Ticket sales service provider “See Tickets” recently informed its customers of a data breach in which cybercriminals may have gained access to the payment card details of those who had purchased tickets through its website.
See also: Netherlands: Hacker arrested for stealing medical data

“Skimming” is a type of fraud where cybercriminals use snippets of JavaScript code to steal payment card details from customers. In this case, the skimmers were inserted into order pages for live entertainment event tickets.
In April 2021, See Tickets discovered the data breach and immediately launched an investigation with the help of a forensics firm.
See also: Hive ransomware: Claims to have attacked Tata Power
The malicious code was not fully removed from the website until January 8, 2022.
See Tickets concluded on September 12, 2022, that unauthorized parties may have gained access to customer credit card information. It worked with forensic experts and Visa , MasterCard , American Express , and Discover to investigate the incident
The infection occurred on June 25, 2019, and was active for 2.5 years before being discovered.
Hackers may have stolen the following customer data:
- Full names
- Address
- Postal code
- Payment card number
- Card expiration date
- CVV number
See Tickets announced that social security numbers, state ID numbers, and bank account information were not exposed as a result of the incident because this type of data is not stored on its systems.
The type of data the hackers stole puts users at risk for unauthorized credit card transactions and identity theft, so See Tickets urges customers to be vigilant.
In order to launder money, threat actors often purchase goods from online stores with stolen credit card details and then resell them to individuals.
The processes of these sales often bounce through “money mule” networks before reaching the fraudsters to cover their tracks .

See also: Cuba ransomware attacks critical Ukrainian networks
The notice urges affected recipients to be wary of phishing emails or other unsolicited communications and to monitor their credit card statements for any unusual charges.
It is unclear how many customers were affected by the skimmers, and See Tickets has not commented on whether only the global website or any of its other domains in different regions were infected.
Information source: bleepingcomputer.com
