HackingRetail & ConsumerTechnologyInformationCapture Stored DataSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICMediumContained
Ticketmaster Entertainment, Inc.
bd_deb6d2a5bcc2b0c9 · schema v1 · pii pii-v1
Full breach record for Ticketmaster Entertainment, Inc. →Ticketmaster LLC disclosed a breach of a cloud database at a third-party data services provider. Unauthorized activity ran April 2–May 18, 2024; discovered May 23, 2024. Exposed data included names, contact info, and additional personal identifiers. 1,000+ Maine residents affected. Remediation included password rotation, access review, enhanced alerting, and 12-month TransUnion identity monitoring.
Maine clockDiscovered May 23, 2024 → Filed with AG Jun 28, 202436d ⏱ ME AG >30d5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_bf0a03842a98127dCalifornia State AGfiled 2024-06-27(1d gap)Verified
- bd_c57115259345cf71Indiana State AGfiled 2024-06-27(1d gap)Verified
- bd_e9e9b2d5155b036fVermont State AGfiled 2024-07-05(7d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/0d26b6dd-b466-4f2a-bec0-ec2ad0738583.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 28, 2024
- Raw hash
- b0eca41e3d8e0fb657ae7ab8d7c3603e093837c73def81b05299351c00d7b855
Reporting entity
- Name
- Ticketmaster Entertainment, Inc.norm: ticketmaster entertainment
- Domain
- ticketmaster.com
Victim entity
- Name
- Ticketmaster Entertainment, Inc.norm: ticketmaster entertainment
- Domain
- ticketmaster.com
- Industry
- Retail & ConsumerllmTechnologyllm
Incident
- Discovered
- May 23, 2024
- Materiality determined
- May 23, 2024
- Notification sent
- Jul 8, 2024
- Affected individuals
- 1,000
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1530 Data from Cloud StorageT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Cooperating with federal law enforcementNotified Maine Attorney General
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- ME AG >30d · 36d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: May 23, 2024→ Filed with AG: Jun 28, 202436d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.