Ticketek Australia customer data exposed via third-party cloud platform

Organization
Ticketek Australia
Exploit
Third-Party Data Breach
Industry
Ticketing

Ticketek Australia, the ticketing business of TEG, told customers in a statement late on May 31, 2024 that their personal information had been exposed through a cloud-based platform operated by what it described as a reputable, global third-party supplier. The company said the evidence available at that point indicated customer names, dates of birth and email addresses may have been affected.

Ticketek said payment card details and account passwords held in its own environment were not involved, because online payments run through a separate encrypted system that was not touched. It declined to identify the supplier and did not say how many accounts were caught up in the incident.

Independent assessments were larger than the company's description implied. Have I Been Pwned catalogued almost 30 million rows containing 17.6 million unique email addresses, alongside names, dates of birth, genders, salutations and hashed passwords. Australian reporting put the exposure at up to 30 million TEG user records, and a seller using the handle Sp1d3r advertised the data on a crime forum for A$45,000, about US$30,000.

Ticketek notified the National Office of Cyber Security, the Australian Signals Directorate and the Australian Federal Police, and the home affairs and cyber security minister urged Australians to watch for scams. The incident was widely linked to the campaign against Snowflake customer accounts that also produced the Ticketmaster and Santander breaches, though TEG did not confirm that connection.

Sources