Skip to main content
Breach Signal

Breach report

Ticketing & Entertainment

Ticketmaster (Live Nation)

Live Nation confirms Ticketmaster breach after hackers hawk stolen info of 560 million

Hackers used stolen login credentials to raid a Ticketmaster database hosted on Snowflake and advertised data on 560 million customers for $500,000, making it the most visible victim of a sweeping 2024 cloud data theft campaign.

Reported by The Record

Records exposed

560M

Up to 560 million customers (hacker claim)

Scale vs. largest on file

When
2024
How they got in
Stolen credentials to Snowflake cloud database without multifactor authentication
Sector
Ticketing & Entertainment

In late May 2024, the hacking group ShinyHunters advertised a 1.3-terabyte database on a criminal forum that it said contained personal information on 560 million Ticketmaster customers, with an asking price of $500,000. On May 31, Ticketmaster's parent company Live Nation Entertainment confirmed in a filing with the U.S. Securities and Exchange Commission that it had detected unauthorized activity in a third-party cloud database on May 20 and that a criminal actor had offered what appeared to be company user data for sale about a week later.

The database was hosted on Snowflake, a cloud data warehousing company used by many large enterprises. Investigators, including Mandiant, found that the attackers had not breached Snowflake's own platform. Instead, they logged into customer accounts using usernames and passwords previously harvested by infostealer malware from contractors' and employees' computers, targeting accounts that were not protected by multifactor authentication. The same campaign hit around 165 organizations, including Santander, AT&T, Advance Auto Parts and Neiman Marcus.

The stolen data reportedly included customer names, addresses, email addresses, phone numbers, ticket sales and event information, order details and partial payment card information such as the last four digits and expiration dates. Live Nation said in its filing that it did not expect the incident to materially affect its business. Ticketmaster began notifying customers in the following weeks and offered free identity monitoring. Later in the summer, a hacker leaked ticket barcode data for major concerts, including Taylor Swift shows, in an extortion attempt; Ticketmaster said its rotating mobile barcodes limited the risk.

The breach arrived as Live Nation faced an antitrust lawsuit from the U.S. Justice Department, adding to public scrutiny of the company. Consumer class actions followed. Law enforcement moved against suspects in the broader Snowflake campaign: Canadian authorities arrested Connor Moucka in late 2024 at the request of the United States, and prosecutors also charged an American living in Turkey, John Binns, with involvement in the thefts and subsequent extortion of victim companies.

The Ticketmaster incident showed how a single missing safeguard, multifactor authentication on cloud accounts, could expose data on hundreds of millions of people. It shifted attention to the shared-responsibility model in cloud computing, prompting Snowflake to move toward mandatory MFA, and served as a warning that credentials stolen years earlier by commodity malware remain dangerous if never rotated. For consumers, it was another reminder to watch for phishing that references real purchases.

More from the wire

More in Ticketing & Entertainment.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.