International ticketing services company See Tickets disclosed a data breach that exposed customers’ payment card details.
The threat actors managed to steal payment card data by implanting a software skimmer on its website.
The company discovered the security breach in April 2021 and immediately launched an investigation with the help of a forensics firm. The company completely removed the malware from its website on January 8, 2022.
According to the data breach notification sent to the impacted customers, See Tickets noticed potential unauthorized access by a third party to certain event checkout pages on their website in April 2021. The firm launched an investigation and took steps to shut down the unauthorized activity. Their response efforts had multiple phases and resulted in the complete shutdown of the unauthorized activity in early January 2022.
On September 12, 2022, the firm determined the event may have resulted in unauthorized access to the payment card information of some of their customers. The investigation is ongoing and the firm has notified its customers out of an abundance of caution based on available information.
The attackers obtained data provided by the customers while purchasing event tickets on the See Tickets website between June 25, 2019, and January 8, 2022. Stolen data includes name, address, zip code, payment card number, card expiration date, and CVV number.
However, the customer’s Social Security numbers, state identification numbers, or bank account information were not exposed as the company doesn’t store them.
See Tickets worked with Visa, MasterCard, American Express, and Discover to identify the impacted transactions.
See Tickets warns that users should check their recent bank and/or credit card statements for any unauthorized charges. Users are also recommended to immediately notify their financial institution if they find any suspicious activity.
As of now, the number of impacted customers is not known.















Comments