{"id":24578,"date":"2024-05-29T05:10:07","date_gmt":"2024-05-29T13:10:07","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2024\/05\/29\/news-18308\/"},"modified":"2024-05-29T05:10:07","modified_gmt":"2024-05-29T13:10:07","slug":"news-18308","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2024\/05\/29\/news-18308\/","title":{"rendered":"Data leak site BreachForums is back, boasting Live Nation\/Ticketmaster user data. But is it a trap?"},"content":{"rendered":"\n<p>Notorious data leak site BreachForums appears to be back online after it <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2024\/05\/notorious-data-leak-site-breachforums-seized-by-law-enforcement\">was seized by law enforcement<\/a> a few weeks ago.<\/p>\n<p>At least one of BreachForums domains and its dark web site are live again. However, questions have been raised over whether it is a genuine attempt to revive the forums once again or set up as a lure by law enforcement to entrap more data dealers and cybercriminals.<\/p>\n<p>The administrator of the new forum posts under the handle ShinyHunters, which is a <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2024\/03\/the-att-breach-what-you-need-to-know\">name associated with the AT&amp;T breach and others,<\/a> and believed to be the main administrator of the previous BreachForums.<\/p>\n<p>Yesterday, ShinyHunters posted a new dataset for sale that allegedly stems from Live Nation\/Ticketmaster.<\/p>\n<figure class=\"wp-block-image aligncenter size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"817\" height=\"588\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/05\/Administrator_post.jpg\" alt=\"Post on BreachForums by administrator ShinyHunters\" class=\"wp-image-111139\" \/><figcaption class=\"wp-element-caption\"><em>Post by ShinyHunters to sell the Live Nation Ticketmaster data set<\/em><\/figcaption><\/figure>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cLive Nation \/ Ticketmaster<\/p>\n<p>Data includes<\/p>\n<p>560 million customer full details (name, address, email, phone)<\/p>\n<p>Ticket sales, event information, order details<\/p>\n<p>CC detail \u2013 customer last 4 of card, expiration date<\/p>\n<p>Customer fraud details<\/p>\n<p>Much more<\/p>\n<p>Price is $500k USD. One time sale.\u201d<\/p>\n<\/blockquote>\n<p>But, an avatar and a handle are easily copied, and there are a few things that raised our spidey-senses that something is up.<\/p>\n<p>First, the data set was offered for sale on another dark web forum by a user going by SpidermanData with the exact same text.<\/p>\n<figure class=\"wp-block-image aligncenter size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"532\" height=\"424\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/05\/SpidermanData.jpg\" alt=\"Post by SpidermanData on another forum selling the same data set\" class=\"wp-image-111140\" \/><figcaption class=\"wp-element-caption\"><em>SpidermanData offering the same data set on another forum<\/em><\/figcaption><\/figure>\n<p>Second, this data set seems way too big for its nature. Live Nation and Ticketmaster are big enough to be <a href=\"https:\/\/apnews.com\/article\/justice-department-live-nation-ticketmaster-antitrust-lawsuit-df9b552d127e1494db13e3cd625787a8\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">considered a monopolist<\/a>, but 560 million users seems like a stretch.<\/p>\n<p>After looking at the shared evidence, security researcher CyberKnow <a href=\"https:\/\/x.com\/cyberknow20\/status\/1795667145235595332?s=46\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">tweeted<\/a>:<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cWhile there is some new data in the shared evidence there is also old customer information, making it possibly this is a series of data jammed together.\u201d<\/p>\n<\/blockquote>\n<p>Third, a new feature is that visitors need to register before they can see any content. Why would the administrators change that?<\/p>\n<p>And, last but not least, would the FBI let the cybercriminals regain control over the domains that easily? That would be <a href=\"https:\/\/www.hackread.com\/breach-forums-return-clearnet-dark-web-fbi-seizure\/\">quite embarrassing<\/a>.<\/p>\n<p>So, we dare conclude that this dataset&#8217;s goal is to generate some attention and act as a lure to let old forum users know that BreachForums is alive and kicking. But who is running the show, is the question that we hope to answer soon.<\/p>\n<p>Stay tuned for updates on this developing story.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-protecting-yourself-from-a-data-breach\">Protecting yourself from a data breach<\/h2>\n<p>There are some actions you can take if you are, or suspect you may have been, the <a href=\"https:\/\/www.malwarebytes.com\/blog\/personal\/2023\/09\/involved-in-a-data-breach-heres-what-you-need-to-know\">victim of a data breach<\/a>.<\/p>\n<ul>\n<li><strong>Check the vendor&#8217;s advice.<\/strong> Every breach is different, so check with the vendor to find out what&#8217;s happened, and follow any specific advice they offer.<\/li>\n<li><strong>Change your password.<\/strong> You can make a stolen password useless to thieves by changing it. Choose a&nbsp;<a rel=\"noreferrer noopener\" href=\"https:\/\/www.malwarebytes.com\/computer\/how-to-create-a-strong-password\" target=\"_blank\">strong password<\/a>&nbsp;that you don&#8217;t use for anything else. Better yet, let a&nbsp;<a rel=\"noreferrer noopener\" href=\"https:\/\/www.malwarebytes.com\/what-is-password-manager\" target=\"_blank\">password manager<\/a>&nbsp;choose one for you.<\/li>\n<li><strong>Enable two-factor authentication (2FA).<\/strong> If you can, use a FIDO2-compliant hardware key, laptop or phone as your second factor. Some forms of&nbsp;<a rel=\"noreferrer noopener\" href=\"https:\/\/www.malwarebytes.com\/glossary\/multi-factor-authentication-mfa\" target=\"_blank\">two-factor authentication (2FA)<\/a>&nbsp;can be phished just as easily as a password. 2FA that relies on a FIDO2 device can\u2019t be phished.<\/li>\n<li><strong>Watch out for fake vendors.<\/strong> The thieves may contact you posing as the vendor. Check the vendor website to see if they are contacting victims, and verify any contacts using a different communication channel.<\/li>\n<li><strong>Take your time.<\/strong> Phishing attacks often impersonate people or brands you know, and use themes that require urgent attention, such as missed deliveries, account suspensions, and security alerts.<\/li>\n<li><strong>Set up identity monitoring.<\/strong> <a href=\"https:\/\/www.malwarebytes.com\/identity-theft-protection\">Identity monitoring<\/a> alerts you if your personal information is found being traded illegally online, and helps you recover after.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\" id=\"h-check-if-your-data-has-been-breached\">Check if your data has been breached<\/h2>\n<p>Our Digital Footprint portal allows you to quickly and easily check if your personal information has been exposed online. Just enter your email address (it\u2019s best to submit the one you most frequently use) to our\u00a0<a href=\"https:\/\/www.malwarebytes.com\/digital-footprint\">free Digital Footprint scan<\/a>\u00a0and we\u2019ll give you a report.<\/p>\n<div class=\"wp-block-malware-bytes-button mb-button\" id=\"mb-button-7ba16f0b-04e8-4679-9512-2f21a0971dcf\">\n<div class=\"mb-button__row u-justify-content-center\">\n<div class=\"mb-button__item mb-button-item-0\">\n<p class=\"btn-main\"><a href=\"https:\/\/www.malwarebytes.com\/digital-footprint?utm_source=blog&amp;utm_medium=social&amp;utm_campaign=b2c_pro_acq_fy25dfplaunch_171269600960&amp;utm_content=V1\"><\/a><a href=\"https:\/\/www.malwarebytes.com\/digital-footprint\">SCAN NOW<\/a><\/p>\n<\/div>\n<\/div>\n<\/div>\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\" \/>\n<p><strong>We don&#8217;t just report on threats &#8211; we help safeguard your entire digital identit<\/strong>y<\/p>\n<p>Cybersecurity risks should never spread beyond a headline. Protect your\u2014and your family&#8217;s\u2014personal information by using <a href=\"https:\/\/www.malwarebytes.com\/identity-theft-protection\">identity protection<\/a>.<\/p>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2024\/05\/data-leak-site-breachforums-is-back-boasting-live-nation-ticketmaster-user-data-but-is-it-a-trap\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> The notorious BreachForums seem to have returned, but the question is: who&#8217;s pulling the strings? <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[28039,31476,32,27267,31477,18888],"class_list":["post-24578","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-breachforums","tag-live-nation","tag-news","tag-shinyhunters","tag-spidermandata","tag-ticketmaster"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24578","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=24578"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24578\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=24578"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=24578"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=24578"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}