{"id":3852,"date":"2024-06-03T12:20:05","date_gmt":"2024-06-03T17:20:05","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/ticketmaster-confirms-cloud-breach-murky-details"},"modified":"2024-06-03T12:20:05","modified_gmt":"2024-06-03T17:20:05","slug":"ticketmaster-confirms-cloud-breach-amid-murky-details","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/06\/03\/ticketmaster-confirms-cloud-breach-amid-murky-details\/","title":{"rendered":"Ticketmaster Confirms Cloud Breach, Amid Murky Details"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt783461e609a2ba2b\/665dfc477182360786a98ba4\/ticketmaster_Jaap_Arriens_alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ticketmaster-confirms-cloud-breach-amid-murky-details.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ticketmaster-confirms-cloud-breach-amid-murky-details.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Last week, the hack-and-leak ring known as ShinyHunters put what it alleged to be data on more than a half-billion <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/leak-site-breachforums-springs-back-to-life-weeks-after-fbi-takedown\" rel=\"noopener\">Ticketmaster customers up for sale on the BreachForums underground market<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. After days of reports and speculation from media about the validity of the claim, Ticketmaster parent Live Nation has now acknowledged that the breach was real. However, it has confirmed few other details.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Last Friday, Live Nation filed a data breach disclosure <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.sec.gov\/Archives\/edgar\/data\/1335258\/000133525824000081\/lyv-20240520.htm\" rel=\"noopener\">notice<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> with the US Securities and Exchange Commission (SEC), noting that there was &#8220;unauthorized activity within a third-party cloud database environment containing company data&#8221; on May 20, and that &#8220;a criminal threat actor offered what it alleged to be company user data for sale via the Dark Web&#8221; on May 27.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">However, the events giant didn&#8217;t confirm the mind-boggling number of records (560 million) that <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/researchers-share-common-tactics-of-shinyhunters-threat-group\" rel=\"noopener\">ShinyHunters<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> claimed to have, nor did it reveal details on what type of data the heist contains. In the BreachForums listing, the threat actors professed to have personally identifiable information (PII) such as names, emails, addresses, and partial payment card details.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Nonetheless, the SEC filing appears to be voluntary, and notes that <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/orgs-face-major-sec-penalties-failing-disclose-breaches\" rel=\"noopener\">LiveNation doesn&#8217;t expect the breach to be &#8220;material,&#8221;<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> i.e. impactful to its financial profile going forward. That suggests that it expects little fallout from the incident, and belies the claims in the underground listings.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Ticketmaster did not return a request for comment from Dark Reading.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Third-Party Cloud Database Security Lacking\">Third-Party Cloud Database Security Lacking<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As for the third-party cloud database involved, members of the threat intelligence community in emails to Dark Reading have identified it to be Snowflake, which issued its own statement acknowledging that there has been cyberactivity directed towards some of its customers, which include Ticketmaster. But, the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/community.snowflake.com\/s\/question\/0D5VI00000Emyl00AB\/detecting-and-preventing-unauthorized-user-access\" rel=\"noopener\">posting<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> on its community forum didn&#8217;t name names as to which customers are affected, and the company didn&#8217;t immediately respond to a request for comment.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Snowflake did note that the attacks succeeded due to poor customer configuration: &#8220;This appears to be a targeted campaign directed at users with single-factor authentication; as part of this campaign, threat actors have leveraged <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/sale-of-stolen-credentials-and-initial-access-dominate-dark-web-markets\" rel=\"noopener\">credentials previously purchased or obtained<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> through infostealing malware.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Overall, there&#8217;s little confirmation when it comes to the exact details of the breach, who&#8217;s affected and how, and the contours of the incident regarding Snowflake and which of its <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.snowflake.com\/en\/customers\/\" rel=\"noopener\">customers <\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">might be affected. Beyond Ticketmaster, high-profile Snowflake accounts include AT&amp;T, jetBlue, Mastercard, and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/santander-falls-victim-to-data-breach-involving-third-party-provider\" rel=\"noopener\">Santander, which recently reported its own data breach<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> involving an unnamed third-party provider (it has not confirmed that Snowflake was the affected account).<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">To boot, Matt Hull, global head of threat intelligence at NCC Group, said that it&#8217;s even unclear what role ShinyHunters is playing.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;A post on a Russian cybercriminal forum was made more than a day before ShinyHunters&#8217; post on BreachForums concerning the sale of Ticketmaster\/Live Nation data,&#8221; he said in an emailed statement. &#8220;The notable difference between the two listings is that the post on the Russian forum requires a guarantor, whereas ShinyHunters&#8217; post on Breach Forums does not. It is possible that ShinyHunters are acting as a proxy\/middleman for the sale of data for the original attackers.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It&#8217;s unclear when additional details might emerge on the breach, but for now, Live Nation delivered boilerplate language in its SEC filing: &#8220;We are working to mitigate risk to our users and the company, and have notified and are cooperating with law enforcement. As appropriate, we are also notifying regulatory authorities and users with respect to unauthorized access to personal information.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/ticketmaster-confirms-cloud-breach-murky-details\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Last week, the hack-and-leak ring known as ShinyHunters put what<\/p>\n","protected":false},"author":12,"featured_media":3853,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3852","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ticketmaster-confirms-cloud-breach-amid-murky-details.jpg?fit=1800%2C1013&ssl=1",1800,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ticketmaster-confirms-cloud-breach-amid-murky-details.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ticketmaster-confirms-cloud-breach-amid-murky-details.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ticketmaster-confirms-cloud-breach-amid-murky-details.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ticketmaster-confirms-cloud-breach-amid-murky-details.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ticketmaster-confirms-cloud-breach-amid-murky-details.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ticketmaster-confirms-cloud-breach-amid-murky-details.jpg?fit=1800%2C1013&ssl=1",1800,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ticketmaster-confirms-cloud-breach-amid-murky-details.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ticketmaster-confirms-cloud-breach-amid-murky-details.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ticketmaster-confirms-cloud-breach-amid-murky-details.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ticketmaster-confirms-cloud-breach-amid-murky-details.jpg?fit=1800%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3852","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3852"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3852\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3853"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3852"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3852"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3852"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}