[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3iha2g1hrsudz":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":21,"affectedCount":21,"affectedCountStatus":22,"affectedCountLowerBound":23,"affectedCountUnit":24,"hasEnglishDescription":4,"severity":25,"dataClasses":26,"description":33,"seoTitle":34,"seoTitleEn":35,"seoDescription":34,"seoDescriptionEn":36,"logoUrl":37,"isVerified":4,"isSensitive":38,"isSpamList":38,"isMalware":38,"company":39},"68e3266eda11adda488253c9","Ticketek","Ticketek Data Breach","ticketek","ticketek.com.au","2024-05-31T00:00:00.000Z","2024-06-28T01:17:02.000Z","2024-07-17T20:43:22.000Z","2026-07-19T23:20:46.071Z","Third-party cloud platform breach","https:\u002F\u002Fwww.teg.com.au\u002Fstatement-regarding-ticketek-cyber-incident\u002F",[16,18,19,20],"https:\u002F\u002Fwww.abc.net.au\u002Fnews\u002F2024-05-31\u002Fticketek-australia-cyber-security-data-breach-names-emails-leak\u002F103921986","https:\u002F\u002Ftechcrunch.com\u002F2024\u002F06\u002F21\u002Fhacker-claims-to-have-30-million-customer-records-from-australian-ticket-seller-giant-teg\u002F","https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Func5537-snowflake-data-theft-extortion",17643173,"known",null,"unknown","Critical",[27,28,29,30,31,32],"Dates of birth","Email addresses","Genders","Names","Passwords","Salutations","\u003Cp>The May 2024 Ticketek data breach affected 17,643,173 unique email addresses and exposed identity data together with password hashes.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The confirmed data classes are names, email addresses, dates of birth, gender data, salutations and password hashes. The reviewed dataset contained almost 30 million rows, but deduplication produced \u003Cstrong>17,643,173 unique email addresses\u003C\u002Fstrong>; the row count must therefore not be treated as a count of unique people or accounts. The password field contained non-plaintext hash values designed to be difficult to reverse. The hashing algorithm and additional protections have not been publicly verified. Combining an email address with a name, date of birth, gender and salutation increases the risk of targeted phishing, account-recovery fraud and impersonation. Password hashes may also enable offline guessing against weak choices and create credential-stuffing risk when a password was reused elsewhere. Payment card data and other payment details have not been verified in the dataset, and the company said payment information was not affected.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>On 31 May 2024, Ticketek announced that some information belonging to Australian customers may have been accessed from a cloud platform hosted by a third party. Its initial notice identified names, email addresses and dates of birth, said customer passwords were protected by secure storage methods and reported no evidence that customer accounts or payment details had been compromised. In June, a dataset attributed to Ticketek’s parent company was advertised on a criminal forum as almost 30 million rows; samples showed additional identity fields and password hashes. Later incident analysis linked the event to a broader campaign in which stolen credentials were used to access cloud data stores belonging to many organizations. The cloud provider was not named in the initial company notice. The record uses 31 May as the public disclosure date; reliable public evidence does not establish the exact beginning or end of the unauthorized access.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The highest-risk group includes customers who reused their Ticketek password on another service and whose email, date of birth and name in the dataset remain current. A hash is not a readable password, but attackers can test common guesses offline and try a recovered value against email, shopping, social media or other ticketing accounts. Dates of birth and salutations can make messages about a real event, ticket delivery or refund appear more convincing. \u003Cstrong>Compromise of customer accounts or payment information has not been verified\u003C\u002Fstrong>, yet the exposed identity fields still provide enough context for fraud. Customers who used a long, unique password face less risk from credential reuse, but personalized phishing remains relevant whenever their identity fields were included.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>Even if you changed your Ticketek password, check whether the password you used in 2024 still exists on another account and replace every reused copy with a unique credential. Prioritize your primary email account, password manager, financial services and shopping accounts that hold a saved payment method. Enable multi-factor authentication on email and other critical services, preferably through an authenticator app or hardware security key. Do not follow links in messages claiming to concern a Ticketek refund, event change, payment problem or password reset; navigate to the official site independently. Review account sessions, recovery addresses and recognized devices for changes you did not make. Payment card data is outside the verified scope of this breach, but continue monitoring unexpected transactions as part of normal account security. Do not trust a caller or message merely because it knows your name, date of birth or details about an event, and never disclose a one-time authentication code.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Use a password manager to generate a random, unique password for every online service so that recovery of one leaked hash cannot spread to other accounts. Keep multi-factor authentication enabled on critical services, store recovery codes safely offline and review account-recovery options at regular intervals. Verify unexpected attachments, QR codes, calendar invitations and payment requests associated with ticketing through a separate channel. \u003Cstrong>Treat immutable details such as a date of birth as permanent risk signals\u003C\u002Fstrong>; once disclosed, they may be reused in future social-engineering campaigns. Avoid using real, easily researched answers repeatedly for security questions. If you receive an alert about a new device, password reset or email-address change, open the service’s security page directly, revoke active sessions and review permissions granted to connected applications.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>Use the secure search field on this page to check every current and historical email address you used with Ticketek. A match means the address is one of the 17,643,173 unique emails in the verified dataset; it does not mean a plaintext password was exposed or that the account was definitely taken over. If you receive a match, identify every account where you reused the password from 2024 and secure the most important services first. No result is an absolute guarantee because a differently written address, a record outside this dataset or another breach may still exist. Never enter your password, payment card number or one-time authentication code into a breach search. Rechecking older addresses periodically helps you discover newly published breach records early and recognize personalized fraud messages before acting on them.\u003C\u002Fp>","","Ticketek Data Breach (17.6 Million Reported Records)","Ticketek Data Breach. 17.6 Million reported records were reported. Reported data: Dates of birth, Email addresses, Genders. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fticketek_com_au.webp",false,{"name":7,"sector":40,"country":41,"website":10,"websiteArchiveUrl":34,"websiteStatus":34,"websiteCheckedAt":23},"Event ticketing","Australia"]