In late May 2024 a listing appeared offering data said to cover around 560 million Ticketmaster customers, taken from the company’s Snowflake environment. The figure came from the sellers.
The parent company subsequently confirmed unauthorised activity and notified affected individuals. This desk has not seen a company figure that corroborates 560 million, and treats the number as a claim throughout.
Why This File Is Graded Low And 24-0712 Is Graded High
The AT&T figure came from the company under a disclosure obligation. This one came from a sales post. Both describe the same campaign and they are not the same kind of statement.
The grade tracks what is established, not how large the incident was. A 560 million claim graded low sits below a 110 million disclosure graded high, and that ordering is the point of having grades at all.
A Ticketing Record Count Is Not A Person Count
A row in a ticketing database is a transaction. One person who has bought tickets over a decade may appear many times, under different addresses and cards.
The corpus keeps records and people apart wherever it can, and a seller has every incentive to quote whichever is larger. At 25-0215 the leaked chats suggested demands were priced off victim revenue rather than off the material taken, which gives the volume figure no role except advertising.
What Is Established
That the tenant was reached, that data was taken, and that notifications followed. That is considerably less than the headline and it is what this file records.
Compiled from contemporaneous reporting, listed below. The 560 million figure originates with the party offering the data for sale and is labelled a claim in the prose and in the case card. This desk has not seen the listing, has not reviewed any sample, and has not seen a company figure. Graded low on that basis, not because the incident was small. Corrections: corrections@forensicpost.com.