HackingDelayed DiscoveryMulti-Stage ChainIDENTITY_BASICFINANCIAL_ACCOUNTAUTHENTICATIONLowContained
Vivendi Ticketing US, LLC
bd_2805835511f4b1cb · schema v1 · pii pii-v1
Full breach record for Vivendi Ticketing US, LLC →Vivendi Ticketing US LLC (d/b/a See Tickets US) notified customers of a data breach involving unauthorized access to event checkout pages. The incident, detected in April 2021, affected payment card data (including CVV) and basic PII for transactions between June 2019 and January 2022. The company engaged forensic investigators and law enforcement, and deployed additional security monitoring and authentication safeguards.
California clockDiscovered Apr 1, 2021 → Notified Oct 21, 2022568d ✗ CA 60-day late19 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_049137d5e49d3d0aMaine State AGfiled 2022-10-24Verified
- bd_34a562dc28087291Oregon State AGfiled 2022-10-24Verified
- bd_57af8d246f1d6637Montana State AGfiled 2022-10-21(3d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-558540
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 24, 2022
- Raw hash
- 90bfaa02c0aa35cb4eb7e8f6cd12326a5613073f5d1acea7126cd4fc22a724bd
Reporting entity
- Name
- Vivendi Ticketing US, LLCnorm: vivendi ticketing us
Victim entity
- Name
- Vivendi Ticketing US, LLCnorm: vivendi ticketing us
Incident
- Discovered
- Apr 1, 2021
- Materiality determined
- Sep 12, 2022
- Notification sent
- Oct 21, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTAUTHENTICATION
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 19 months(571 days from discovery to filing)
- Compliance flags
- CA 60-day late · 568d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 1, 2021→ Notified: Oct 21, 2022568d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.