Ticketmaster parent company Live Nation has confirmed that internal data was exposed in a cyber-attack identified last month compromising the data of 560 million customers.
ShinyHunters, the current administrator of BreachForums, recently claimed the hack of Ticketmaster and offered for sale 1.3 TB of data, including full details of 560 million customers, for $500,000. Stolen data includes names, emails, addresses, phone numbers, ticket sales, and order details.
Live Nation has identified unauthorized activity within a third-party cloud database environment containing Company data and launched an investigation with leading forensic investigators.
The company claimed that the incident has not had a material impact on its overall business operations or on the financial condition or results of operations.
The stolen data were offered for sale on the dark web by ShinyHunters. According to screenshots of the dark web ad, they are selling 1.3TB of stolen customer data, including names, addresses, emails and phone numbers, the last four digits of card numbers and expiry dates, ticketing order details and much more. The trove is on offer as a “one-time sale” for $500,000.
Live Nation confirmed to various outlets that cloud storage firm Snowflake is the third party whose environment was targeted in the breach.
In a removed blog post, security researchers at Hudson Rock reported that the threat actor targeted a Snowflake employee’s ServiceNow account with stolen credentials, enabling them to subsequently access the Ticketmaster database.
However, a post from Snowflake explained that an increase in threat activity targeting some of their customers’ accounts is down to ongoing industry-wide, identity-based attacks designed to exfiltrate customer data.
They do not believe that this activity is caused by any vulnerability, misconfiguration or malicious activity within the Snowflake product.














Comments