[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f74lkj98ok3xt":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":32,"seoTitle":15,"seoTitleEn":33,"seoDescription":15,"seoDescriptionEn":34,"logoUrl":35,"isVerified":4,"isSensitive":4,"isSpamList":36,"isMalware":36,"company":37},"68e3266eda11adda488253c8","ticketcounter","Ticketcounter Data Breach","ticketcounter.nl","2021-02-22T00:00:00.000Z","2021-03-01T22:37:54.000Z","2026-07-03T15:27:19.932Z","2026-07-18T23:59:33.584Z","Third party breach","",[],1921722,"known",null,"unknown","Critical",[23,24,25,26,27,28,29,30,31],"Bank account numbers","Dates of birth","Email addresses","Genders","IP addresses","Names","Payment histories","Phone numbers","Physical addresses","\u003Cp>The Ticketcounter data breach is a 2021 incident associated with a backup of the database of Netherlands-based ticketing service Ticketcounter being published in a publicly accessible location. The record contains 1,921,722 unique email addresses. The types of data include bank account numbers, dates of birth, email addresses, gender information, IP addresses, names, payment histories, phone numbers, and physical addresses.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>This record is considered sensitive in terms of risk because it contains bank account number and payment history fields. Along with name, address, phone, and date of birth, the financial transaction context becomes visible. Ticketing and event context can make fraudulent refund, ticket transfer, payment correction, or debt notification messages more convincing.\u003C\u002Fp>\u003Cp>When fields such as name, email, phone, address, username, or location are combined, attackers may approach the user as if there is a legitimate service relationship. This information alone does not always mean account takeover; however, it can be used for phishing, fake support requests, account verification, and personalized fraud flows. Passwords are not listed in the record; however, fields like bank account and payment history are very valuable from a social engineering perspective. The user should not be given the impression that a message knowing partial or full bank information is trustworthy.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The event date is recorded as February 22, 2021. Reliable records indicate that the backup mistakenly published by Ticketcounter in 2020 was found and downloaded in 2021, that the data was put up for sale, and later used with a ransom threat. The current data categories are compatible with this scope.\u003C\u002Fp>\u003Cp>When explaining the scope, it should not be assumed that every user has all banking or payment fields. However, listing the bank account number and payment history fields is sufficient to mark the record as sensitive data.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Users at risk are those who have purchased tickets through Ticketcounter, made event payments, or shared address\u002Fphone information. Users who are accustomed to messages themed around event cancellations or ticket refunds may be targeted for fraud.\u003C\u002Fp>\u003Cp>Users who have a bank account and payment history should be especially careful against fake refund or bank verification messages. Even if messages use a real event name or payment information and appear official, the transaction should be initiated through the official channel.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users in the matching field should monitor bank account transactions and verify suspicious automatic payment or refund requests with the bank. Unique passwords should be used for Ticketcounter and ticketing accounts used with the same email.\u003C\u002Fp>\u003Cp>Instead of opening incoming links directly, the user should log in through the known web address or official application of the relevant service. Knowing the caller's name, email, address, order, or profile information does not prove that they are trustworthy. One-time verification codes, payment card information, or account passwords should not be shared in any support conversation.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In the long term, the habit of using a password manager, unique passwords, two-factor authentication, and removing unnecessary personal information from accounts reduces risk. Reusing the same email address across different platforms makes it easier to combine data from different breaches; using a separate email or alias for critical accounts can be considered.\u003C\u002Fp>\u003Cp>Unnecessary payment and address information should be cleared from ticketing accounts, bank notifications should be kept on, and transactions such as event refunds should only be carried out through the official website. Long-term monitoring is important in violations involving financial areas.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>LeakData check indicates whether the queried email address is found in this record. A positive result does not necessarily mean that all data fields definitely belong to that user; however, it is a sufficient warning for precautionary measures. A negative result only indicates that there is no match in this dataset, and does not eliminate the possibility of appearing in other breaches.\u003C\u002Fp>\u003Cp>A positive result is a high-priority alert due to payment history and bank account risk. A negative result means that there is no match within this record; the same email should also be checked in other ticketing or payment records.\u003C\u002Fp>","Ticketcounter Data Breach (1.9 Million Reported Records)","Ticketcounter Data Breach. 1.9 Million reported records were reported. Reported data: Bank account numbers, Dates of birth, Email addresses. Review the scope…","\u002Fuploads\u002Flogo\u002Fticketcounter_nl.webp",false,{"name":38,"sector":39,"country":40,"website":9,"websiteArchiveUrl":15,"websiteStatus":15,"websiteCheckedAt":19},"Ticketcounter","Events and Ticketing","Netherlands"]