In May 2024, the hacking group ShinyHunters claimed to have stolen 1.3 terabytes of data from Ticketmaster and its parent company Live Nation — affecting an estimated 560 million customers worldwide. If you received a Ticketmaster data breach notification letter or email, your personal and financial information may have been exposed. Here is what you need to know.
ShinyHunters announced the breach on May 20, 2024, on a notorious cybercrime forum, offering the stolen data for sale for $500,000. Live Nation confirmed the breach on May 31, 2024, in an SEC filing, acknowledging that a criminal threat actor had obtained data from a third-party cloud database environment — later identified as Snowflake, a cloud data storage provider.
This breach was not caused by a vulnerability in Ticketmaster's own network alone, but rather through compromised credentials that allowed attackers access to Ticketmaster's cloud-hosted data. This distinction matters legally — companies have an obligation to protect data regardless of where it is stored.
Based on information published by the threat actors and confirmed in part by Ticketmaster, the stolen data includes:
The breadth of this dataset — combining contact information with purchase history and partial payment data — creates significant risk for phishing attacks and social engineering fraud.
Multiple class action lawsuits were filed against Live Nation and Ticketmaster in the weeks following the breach disclosure. These lawsuits allege that Live Nation failed to implement adequate security measures to protect customer data and was too slow to notify affected customers.
As a named affected customer, you may be eligible to participate in one of these class action claims. Participation is typically free and requires no upfront costs — attorneys are compensated only if a settlement or judgment is reached.
The breach affected users globally. The majority of Ticketmaster's customer base is in the United States, and early estimates suggested tens of millions of U.S. customers were included in the compromised dataset.
This breach is specific to Ticketmaster and Live Nation platforms. If you used StubHub, SeatGeek, or other services, your data there was not affected by this particular breach.
No. In many data breach class actions, the exposure of your personal data itself constitutes a compensable harm. You do not need to demonstrate that you were a victim of fraud as a result of this specific breach in order to be eligible.
Related: Search the Breach Registry · How to Join a Data Breach Class Action · Free Case Review
The Law Office of David S. Harris offers free consultations — no fee unless we win.
No fee unless we win your case. Licensed in Florida — nationwide cases.
(786) 306-7278Get a Free Case ReviewData Breach Class Action: A Comprehensive Guide to Your Rights and Recovery
July 19, 2026 · 14 min read
Data Breach Notification Letter Guide: What Your Notice Means and How to Respond in 2026
July 19, 2026 · 12 min read
Class Action Lawsuit Settlement Guide: How to Claim Your Recovery in 2026
July 19, 2026 · 13 min read