Fraud Basics
Fraud Basics

Is account takeover taking over the fraud landscape?

By Laura Harris, CFE
Please sign in to save this to your favorites.
Written by: Laura Harris, CFE
Date: January 1, 2025
Read Time: 8 mins

In May 2024, more than 500 million Ticketmaster customers were victims of a data breach attributed to hacking group ShinyHunters. Live Nation Entertainment, Ticketmaster’s parent company, confirmed the breach in a filing with the U.S. Securities and Exchange Commission (SEC) and reported that it had identified unauthorized activity within a third-party cloud database that contained company data.

ShinyHunters says it obtained 1.3 terabytes of Ticketmaster’s sensitive customer data, including credit card numbers and ticket sales. The group reportedly breached Ticketmaster’s cloud data because it had compromised the credentials of an employee of Snowflake, Ticketmaster’s cloud account. With the employee’s credentials, the cyberfraudsters created session tokens and accessed customer data. (See “Ticketmaster’s Encore: How ‘ShinyHunters’ Hacked the Show,” by Rodman Ramezanian, Skyhigh Security, July 11, 2024; “Ticketmaster Confirms Data Breach. Here’s What to Know.”, by Sopan Deb, The New York Times, May 31, 2024; and “U.S. SEC Form 8-K, 001-32601,” May 20, 2024.)

Begin Your Free 30-Day Trial

Unlock full access to Fraud Magazine and explore in-depth articles on the latest trends in fraud prevention and detection.