HomeData BreachTicketmaster confirms large breach after stolen knowledge on the market on-line

Ticketmaster confirms large breach after stolen knowledge on the market on-line

Stay Nation has confirmed that Ticketmaster suffered a data breach after its knowledge was stolen from a third-party cloud database supplier, which is believed to be Snowflake.

“On Might 20, 2024, Stay Nation Leisure, Inc. (the “Firm” or “we”) recognized unauthorized exercise inside a third-party cloud database atmosphere containing Firm knowledge (primarily from its Ticketmaster LLC subsidiary) and launched an investigation with industry-leading forensic investigators to know what occurred,” Stay Nation shared in a Friday evening SEC submitting.

“On Might 27, 2024, a felony menace actor provided what it alleged to be Firm person knowledge on the market through the darkish net.”

“We’re working to mitigate threat to our customers and the Firm, and have notified and are cooperating with regulation enforcement. As acceptable, we’re additionally notifying regulatory authorities and customers with respect to unauthorized entry to private data.”

Whereas the breach has allegedly uncovered the information of over 560 million Ticketmaster customers, the corporate states that they don’t imagine that the breach can have a fabric affect on the general enterprise operations or its monetary situation.

See also  5 SaaS Misconfigurations Resulting in Main Fu*%@ Ups

This admission comes after a menace actor often called Shiny Hunters has been trying to promote the Ticketmaster knowledge on a hacking discussion board for $500,000.

The allegedly stolen databases supposedly include 1.3TB of information, together with prospects’ full particulars (i.e., names, residence and electronic mail addresses, and telephone numbers), in addition to ticket gross sales, order, and occasion data for 560 million prospects.

Ticketmaster data for sale on a hacking forum
Ticketmaster knowledge on the market on a hacking discussion board
Supply: BleepingComputer

In a dialog with the menace actor, ShinyHunters advised BleepingComputer that there have been consumers within the knowledge. They believed that one of many consumers that approached them was Ticketmaster themselves.

When requested how they stole the information, the menace actor mentioned they “cannot say something about this.”

Nonetheless, at the moment, extra data was revealed on how the menace actors gained entry to the Ticketmaster database and probably the information of many different prospects.

Alon Gal of Hudson Rock spoke to one of many menace actors behind the assault, who claimed they have been chargeable for current Santander and Ticketmaster data breaches and mentioned they stole the information from cloud storage firm Snowflake.

See also  Kansas courts affirm knowledge theft, ransom demand after cyberattack

Based on the menace actor, they used credentials stolen utilizing information-stealing malware to breach a Snowflake worker’s ServiceNow account, which they used to exfiltrate data from the corporate. This data included unexpired auth tokens that might be used to create session tokens and entry buyer accounts to obtain knowledge.

The menace actor claims that they used this methodology to steal knowledge from different firms, together with Anheuser-Busch, State Farm, Mitsubishi, Progressive, Neiman Marcus, Allstate, and Advance Auto Components.

Progressive and Mistubishi disputed the menace actor’s claims, telling BleepingComputer that there isn’t a indication of any breach of their methods or knowledge.

Snowflake says the current breaches have been brought on by poorly secured buyer accounts whose credentials have been stolen and didn’t have multi-factor authentication enabled.

The corporate added that the assaults started in mid-April, with prospects’ knowledge first being stolen on Might 23. Snowflake has shared IOCs from the assaults in order that prospects can question logs to find out in the event that they have been breached.

See also  Risk Prevention & Detection in SaaS Environments

Mandiant Consulting CTO Charles Carmakal advised BleepingComputer that Mandiant has been investigating compromised Snowflake purchasers over the previous few weeks and believes their Snowflake tenants have been breached utilizing stolen credentials.

After we contacted Snowflake to verify the menace actor’s claims that they hacked an worker’s account, as an alternative of disputing them, they mentioned that they had nothing additional to share.

It is a creating story.

- Advertisment -spot_img
RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -

Most Popular