DisclosureLens
SINGAPOREUnknownLow

Ticketmaster - Singapore Pte Ltd

bd_ca4660eab158cac1 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

May 23, 2024

To disclose

Affected

Not disclosed

Confidence

90%
Full breach record for Ticketmaster - Singapore Pte Ltd

Regulator's decision — not a breach notification

This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.

Background On 1 December 2023, Personal Data Protection Commission (the “ Commission ”) commenced investigations against Ticketmaster – Singapore Pte. Ltd. (the “ Organisation ”) upon being alerted that users trying to buy tickets to an event on the Organisation’s website were able to access and view another user’s Ticketmaster account (the “Incident”) . A s a result of the Incident, the personal data of a user, including their names, phone numbers, email addresses and order information (but not the ticket barcodes), was disclosed to a different user. The personal data of about 400 individuals was affected. Investigations revealed that the Incident occurred because the Organisation had failed to configure its content distribution network (“ CDN ”) software correctly when the Organisation upgraded its software. The users’ personal data was stored as shared cache objects based on the users’ IP address. This led to a user’s personal data being shown to another user if these users had been assigned to the same IP address when using the Organisation’s website. The Commission also found that the Organisation did not detect the misconfiguration as it conducted limited testing after the software upgrade. Remedial Actions Upon discovering the incident, the Organisation immediately took the following actions: (a) Rolled back its CDN software to an earlier version which resolved the cause of the Incident; and (b) Developed a dedicated testing environment for its CDN software. Voluntary Undertaking Having considered the circumstances of the case, including the remedial steps taken by the Organisation, the Commission accepted a voluntary undertaking on 9 April 2024 (the “ Undertaking ”) from the Organisation to improve its compliance with the Personal Data Protection Act 2012 (“ PDPA ”). The Organisation provided a comprehensive remediation plan to the Commission that sought to re

Incident timeline — partial

? — ?

Breach window unknown

May 23, 2024

Filed

No linked breach filing · watching

Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

Source ceiling

  • outcome + obligations
  • fine (SGD) and affected count where a grounds document states them
  • discovery date
  • notification clock

See the underlying breach notice, if any.