Cornell ticket buyers hit by AudienceView Campus platform breach

Organization
Cornell University
Exploit
Supply Chain Attack
Industry
Higher Education

Cornell University warned ticket buyers in late February 2023 that payment card details had been stolen through AudienceView, the vendor behind its online ticketing system. AudienceView identified suspicious activity in its Campus product on 21 February and determined that malware had been planted on it. Purchases made between 17 and 21 February were affected.

Cornell said the exposure covered events sold through Cornell Athletics, Cornell Tickets, the Cornell Concert Series and the Schwartz Center for the Performing Arts. Names, billing and shipping addresses, email addresses and payment card information were involved, and at least one affected institution reported that card numbers, expiry dates and CVV codes were included. Cornell students told The Ithacan that they had lost between 60 and 400 dollars, and social media posts reported losses of more than 1,000 dollars. A law firm investigating the breach said some platform customers were defrauded by people posing as representatives of their banks, who tricked them into giving up PINs and Social Security numbers.

Cornell was one of dozens of victims. Reporting in late March and early April put the total at roughly 13,045 people across at least 25 institutions, among them MIT, Virginia Tech, Pomona College, SUNY Oswego, Colorado State University, Loyola University Chicago and McMaster University, each of which issued its own advisory. Johns Hopkins University, American University and Eastern Illinois University appear on AudienceView's website as Campus customers, which is not the same as being confirmed affected.

AudienceView suspended online ticket sales while it investigated, engaged the incident response firm Mandiant, removed the malware, contacted federal law enforcement, and offered those affected 12 months of credit monitoring and identity protection at no charge.

Sources