Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesSome links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Live Nation confirmed that an unauthorized party accessed a third-party cloud database containing primarily Ticketmaster data. But the company did not verify the widely repeated claim that 560 million customer records were stolen, and its public disclosures do not establish the full contents of the database or exactly how access occurred.
What Live Nation confirmed
In a May 31, 2024 filing with the U.S. Securities and Exchange Commission, Ticketmaster parent company Live Nation said it had identified unauthorized activity in a third-party cloud database containing primarily Ticketmaster data. The company said it discovered the activity on May 20 and began an investigation, working with law enforcement.
That establishes an unauthorized-access incident involving a database with Ticketmaster information. It does not establish that every record in the database was taken, how many unique people were affected, or that all Ticketmaster systems were accessed.
Recommended Free Tools
What information may have been involved
Ticketmaster’s customer incident notice says information potentially affected for some customers who bought tickets to events in the United States, Canada, and/or Mexico may have included email addresses, phone numbers, encrypted credit-card information, and other information customers provided to Ticketmaster.
#1 Best Overall
The notice does not say that every customer was affected. Nor does it confirm that passwords, ticket barcodes, government identification, or plaintext card numbers were exposed. “Encrypted” card information should not be treated as proof that the data was harmless, but the public notice does not provide enough technical detail to say whether it could be decrypted or used.
The 560-million figure is an attacker claim
The figure of 560 million came from hackers advertising an alleged Ticketmaster database for sale. Reports said the group ShinyHunters claimed the database contained that many customer records and advertised it as a 1.3-terabyte file. Live Nation’s SEC filing and Ticketmaster’s customer notice did not confirm either figure.
A record count is not necessarily a count of unique, current customers. A dataset offered for sale could contain duplicates, outdated or incomplete entries, or records from different sources. The company’s public disclosures do not authenticate the advertised database or establish how much of it, if any, was taken. Coverage by TechCrunch and Dark Reading describes the claims; they should not be mistaken for a company-verified customer count.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
What is known about the timeline
- May 20, 2024: Live Nation said it identified unauthorized activity and began investigating.
- May 27: Live Nation reportedly said a criminal threat actor had offered Ticketmaster data for sale on the dark web.
- May 31: Live Nation disclosed the incident in its SEC filing.
- June 2024 onward: Ticketmaster’s customer-facing notice described potentially affected information and its notification and monitoring process.
These are different milestones: discovery, an alleged sale, public corporate disclosure, and customer notification. Some customer communications reportedly placed activity between April 2 and May 18, 2024; that period is not the same as the date Live Nation said it discovered the incident.
Was Snowflake breached?
News reports linked the Ticketmaster incident to Snowflake, a cloud data-services provider. Snowflake separately acknowledged targeted cyberactivity involving some customers during the period. However, Live Nation’s SEC filing described a third-party cloud database without naming Snowflake. The connection is widely reported, but it is not identified in that filing as Ticketmaster’s confirmed provider.
More importantly, “cloud breach” does not by itself explain the access path. A cloud database can be reached through compromised credentials, weak authentication, overly broad permissions, exposed access tokens, or a provider-side issue. The public disclosures cited here do not establish which mechanism was responsible. It would therefore be premature to say that a Snowflake platform vulnerability caused the incident.
Were Ticketmaster accounts or passwords compromised?
Ticketmaster says customer accounts were not affected and that customers did not need to reset passwords because of this incident. It also says it found no further unauthorized activity in the affected database. That is the company’s statement about this incident—not a guarantee against separate risks such as reused passwords, compromised email accounts, or phishing.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Ticketmaster said relevant customers would be notified by email or first-class mail and offered 12 months of credit or identity monitoring. If you received a notice, follow the instructions through verified Ticketmaster channels and check the eligibility and enrollment details in the notice.
Best Value
What customers should do
- Look for an official notice. Ticketmaster says affected customers would be contacted by email or first-class mail. If you are unsure whether a message is genuine, do not use its links or phone number; navigate to Ticketmaster’s site or support independently.
- Review card and bank activity. Contact the card issuer or bank promptly if you see an unfamiliar transaction. Ask whether it recommends replacing the card; the breach alone does not mean every customer needs to cancel a card.
- Watch for tailored phishing. An email address or phone number combined with event-related context can make a fake message more persuasive. Do not provide passwords, one-time verification codes, payment details, or identity documents through unsolicited links or calls.
- Use unique passwords. Ticketmaster said a reset was not required because of this incident. Still, if you reused your Ticketmaster password elsewhere, change it on those other services and secure the associated email account with a unique password.
- Consider a credit freeze if the notice or your circumstances warrant it. A freeze can make it harder for someone to open new credit in your name, but it can also complicate legitimate credit applications until lifted. In the United States, the bureaus provide freeze instructions at Equifax, Experian, and TransUnion. Procedures differ by country.
- Report suspicious Ticketmaster impersonation. Ticketmaster’s scam guidance says suspicious messages can be reported to
[email protected]. Use the official site for support rather than numbers or links supplied by strangers or search advertisements.
These are precautions, not evidence that every listed fraud scenario occurred. The risk depends on which information, if any, was associated with a particular customer.
Confirmed, reported, and still unknown
| Status | What the evidence supports |
|---|---|
| Confirmed by Live Nation or Ticketmaster | Unauthorized activity in a third-party cloud database containing primarily Ticketmaster data; discovery on May 20, 2024; potentially affected data categories and North American scope described in Ticketmaster’s notice. |
| Reported or claimed | Hackers advertised a large database and claimed it covered 560 million customers; reporting linked the incident to Snowflake. |
| Not established in the cited public disclosures | The number of unique affected customers, exact records taken, whether the advertised dataset was authentic and complete, the precise access method, and whether passwords or ticket barcodes were involved. |
The key distinction is between confirmation that unauthorized access occurred and proof of the size and contents of what was accessed. The public record supports the former; it does not settle the latter.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

