Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes—Ticketek disclosed a May 2024 data breach involving a third-party cloud platform. Have I Been Pwned (HIBP) later recorded almost 30 million rows and 17.6 million unique email addresses. Those are different measures: the row count is not a confirmed count of distinct people. The cloud provider and attacker have not been conclusively identified.

What happened in the Ticketek breach?

Ticketek’s parent company, TEG, said in May 2024 that customer information on a third-party cloud-based platform may have been accessed. In the contemporaneous disclosure quoted by AUSCERT on 28 June 2024, TEG said: “The available evidence at this time indicates that, from a privacy perspective, customer names, dates of birth and email addresses may have been impacted.”

HIBP records the incident as occurring in May 2024 and added it to the service on 28 June 2024.

How many people were affected?

No reviewed source establishes a final number of distinct affected people. HIBP’s current record, accessed in 2026, reports two separate figures:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Measure Figure What it means
Rows in the reported dataset Almost 30 million Records or rows in the dataset reported by HIBP; repeated addresses or multiple records may be included.
Unique email addresses 17.6 million Distinct email-address values identified by HIBP, not a verified count of individual people.

Accordingly, “almost 30 million affected” should not be read as proof that 30 million separate customers were involved. Even 17.6 million unique addresses cannot be converted directly into a people count because one person can have multiple addresses, an address can be shared, and some records may not represent current customers.

What information was exposed?

The sources describe the contents at different stages:

  • TEG’s initial public-facing statement: names, dates of birth and email addresses may have been impacted.
  • HIBP’s later dataset record: names, genders, dates of birth, salutations, email addresses and hashed passwords.

These descriptions are not necessarily contradictory: the first was a preliminary statement about information that may have been affected, while HIBP’s listing describes fields present in the dataset it received.

Was my Ticketek password or credit card exposed?

HIBP lists hashed passwords among the reported fields. A hash is not the original password, but weak or reused passwords can sometimes be guessed or cracked. Change the relevant password anywhere else you reused it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The reviewed disclosures do not list credit-card numbers as exposed data. That does not establish what every individual account contained; it means there is no evidence in these sources that payment-card details were part of the reported dataset.

Was Snowflake or ShinyHunters responsible?

That attribution remains unconfirmed. Dark Reading reported on 24 June 2024 that the cloud provider was unnamed and that TEG had not confirmed either Snowflake involvement or ShinyHunters as the attacker. Claims by an alleged attacker and similarities to other incidents should therefore be treated as allegations, not established facts.

What is confirmed

  • Ticketek disclosed a May 2024 incident involving a third-party cloud platform.
  • HIBP reported almost 30 million rows and 17.6 million unique email addresses.
  • HIBP’s listed fields include names, genders, dates of birth, salutations, email addresses and hashed passwords.

What is not established

  • The identity of the cloud provider.
  • A definitive count of distinct people affected.
  • A conclusive identification of the attacker.

What should Ticketek customers do now?

  1. Change reused passwords. If the password used for Ticketek was used on any other service, replace it there with a unique password. HIBP specifically advises changing an affected password anywhere it was reused.
  2. Turn on two-factor authentication. Enable 2FA on email, financial, shopping and other important accounts wherever the service supports it. An optional FIDO2 security key can provide a physical second factor, but compatibility varies by service and device.
  3. Watch for targeted scams. Be cautious with messages that use Ticketek details to request a password, payment or one-time code. Open the official app or type the known website address yourself instead of following an unexpected link.
  4. Secure your email account first. A compromised email account can be used to reset other passwords. Use a unique password, 2FA and review recovery addresses, phone numbers and active sessions.
  5. Check for account activity. Review Ticketek and other high-value accounts for unfamiliar sign-ins, profile changes, new payment methods or password-reset notices.

What does HIBP’s “Retired Breach” status mean?

HIBP currently labels the Ticketek incident a Retired Breach. HIBP uses that status rarely when data is no longer appearing elsewhere online or being traded or redistributed. It does not prove that no historical exposure occurred, that every copy was deleted, or that no one retained a downloaded copy. Security precautions remain appropriate for anyone whose information may be involved.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Bottom line

Ticketek did disclose a May 2024 cloud-platform breach. HIBP’s almost 30 million figure counts rows, while 17.6 million counts unique email addresses; neither is a confirmed number of distinct people. Names, dates of birth and email addresses were identified by TEG as potentially affected, and HIBP additionally reports gender, salutations and hashed passwords. The provider and attacker attribution remain unresolved, so change reused passwords and enable two-factor authentication without relying on speculation about who was responsible.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.