1 December 2024
What was exposed
3 types of data · 1 more reported
- Email addresses6,150,638
- Names4,049,777
- Phone numbers3,620,886
- Home addressesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
A hacker took over Ticketfly's website and stolen customer data in a May 2018 attack that exposed personal information linked to roughly 27 million accounts. Ticketfly, an online ticketing platform for music venues that was owned by Eventbrite at the time, confirmed the scale of the breach on June 7, 2018, about a week after the incident began. According to reporting by Motherboard, the attacker said he had warned Ticketfly about a vulnerability beforehand and demanded one bitcoin, roughly $7,500 at the time, in exchange for details on the flaw. When the company did not respond, the hacker defaced the site and leaked customer data online.
According to our investigation team's records, this listing indexes about 6.15 million records tied to the Ticketfly breach, including more than 6.1 million email addresses. The company's own statement pointed to a considerably larger exposure across its full customer base.
Breach Timeline
May 30, 2018: An attacker, using the handle "IShAkDz," compromised Ticketfly's website, according to reporting by Motherboard and Variety. The homepage was briefly defaced with a message taunting the company's security.
May 31, 2018: Ticketfly took its website offline and told visitors it had been the target of a cyber incident.
June 6, 2018: The website came back online after the company reset user passwords, per CNET.
June 7, 2018: Ticketfly confirmed that names, addresses, email addresses, and phone numbers connected to approximately 27 million accounts were accessed, and said credit and debit card information was not accessed.
What Information Was Compromised?
Our analysis found the following data types in this breach: 6,150,638 email addresses, 3,620,886 phone numbers, and 4,049,777 names.
Ticketfly's own statement and published FAQ confirmed that the compromised information included fans' names, mailing and billing addresses, email addresses, and phone numbers. The company said no passwords and no credit or debit card information were accessed.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Even without passwords or payment data, an exposed name paired with an email address, phone number, and home address gives criminals the raw material for targeted phishing. Messages that reference real events you attended through Ticketfly can appear convincingly legitimate.
The phone numbers in this dataset could be used for smishing, which is phishing by text message, or for unwanted robocalls. Home and billing addresses raise concerns for anything from targeted scams to mail fraud.
Because the attacker posted some of this data online in 2018, it has been circulating for years. That means anyone affected should assume the information is permanently available to scammers, not just to the original hacker.
What Is Ticketfly Doing in Response?
Ticketfly took its website offline the day after the attack and worked with third-party forensic cybersecurity experts, according to CNET. The company reset every user password, for both ticket buyers and venue promoters, before restoring its site on June 6, 2018. It published an FAQ about the incident and advised customers to change passwords on other services where they had reused the same login information. Ticketfly also said it never received follow-through on the hacker's threat to publish more data.
What Should You Do If You Were Affected?
Change your Ticketfly password if you have not done so since 2018, and change it anywhere else you reused it.
Be skeptical of emails or texts that reference concerts, venues, or ticket purchases, especially any that ask you to click links, log in, or pay a fee.
Consider screening calls and texts from unknown numbers, since your phone number may be in circulation.
Review what else is tied to your email address and consider a password manager so each account has a unique password.
Watch your mail and billing statements for anything unusual, given that home addresses were part of the exposure.
In the news
- CNET: Ticketfly confirms 27M peoples' data stolen, a week after hackcnet.com (opens in a new tab)
- Motherboard (Vice): Hacker Stole 26 Million Email And Home Addresses Of Ticketfly Usersvice.com (opens in a new tab)
- Motherboard (Vice): Hacker Defaces Ticketfly's Website, Steals Customer Databasevice.com (opens in a new tab)
- Variety: Ticketfly Hackers Stole Data From 27 Million Accountsvariety.com (opens in a new tab)
- Pollstar: Ticketfly Back Online
