Ticketmaster breach affects more than half a billion users
mashable.com
mashable.com
Lol, if an individual does this, you're going to go to jail. A company does this? Tiny fine. What a world we live in.
Prosecutorial discretion is real and dangerous. There are two sets of laws at work in the US, one for us, and a different one for them.
A complete lack of it is also dangerous; that's what gets us zero-tolerance policies of suspending victims of school bullying.
https://www.justice.gov/usao-edny/pr/ticketmaster-pays-10-mi...
As far as credentials being intellectual property, that doesn't sound quite right but I'm not an IP lawyer and it doesn't really matter.
If he did that it'd be prosecutable as breaking and entering, and it's perfectly reasonable to use the term "hacking" as the digital counterpart for "breaking and entering".
EDIT: It also looks like you work at Ticketmaster, or at least used to? If that's the case, that's a rather weird thing not to mention in the context of this thread.
I used to work at Ticketmaster. I don't anymore and I didn't at the time of the incident, so it didn't seem relevant to the discussion.
Like, what would make this hacking to you? The way an attacker gains credentials to access a system does not really matter. If he socially engineered these credentials, it'd still be hacking.
The term is appropriate, but it tends to evoke ideas of serious crimes, when hacking can be much more innocuous acts that often don't see much in the way of prosecution.
Telling the judge "but I wasn't wearing my black hoodie while listening to K-pop while doing it!" is going to be about as effective as telling the judge the legal code can't be trusted because it's not backed by a CI/CD system adhering to Agile practices. (Which a non-trivial number of Hacker News posters probably think would work.)
People have been prosecuted and convicted under the CFAA for significantly less.
The CFAA is a terribly abused law, but that is a fair use of the word "hacking".
No, they'd have called it breaking and entering. I don't know what point you think you're making.
No, if someone retains a key to a location after their legal authorization to access the location has been rescinded, and then uses it to access that physical location, that is breaking and entering.
Regardless, "if they committed this crime with physical means instead of digitally, there would be a different criminal charge and a different word for it" is a point that is not particularly insightful, relevant, or interesting to discuss.
The claim was that individuals suffer bigger consequences than people. The person involved was not fined $10 million. AFAIK, they were not prosecuted criminally.
No. This is right up there with "you can't report a person missing until it's been 24 hours" for most common popular legal misconceptions. It would be prosecutable as breaking and entering.
> The claim was that individuals suffer bigger consequences than people. The person involved was not fined $10 million. AFAIK, they were not prosecuted criminally.
Yeah, and that's not the comparison OP was making. If that's what you took away, read again, because you missed their point entirely.
An individual did do this. They did not go to jail.
Trespass vs. B&E is nuanced, and I'm definitely oversimplifying it. The "misconception" is widespread enough that it includes lawyers: https://www.shouselaw.com/ca/blog/breaking-entering-vs-tresp...
Right, and that's not the point OP was making.
> Trespass vs. B&E is nuanced, and I'm definitely oversimplifying it. The "misconception" is widespread enough that it includes lawyers
I'm guessing you didn't bother to read the link you dropped, because it actually undermines your entire claim. Before you pat yourself on the back, you might want to look up what qualifies as "use of force". It's not the way you seem to be using the word.
The only lens through which what you're saying is even vaguely correct is that some states don't have a specific statute of "breaking and entering", instead prosecuting it as "criminal trespass", but even then it's a distinction without a difference: it's prosecutable as a charge for using force to gain unauthorized access to a location with the express intent of committing a felony.
In any case, this whole discussion is pretty pointless, because as I already said, the fact that there's a different word used when the crime happens in meatspace vs. cyberspace is wholly uninteresting and not relevant to the original topic, and - as I also already said - you have clearly misunderstood the crux of OP's statement and so there's no point in continuing down this rabbithole.
That's a good guess, but wrong.
> The only lens through which what you're saying is even vaguely correct is that some states don't have a specific statute of "breaking and entering", instead prosecuting it as "criminal trespass", but even then it's a distinction without a difference: it's prosecutable as a charge for using force to gain unauthorized access to a location with the express intent of committing a felony.
I mentioned that trespass vs. B&E is nuanced, and that I was definitely oversimplifying it. If someone was curious they might have investigated this matter for the relevant jurisdiction. They might even have some familiarity with the case. But that would indeed require more curiosity than someone who doesn't even read a link before they drop it.
> In any case, this whole discussion is pretty pointless, because as I already said, the fact that there's a different word used when the crime happens in meatspace vs. cyberspace is wholly uninteresting and not relevant to the original topic, and - as I also already said - you have clearly misunderstood the crux of OP's statement and so there's no point in continuing down this rabbithole.
Or maybe I just wasn't doing a good job of being clear on the point. There was both an individual and a corporation at fault in that specific case, so you don't have to speculate as to which party was more severely punished. The OP's assertion is flat wrong.
A company itself does nothing. People make decisions and carry them out and should be accountable.
imagine being a young woman with a stalker
In my case my partner (Abby) made a new friend (Brandy). Brandy called me a few times while we were coordinating social activities. Brandy’s soon-to-be ex-husband (Malicious Michael) saw the late-night phone calls on the phone bill records, looked up my phone number, saw that I was a man, assumed she started dating me, and became completely obsessed with me.
Now I get about 30 texts and 12 emails from Mike every day, all of them very deranged and alarming. I have never met, interacted, talked with, responded to, or crossed paths with Mike.
But suddenly I have to worry about how even these relatively benign leaks might impact his ability to find me or attempt to fuck up my life.
I blocked it immediately. So he might have texted me a bunch of angry stuff. I’ve no idea. I never saw it.
Block him. He’ll get bored. I wish you the best, it’s not nice.
I wish that women were this fortunate.
It would take more personal information for me to really care (private messages, emails, social network interactions).
Unless there are lawsuits most people will forget about this breach in a week.
My favorite is when a credit bureau like Experian leaks your info and offers free monitoring as compensation - but you have to give them your info again to get the free monitoring.
They also continuously spam your email, but they’re easy enough to block.
> Based on data provided to us by the Threat Group responsible for the compromise, we can assert with a high degree of confidence the data is legitimate. Date ranges in the database appear to go as far back as 2011. However, some dates show information from the mid-2000's.
> NOTE: The data provided to us, even as a 'sample', was absurdly large and made it difficult to review in depth. We are unable to verify the authenticity of financial information. Briefly skimming the PII present in the dump, it appears authentic.
https://x.com/vxunderground/status/1796063116574314642
---
No official confirmation yet.
https://www.sec.gov/news/statement/gerding-cybersecurity-dis...
All my previous comments on this specific story have been that this isn’t verified.
Lots of major news sites pulled the trigger on the headline for nothing more than clicks.
Some journalists say that Australian Home Affairs confirmed the breach… lol! They acknowledged the rumour, but that got spun as “verification”.
Then again, maybe it’s lack of decent cybersecurity writers.
I personally can’t stand this weaksauce writing with no fact checking and the nonchalant way of throwing companies under the bus.
[1] https://www.linkedin.com/posts/aucyberseccoord_today-i-was-a...
Whether or not it’s a rumour based on speculation has nothing to do with it. It either is or it isn’t.
There is no confirmation that it isn’t.
--
Just to provide receipts:
Home Affairs Department confirms cyber incident impacting Ticketmaster customers (https://www.abc.net.au/news/2024-05-29/ticketmaster-hack-all...) - May 29th
> The Department of Home Affairs said it is aware of a cyber incident impacting Ticketmaster customers in response to claims it is part of a data leak expected to impact millions of customers globally.
How exactly "being aware" counts as "confirmation" in this case?
Any other article (outside of those who used ABC Aus as a source) on this matter have specifically used words like "allegedly", "purported", etc.
That's the only argument I am making.
It clearly says:
A spokesperson from the Department of Home Affairs told the ABC it is "Working with Ticketmaster to understand the incident".
Which is more than they are aware of a rumour
Tickettek is Australia's largest ticketing company and a competitor to Ticketmaster
Are you saying data was stolen? Because the headline here is "allegedly." So, unless you know absolutely one way or the other, allegedly is accurate.
Irish Independent -> Hackers access half a billion customers’ data in Ticketmaster cyber attack
Gizmodo -> Ticketmaster Hack Reveals Sensitive Data for 560 Million People
Daily Mail -> Details of 560 million Ticketmaster customers are stolen in data leak
And so on...
(all these stories/headlines were published on May 29th, on the day when the rumor began to spread)
As long as the investor is hurt, right? The users are just collateral.
Also. As the excellent Matt Levine never ceases to repeat : everything is securities fraud.
If you didn't state in your regular filings "our security is poor, we may get hacked", then you lied by omission.
SEC 8K being enforced has been nothing but good overall.
These companies were being hacked and it was hidden from you.
Now, it’s open, embarrassing, and costly. So they’re taking security more seriously.
If you are concerned about share price, buy the dip on hack.
(E.g. “money laundering” seemed like a reasonable hack for the first couple of decades, but these days banks have turned into an surveillance and enforcement apparatus with a presumption of guilt and no right of appeal.)
If the expectation was that users were screwed and would not be entitled to any compensation, then the news of this breach would be no more material to the company’s investors than learning the at the air conditioning was set to the wrong temperature in one of the company’s offices for a few hours.
I find the "honor amongst thieves" part so interesting in these breach stories
(1) Troy Hunt, via an "X" user has a screenshot to the actual sale -> https://x.com/troyhunt/status/1795551650553491870
Maybe worth pointing out- that's a feature, not a bug.
The value Ticketmaster provides is taking the anger from fans for high prices. The performers (and producers/labels/whatever) want to extract as much value from their fans as they can, and having Ticketmaster look like the greedy badperson prevents their fans from being mad at them.
Comparing apples and oranges here but I like thinking about the monetary value assigned to a byte.
Ticketmaster Hacker Demands $500K Ransom (Plus $300K Ransom Processing Fee, $220K Ransom Handling Fee)
https://theshovel.com.au/2024/05/30/ticketmaster-hacker-dema...
(posted on HN here: https://news.ycombinator.com/item?id=40534868)
Also, general informational map of those likely affected based on the Ticketmaster breach at least.
https://developer.ticketmaster.com/assets/img/products-and-d...
Also: Okta also just got hit, and had 99% of user data stolen. Might be related.
https://www.govexec.com/technology/2023/11/okta-breach-inclu...
The Snowflake breach supposed affects up to 400 companies with a single credential exfiltration. The world wide web's starting to seem like more work than its worth...
Also, lots of coverage. Just not front and center.
(Reuters) https://www.reuters.com/technology/cybersecurity/live-nation...
(Fox Business) https://www.foxbusiness.com/technology/hackers-claim-ticketm...
(Bloomberg) https://www.bloomberg.com/news/articles/2024-05-31/live-nati...
(FT, Santander Portion) https://www.ft.com/content/cfeec015-60b2-4106-a279-4c74fbfd4...
(Associated Press) https://apnews.com/article/ticketmaster-live-nation-data-bre...
(BBC, Santander theft, claimed link to Snowflake) https://www.bbc.com/news/articles/c6ppv06e3n8o
(CNN) https://www.cnn.com/2024/05/31/business/live-nation-ticketma...
(NBC) https://www.nbcnews.com/business/live-nation-probing-ticketm...
(CBS) https://www.cbsnews.com/video/what-to-know-about-alleged-tic...
(Bleeping Computer) https://www.bleepingcomputer.com/news/security/snowflake-acc...
(Law360) https://www.law360.com/articles/1842317/live-nation-confirms...
(Techcrunch, apparently did a secondary verification) https://techcrunch.com/2024/05/31/live-nation-confirms-ticke...
(Security Week, note that new BreachForums and post may be honeypot) https://www.securityweek.com/hackers-boast-ticketmaster-brea...
(Spiceworks, BreachForums may have ShinyHunters as admins, and ShinyHunters are suspected of being middlemen or proxies) https://www.spiceworks.com/it-security/data-security/news/ti...
(Malware Bytes, screen cap of the post from BreachForums) https://www.malwarebytes.com/blog/news/2024/05/the-ticketmas...
> TechCrunch on Friday obtained a portion of the allegedly stolen data containing thousands of records, including email addresses. This included several internal Ticketmaster email addresses used for testing, which are not public but appear as real Ticketmaster accounts. TechCrunch verified on Friday that the records we checked belong to Ticketmaster customers.
> TechCrunch checked the validity of these accounts by running the internal email addresses through Ticketmaster’s sign-up form. All of the accounts came back as real. (Ticketmaster displays an error if someone enters an email address that is already a real Ticketmaster account.)
In addition to the accounts working, which in itself is pretty bad. There's also the internal test accounts.
What's the biggest data hack ever?
Ticketmaster surely uses Snowflakes services to store data making it downstream of Ticketmasters own services.
This is a far more scary claim than OP's article, because that means there could be many more compromised customers out there that don't know it yet. It's a bit chilling, knowing some friends might be in deep shit.
Webdevs of HN: how many of you make a point of allowing sub-addressing?
* https://en.wikipedia.org/wiki/Email_address#Sub-addressing
This was all because people were doing abuse more easily by churning lots of accounts while only needing 1 gmail address. Plugging this gap was a huge deal for us in reducing card testing problems.
At the end of the day, nothing will thwart a determined person. But that’s not the goal. If it deters the vast majority of your users from making duplicate accounts, then it’s still a success.
Perfect is the enemy of good, after all.
Is that limited by domain? gmail's dot handling isn't at all standard; e.g. john.doe@outlook.com and johndoe@outlook.com are different accounts, as are john.doe@icloud.com and johndoe@icloud.com.
Not allowing a '+' to appear in the local part is not even that unreasonable. It's against the standard, but then "My email is this@example.com"@example.com is valid according to the standard so take the standard with a grain of salt.
Because lots of folks fat finger their own e-mail addresses and then complain that a 'site sucks' because signing up doesn't work. Sanity checking to protect people against themselves may be treated as a form of UX: it's probably why some forms insist you type (not copy-paste) your e-mail twice.
Though if possible I'd err on the side of being too permissive rather than too restrictive. In the end the only true way to validate an address is to send it an email.
This is the standard.
“Taking it with a grain of salt” results in broken websites and servers that reject valid mail addresses.
The generated addresses are all completely distinct, and can be revoked.
They look like for example:
happy.wombat-0a@icloud.com
dingus-capybara.0e@icloud.com
Like grandparent said: by having a catch-all email address on a domain. Then emails that are being sent to invalid email accounts on that domain end up in that mailbox.
Another commenter in the thread presented how their company "normalizes" gmail addresses by removing "." character and "+..." suffixes, so users don't abuse their system by creating multiple accounts with what is basically the same email. Having a catch-all mailbox allows people to circumvent this "security" measure.
I'm imagining that you actually want to have separate emails pointing to separate mailboxes, and for that case indeed, your solution is better, but for the life of me I can't imagine why anyone would prefer having to check multiple emails, instead of a single one. :D
I also use random name aliases on each signup. Even if you aggregate multiple breaches I doubt anybody would link it to an individual (me).
The big remaining issue is payments. I use multiple cards and rotate them regularly (I don't have access to privacy.com or similar where I am based).
I believe this is the future - feed each service you signup to a new set of information and keep track in a password managers. Most services don't care what your real name is (I've been using an alias on services like Uber for ~10+ years).
icloud is also a good option - but I don't want to signal being an iCloud user.
Per another comment, all one would need for it to not work is have a regex of [a-zA-Z0-9]@[a-z.]+, or using POSIX-compat, [:alnum:].
* https://en.wikipedia.org/wiki/Regular_expression#Character_c...
Only a small minority of my email addresses I've ever had matches that pattern.
The example is illustrative, and not definitive, as to how the simple and innocuous decision about a regex can determine functionality, and it is not about someone going "out of your way to make that not work" to break things.
And you can unintentionally cause sub-addressing to not work without having "to go out of your way to make that not work" like the GGGP wrote.
David.Calhoun@boeing.com
would be completely normal.
Yet the above regex would not match it. Whoops.
Likewise,
can_you_believe_it@hotmail.com
which is also completely normal and typical, would fail the regex as well.
But I guess if the only kind of customers you want are the
fred@hotstartup.com
and
jane@some-vc.com
people then sure, this otherwise wholly inadequate regex would serve you well.
In my experience, most but not all sites will accept "+" email addresses.
A kid working at McDonalds requires a safe food handling certificate, and the store will be shut down if an inspector sees their fridge is too warm.
Hopefully with E2E encryption, passkeys, and the like, the end of days is near for these massive data leaks, but without real consequences, these companies will never realize holding millions of people’s personal information is both a liability as well as an asset.
> Dear Ticketek Customer,
> We are writing to let you know that Ticketek has become aware of a cyber incident impacting Ticketek Australia account holder information, which is stored in a cloud-based platform, hosted by a reputable, global third party supplier.
> We would like to reassure you that Ticketek has secure encryption methods in place for all passwords and your Ticketek account has not been compromised. In addition, we utilise secure encryption methods to handle credit card information and transactions are processed via a separate payment system which has not been impacted. Ticketek does not hold identity documents for its customers.
> Since our third party supplier brought this to our attention, over the past few days we have worked diligently to put every resource into completing an investigation, so that we can communicate with you as quickly as possible. We wanted to notify you early to enable you to take steps to protect your information as a precautionary measure.
> We have also notified the Australian Cyber Security Centre (ACSC) and we are liaising with the Office of the Australian Information Commissioner (OAIC) and the National Office of Cyber Security in relation to the incident.
Full email: https://imgur.com/a/HOwR98C
Hope you hashed, salted, peppered those passwords Ticketmaster. And I hope you were following PCI level 1 correctly otherwise if this is true then you're a bit fucked really aren't you.
Ah yes, karma, that legendary force which revenges itself upon evil businesses like Ticketmaster by checks notes exposing the personal and financial information of their unwilling customers.
The initial account that shared the sale had no reputation on the forums. But it was then reposted by one of the admins, and that is the only piece of credibility this story has.
https://web.archive.org/web/20060110132428/http://www.mashab...
It makes us wonder how things could be tightened up and what can be applied to our own organisations.
If the hackers got passwords then how come there wasn’t 2FA?
Or did they get a Trojan onto an employee computer and surf onto it the corporate vpn?
Or did they corrupt an employee?
Or did the evil maid or something?
And how long did they have access?
Or another approach?
I don't see appreciable movement in their stock at all.
That's because there is zero accountability for these breaches and even with a civil case you're looking at pennies per user as compensation.
Better to do that than invest the 10s of millions required to correctly invest in good security practice and hygiene.
This is the classic fight club scenario:
"Take the number of vehicles in the field, A, multiply by the probable rate of failure, B, multiply by the average out-of-court settlement, C. A times B times C equals X. If X is less than the cost of a recall, we don't do one."
OF, stolen data _of_ 560M Ticketmaster Users. Mitchell & Webb - Identity Theft all over again.
Security Fee: $49 per ticket.https://www.space.com/brightest-quasar-ever-powered-black-ho...
That's pretty pissed off!
You might not like the term and how it might seem to shift blame, but it's the correct term.
https://www.law.cornell.edu/uscode/text/18/1028A
Aside from legal definitions, it's definitely a broadly used term in the public arena as well. According to Wikipedia, it's been used this way since 1964.
It absolutely shifts blame, and the term came from the banking sector themselves with the purpose of doing so.
I could not care less what the "correct" term is. It is credit fraud, full stop. No one has stolen any one's identity.
Obligatory Mitchell & Webb: https://www.youtube.com/watch?v=CS9ptA3Ya9E
As far as I can see after a bit of research, that doesn't seem to be the case. Do you recall where you first heard that idea?
> No one has stolen any one's identity.
Nobody thinks that a victim of identity theft is left with no identity. It's figurative language just like your computer firewall isn't there to keep the flames back.
Oh, wait.
There should be real, criminal penalties for leaking authentic, government-ID PII these days.
A prolific poster on Hacker News before his death. You'll need showdead enabled to see most of his comments.
I recently managed to get Temple OS to run in a VM for the first time. It’s quite something!
I didn't know he worked at Ticketmaster. Thanks.
I’m shocked to learn Terry Davis is dead. RIP
I believe he is, and I took OP's comment charitably.
If I told your secrets after we agreed not to share them, it would be a moral violation, even if you still had the copy of the journal that you recorded the secrets in.
Take requires /remove/.