One of the world's biggest ticket websites suffered a multi-year data breach

A white padlock on a dark digital background.
(Image credit: Shutterstock.com)

International ticketing services company See Tickets has been leaking sensitive payment data to cybercriminals for years.

The company, one of the biggest ticket sellers in the world, confirmed the news in a data breach notification shared with the Montana Attorney General’s office, in which it was said that unknown threat actors managed to set up a skimmer on its website on June 25, 2019.

From that date on, the crooks were silently gathering an entire treasure trove of personally identifiable data, including full customer names, postal addresses, credit card numbers, expiration dates, and CVV numbers. Social Security numbers, state identification numbers, and bank account information, were allegedly not affected, as they weren’t stored in See Tickets’ systems, the company said.

Two and a half years of leaks

The company discovered the cyberattack in April 2021 before hiring a forensics firm, as well as partners from Visa, MasterCard, American Express, and Discover, to investigate the matter. 

However it was not until more than half a year later, in January 2022, the skimmer was removed, meaning that all in all, sensitive customer data was exposed to hackers for more than two and a half years. 

We don’t know the exact number of people affected by the attack, or if the skimmer was only installed on the global site or any of See Tickets’ other domains. 

What we do know is that the company did not offer the free identity theft protection services that companies usually offer their customers, when found in this type of situation. Instead, customers are left to their own devices. See Tickets warned them to be extra careful when receiving emails and SMS messages claiming to have something to do with the company and to monitor their credit card transactions for any suspicious activity. 

A skimmer is a JavaScript code that cybercriminals inject on the order checkout page, which steals the payment data people type in. 

See Tickets has had more than 9 million visitors in September 2022, according to data from SimilarWeb.

Via: BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Casio logo
Casio’s online store hit by bogus credit card stealing checkout form
A person with a laptop using a credit card online.
Avery label maker confirms attack on its site, customer credit card info stolen
A computer being guarded by cybersecurity.
Wacom warns users their data may have been stolen in breach
A person holding a credit card in one hand while typing on a laptop keyboard with the other.
WordPress users targeted by devious new credit card skimmer malware
A person holding a credit card in one hand while typing on a laptop keyboard with the other.
European Space Agency hack sees official store hijacked to steal customer details
Woman shocked by online scam, holding her credit card outside
Cybercriminals used vendor backdoor to steal almost $600,000 of Taylor Swift tickets
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)