HackingStolen CredentialsTargetedPIIIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Vivendi Ticketing US, LLC
bd_b32d0c2905129347 · schema v1 · pii pii-v1
Full breach record for Vivendi Ticketing US, LLC →Vivendi Ticketing US LLC d/b/a See Tickets notified consumers of a security compromise in May 2023 involving malicious code inserted into e-commerce checkout pages. The incident affected customer payment card information, names, and addresses for purchases made between February 28 and July 2, 2023. See Tickets engaged forensic specialists, implemented additional safeguards, and offered 12 months of identity monitoring through Kroll.
Vermont clock✗ VT AG >45 bday18 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_68b0b0d0ba644e3dNew Hampshire State AGfiled 2023-09-05Verified
- bd_7c9016418a3cd955Washington State AGfiled 2023-09-05Candidate
- bd_cecd7c73d6edfb66California State AGfiled 2023-09-05Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-09-05-vivendi-ticketing-us-llc-dba-see-tickets-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 5, 2023
- Raw hash
- 78240aa86bd7478ce6a6a4e0af4ec1fb2bd8d779d924bbab2dc9be06b07a67f6
Reporting entity
- Name
- Vivendi Ticketing US, LLCnorm: vivendi ticketing us
Victim entity
- Name
- Vivendi Ticketing US, LLCnorm: vivendi ticketing us
Incident
- Discovered
- May 1, 2023
- Materiality determined
- Sep 5, 2023
- Notification sent
- Sep 5, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Regulator citations
- notified applicable regulatory bodies
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 18 weeks(127 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.