HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)PIIIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
ShowTix4U
bd_1eff4f516cf58698 · schema v1 · pii pii-v1
Full breach record for ShowTix4U →ShowTix4U disclosed a data breach affecting customers who made payment card purchases on ShowTix4U.com between December 11, 2016, and February 2, 2017. An unauthorized actor accessed a third-party vendor's server and installed malicious software to capture payment card information, including names, addresses, email, phone numbers, account numbers, expiration dates, and CVVs. The incident has been contained, forensic experts were engaged, and the company transitioned away from the compromised vendor. The incident was reported to federal law enforcement.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-67213
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 29, 2017
- Raw hash
- 538ea77fea828ff953ed0a4167820a3fe458fd71da32d2df0474a462fbdd4e0d
Reporting entity
- Name
- ShowTix4Unorm: showtix4u
- Domain
- showtix4u.com
Victim entity
- Name
- ShowTix4Unorm: showtix4u
- Domain
- showtix4u.com
Incident
- Discovered
- Feb 2, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1056 Input Capture
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported the incident to federal law enforcement
- Initial access
- supply_chain
Compliance
- Time to disclose
- 8 weeks(55 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.