/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Ticketfly's breach exposed 26M+ email addresses of users, along with home and billing addresses as well as phone numbers, analysis of leaked data shows

The data breach of the ticket and event company Ticketfly exposed the email addresses and other personal data of more than 26 million people …

Motherboard Lorenzo Franceschi-Bicchierai

Context & Ripple Effects

Three days after Ticketfly went offline following a hacker's defacement and boasts of access to customer and employee records — coverage we carried in Ticketfly going offline over a cyber incident — an analysis of the leaked data puts a number on it: more than 26 million email addresses, plus home addresses, billing addresses, and phone numbers.

The scale matters because ticketing platforms aggregate exactly the identity-and-payment-adjacent data phishers want, and the sector keeps reappearing in this corpus: six years later, Ticketmaster faced ShinyHunters advertising 560M users' data for sale and confirmed unauthorized activity in a third-party cloud database.

First-order effects

  • Over 26 million Ticketfly users now have their email, physical address, billing address, and phone number in circulation, making them targets for targeted phishing that can reference real events and purchases.
  • Ticketfly must move from vague 'cyber incident' language to concrete user notification and remediation, now that the exposed fields are publicly documented.

Second-order effects

  • The breach hands Ticketmaster and other ticketing rivals a security-differentiation argument at the box office, while forcing them to audit whether their own customer databases carry the same email-plus-address-plus-phone payload.
  • Event organizers and venues choosing ticketing vendors gain a new due-diligence criterion — where attendee PII lives and how it is segmented — shifting procurement conversations toward data handling.

Third-order effects

  • If the pattern holds — Ticketfly in 2018, T-Mobile exposing names, billing addresses, and phone numbers for over a million customers in 2019, ShinyHunters monetizing alleged Ticketmaster data in 2024 — aggregated contact data stops being an asset on consumer platforms' books and becomes a standing liability priced into regulation and breach insurance.
  • The shift from defacement-style hacks to groups like ShinyHunters selling bulk user data points toward breach economics where stolen PII is inventory, raising the bar for how platforms justify retaining home and billing addresses long-term.

The trend: Consumer platforms' centralized troves of contact and billing data are recurring breach targets whose exposure is shifting from embarrassment incidents to a monetized criminal market, pushing regulators and buyers to treat retained personal data as a liability.