The Arkana Security ransomware group caused a stir last weekend, claiming to have stolen Ticketmaster data for sale . It posted screenshots of the data it had obtained (569 GB) as a result of a recent breach.

However, according to research by BleepingComputer, the data that appeared in Arkana’s post fully matches previous samples that were leaked during the “data thefts ” in 2024.Specifically, one of the images bore the phrase “rapeflaked copy 4 quick sale 1 buyer,” making a clear reference to the “RapeFlake” tool — a specialized tool used by the perpetrators to identify and extract data from Snowflake databases.
See also: Hackers exploit old AT&T data breach
The attacks, claimed by the infamous ShinyHunters, targeted a number of organizations, including Santander, AT&T, Neiman Marcus, Pure Storage , and of course Ticketmaster. The attackers gained access using customer credentials that had previously been stolen via info-stealer malware.
Ticketmaster: The Snowflake leak and the suspicious movements of Arkana Security
Ticketmaster was one of the most prominent victims of the “Snowflake attacks,” with cybercriminals stealing sensitive personal data and ticketing information. The company confirmed the breach in late May, notifying its customers affected by the attack.
The perpetrators didn’t stop there, however. As part of the ensuing extortion campaign, they posted what they claimed were “print-at-home” tickets, including Taylor Swift concert tickets, on hacking forums — a move aimed at causing public panic and increasing pressure on the company.
See also: Malicious RubyGems posing as Fastlane and stealing Telegram API data
Although the Arkana Security did not specify the origin of the data, the use of terms related to Snowflake and the similarity of the files to previous samples suggest recycling of previous thefts, possibly in an attempt to resell already exposed information.
Whether Arkana obtained this data from other actors, whether it already had it in its possession, or whether it was operating in collaboration with the notorious ShinyHunters group remains unclear. However, on June 9, the related post about Ticketmaster disappeared from Arkana Security’s website.

Violations related to ticket companies
Breaches involving concert and event ticketing companies are not uncommon. In March, New York prosecutors alleged that two people working for a third-party contractor for online ticketing site StubHub made $635,000 after stealing nearly 1,000 concert tickets (mostly for Taylor Swift's Eras tour) and reselling them online. In addition to the Taylor Swift tickets, tickets for Ed Sheeran and Adele concerts , as well as for NBA and US Open tennis championships , were also stolen .
See also: The North Face: Credential stuffing attacks allowed data breach
The two defendants, Tyrone Rose and Shamara Simmons, worked for Sutherland Global Services in Jamaica (an external partner of StubHub) and stole the tickets, hacking into approximately 350 StubHub orders. They did this by exploiting a security flaw in the platform of an offshore ticket seller.
Source: www.bleepingcomputer.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
