[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3to78p61irynq":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":21,"affectedCount":21,"affectedCountStatus":22,"affectedCountLowerBound":23,"affectedCountUnit":24,"hasEnglishDescription":4,"severity":25,"dataClasses":26,"description":31,"seoTitle":32,"seoTitleEn":33,"seoDescription":32,"seoDescriptionEn":34,"logoUrl":35,"isVerified":4,"isSensitive":36,"isSpamList":36,"isMalware":36,"company":37},"68e3266eda11adda488253c7","Ticketfly","Ticketfly Data Breach","ticketfly","ticketfly.com","2018-05-31T00:00:00.000Z","2018-06-03T06:14:14.000Z","2026-07-29T11:40:53.262Z","Website hack","https:\u002F\u002Fsupport.ticketfly.com\u002Fcustomer\u002Fen\u002Fportal\u002Farticles\u002F2941983-ticketfly-cyber-incident-update",[15,17,18,19,20],"https:\u002F\u002Fweb.archive.org\u002Fweb\u002F20180614003506id_\u002Fhttps:\u002F\u002Fsupport.ticketfly.com\u002Fcustomer\u002Fen\u002Fportal\u002Farticles\u002F2941983-ticketfly-cyber-incident-update","https:\u002F\u002Fweb.archive.org\u002Fweb\u002F20180721123022id_\u002Fhttps:\u002F\u002Fsupport.ticketfly.com\u002Fcustomer\u002Fen\u002Fportal\u002Farticles\u002F2941983-ticketfly-cyber-incident-update","https:\u002F\u002Fwww.vice.com\u002Fen\u002Farticle\u002Fticketfly-website-database-hacked-data-breach\u002F","https:\u002F\u002Fweb.archive.org\u002Fweb\u002F20180601151932id_\u002Fhttps:\u002F\u002Fmotherboard.vice.com\u002Fen_us\u002Farticle\u002Fmbk3nx\u002Fticketfly-website-database-hacked-data-breach",26151608,"known",null,"unknown","Critical",[27,28,29,30],"Email addresses","Names","Phone numbers","Physical addresses","\u003Cp>A May 2018 attack on Ticketfly's ticketing platform exposed customer data tied to \u003Cstrong>26,151,608 unique email addresses\u003C\u002Fstrong>. The company temporarily took its systems offline after the website was defaced.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The verified data classes are email addresses, names, phone numbers, and physical addresses. Combining these fields can make fake ticket, event cancellation, refund, and account-notice messages more convincing. The company stated that \u003Cstrong>credit and debit card data and ticket-buyer passwords were not accessed\u003C\u002Fstrong>.\u003C\u002Fp>\u003Cp>For venue and promoter clients, the company said there was no evidence that passwords were accessed, although hashed client password values might have been accessible. That possibility is not a verified password field in the publicly released dataset, so passwords are not added to this record's data classes.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>The incident became public on May 31, 2018, when Ticketfly's website was defaced and customer files were uploaded to a publicly accessible location. The attacker claimed to have requested a ransom in exchange for vulnerability details, while independent review confirmed that six sampled records matched real people. The company later said approximately 27 million accounts were affected and noted that the number of individuals could be lower because one person might use multiple email accounts. This record uses the canonical count of 26,151,608 unique email addresses.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>People who bought tickets through Ticketfly and users with venue or promoter accounts are at risk. Names, phone numbers, email addresses, and physical addresses can be combined for targeted phishing, fake event notices, and phone scams. This record should not be expanded to imply that ticket histories, payment cards, or location data were exposed.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>Verify ticket, cancellation, and refund messages through an \u003Cstrong>official event or sales channel\u003C\u002Fstrong>, and do not respond to unexpected payment requests by email or phone. If you used a Ticketfly venue or promoter client account, follow the company's precautionary advice by changing that password and every account where it was reused. Enable two-step verification where supported.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Store only necessary address and contact information in ticketing accounts, close accounts you no longer use, and use a unique password for every service. When hard-to-change data such as a physical address or phone number is exposed, continue verifying future event or delivery messages through an independent channel.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>Check this record with the email address you used for Ticketfly. A match means your email address may appear in the publicly released dataset alongside name, phone, or physical-address fields; it does not mean your password or payment-card data appears in this record. Review password security separately if you had a venue or promoter client account.\u003C\u002Fp>","","Ticketfly Data Breach (26.2 Million Reported Records)","Ticketfly Data Breach. 26.2 Million reported records were reported. Reported data: Email addresses, Names, Phone numbers. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fticketfly_com.webp",false,{"name":7,"sector":38,"country":39,"website":10,"websiteArchiveUrl":40,"websiteStatus":41,"websiteCheckedAt":42},"Ticketing \u002F Event Services","United States","https:\u002F\u002Fweb.archive.org\u002Fweb\u002F20230320014846\u002Fhttp:\u002F\u002Fticketfly.com\u002F","archived","2026-07-29T11:30:22.391Z"]