TrollEye Security

Cyber News

The Ticketmaster Saga Continuous With Taylor Swift Tickets Being Leaked

In the latest chapter of the Ticketmaster and Snowflake breach saga, hackers have leaked alleged barcode data for 166,000 tickets to Taylor Swift's Eras Tour, demanding a $2 million ransom

Details of the Story

In a continuation of the Ticketmaster and Snowflake cyber-attack saga, hackers have leaked what they allege is barcode data for 166,000 tickets to Taylor Swift’s Eras Tour. The cybercriminals are demanding a $2 million ransom to prevent further leaks, warning that more events will be targeted if their demands are not met.

This incident traces back to May when the notorious hacker group, ShinyHunters, began selling data on 560 million Ticketmaster customers for a staggering $500,000. The breach was later confirmed by Ticketmaster, who identified the source of the leak as their account on Snowflake, a cloud-based data warehousing platform used for storing and processing vast amounts of data.

In April, cybercriminals initiated their attacks by downloading databases from at least 165 organizations via Snowflake, utilizing credentials stolen by information-stealing malware. The hackers then extorted these companies, demanding payment to prevent the data from being leaked or sold. Among the affected organizations are high-profile names such as Neiman Marcus, Los Angeles Unified School District, Advance Auto Parts, Pure Storage, and Santander.

A threat actor known as Sp1d3rHunters has claimed responsibility for leaking ticket data for 166,000 Taylor Swift Eras Tour barcodes. Sp1d3rHunters, formerly known as Sp1d3r, has been linked to the sale of data stolen from Snowflake accounts and has publicly extorted companies for payments.

Their extortion demand, first shared by the threat intelligence service HackManac, states: “Pay us $2 million USD or we leak all 680M of your users’ information and 30 million more event barcodes, including more Taylor Swift events, P!nk, Sting, sporting events like F1 Formula Racing, MLB, NFL, and thousands more.”

The post from the hackers claims the barcode data pertains to upcoming Taylor Swift concerts in Miami, New Orleans, and Indianapolis. It includes a sample of the alleged data, showcasing values used to create scannable barcodes, seat information, ticket face value, and more. Instructions on converting this data into scannable barcodes were also provided.

Although the barcode data was not part of the initial leak in May, some of the newly leaked data overlaps with older leaks, including hashed credit card and sales order information.

Ticketmaster has emphasized the robustness of their SafeTix technology, which refreshes unique barcodes every few seconds, making the stolen tickets unusable. They said that their SafeTix technology protects tickets by automatically refreshing a new and unique barcode every few seconds so it cannot be stolen or copied, making these tickets unusable.

The company also confirmed that they did not engage in ransom negotiations with the hackers, disputing claims by ShinyHunters that they were offered $1 million to delete the data.

Share:

Live Webinar

From Discovery to
Risk Reduction

Operationalizing CTEM in Modern Security Programs

Date September 24, 2026
Time 2:00 PM Eastern

Learn how modern security teams can move beyond finding exposures and operationalize every stage of Continuous Threat Exposure Management.

01 Scope
02 Discover
03 Prioritize
04 Validate
05 Mobilize
Reserve Your Spot

Free registration · Live discussion and Q&A

This Content Is Gated