Ticketfly Data Breach (2018): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The Ticketfly Data Breach (2018) (reported May 31, 2018) exposed Email addresses, Names, Phone numbers and Physical addresses belonging to roughly 26.2M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
In May 2018, the Ticketfly ticket-distribution website was defaced and later taken offline. An attacker subsequently posted a data set containing 26.2 million unique email addresses, together with associated names, physical addresses and phone numbers, to a publicly accessible location. No passwords appeared in the material that was placed online. The company later stated that additional records may also have been accessed.
Incidents that combine website defacement with the public release of customer records remain a recurring feature of the threat landscape for any organisation that maintains large online customer databases.
What happened
On or before 31 May 2018 the Ticketfly site was altered by an unauthorised party and rendered unavailable to users. The same party reportedly contacted the organisation with an offer to disclose a vulnerability in exchange for payment. After receiving no response, the party published the data set described above. The exact timing of the initial access, the method used to obtain the records, and the full scope of any additional files remain undisclosed in public statements.
How a breach like this happens
Public-facing web applications that accept user input or serve dynamic content can be compromised when an attacker identifies an unpatched flaw or misconfiguration. Once inside the environment, the attacker may locate customer records stored in connected databases. In some cases the intruder alters visible pages to signal the intrusion, then uses the access to extract or copy data. When the organisation does not meet a ransom demand, the material is sometimes placed on open internet locations where it can be downloaded by anyone.
About Ticketfly
Ticketfly operated an online platform that sold tickets for live events and managed customer accounts for venues and promoters. Services of this type routinely collect and store contact details so that purchasers can receive confirmations, updates and support. A compromise at this scale therefore involves records that many people use daily for both personal and professional communication.
The information in question
The published data set included email addresses, names, physical addresses and phone numbers. No passwords were present in the material released publicly. Ticketfly indicated that further records could have been accessed, but the precise contents of any additional files have not been confirmed in available statements.
Why it matters
Contact information of the types disclosed can be used to construct targeted phishing messages or to enrich existing data sets sold on underground forums. Recipients of unsolicited messages may find it harder to distinguish legitimate communications from fraudulent ones when the sender already possesses their name, address and telephone number. For the organisation, the incident required restoration of service, public notification and potential regulatory scrutiny.
What to do if you're exposed
Individuals whose information may have been included can take several immediate steps. Review recent account activity on any services that use the same email address. Enable or strengthen multi-factor authentication where available. Treat unexpected messages that reference event purchases or account details with caution and verify them through official channels rather than clicking links.
- Change passwords on Ticketfly and any other sites that reuse the same credentials.
- Monitor email and postal mail for unusual requests or offers.
- Consider using a dedicated email address for ticketing services in the future.
Readers can run a free exposure scan of their email address against known breach data sets to determine whether their information appears in this or other documented incidents.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Data & Leads Data Breach (2018)Adapt Data Breach (2018)Elasticsearch Instance of Sales Leads on AWS Data Breach (2018)GoldSilver Data Breach (2018)Latest breaches
Read GalaxyWarden’s full analysis of the Ticketfly Data Breach (2018) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.