2018 Ticketfly (Eventbrite subsidiary) — site defacement / criminal hack; ~27M accounts in HIBP-style tallies
Data compromised
Account contact fields and related ticketing user metadata per Have I Been Pwned and contemporaneous trade coverage
Technical writeup
Days before June 2018, Eventbrite-owned concert-ticketing subsidiary Ticketfly suffered an intrusion that took services offline, drew ransomware-style public messaging, and—per specialist and breach-researcher databases—exposed tens of millions of user accounts with email, physical address, and phone fields in leaked tables. Eventbrite had acquired Ticketfly in 2017; the incident is commonly catalogued under the Ticketfly brand but materially sits in Eventbrite’s corporate lineage for platform risk history.
Root cause
External criminal compromise of Ticketfly web and data infrastructure (specific CVE chain not uniformly detailed in mainstream summaries)