Central Tickets confirms data breach which exposed personal user information

Central Tickets Confirms Data Breach Exposing Personal User Information

Central Tickets, a London-based theatre ticketing platform, has experienced a data breach that exposed the personal information of its users. The company confirmed that the breach occurred on July 1 but was only discovered in September after being alerted by the Metropolitan Police about activity related to the incident on the dark web.

The cyber attack targeted a staging database used for testing purposes, separate from the main website and app, and was breached by a threat actor. Central Tickets clarified that earlier reports overstated the number of affected users, and the breach specifically exposed names, email addresses, mobile numbers, and hashed passwords of some users.

Chief executive Lee McIntosh issued an apology to users for any distress caused by the breach and confirmed that the company promptly reported the incident to the Information Commissioner’s Office (ICO) upon learning about it. However, the exact number of affected users was not disclosed.

In response to the breach, Central Tickets has taken measures to enhance cybersecurity, including conducting an investigation with an external cybersecurity team and implementing safeguards like a forced password reset for all members and an audit of its IT infrastructure. The company warned affected users to be cautious of potential phishing attempts and advised them to monitor their accounts closely for any suspicious activity.

McIntosh reassured customers of Central Tickets’ commitment to preventing future breaches, acknowledging the growing challenge of cybersecurity for businesses and highlighting ongoing investments in proactive defences to safeguard user data. Authorities such as the Metropolitan Police, ICO, and the National Cyber Security Centre have been contacted for further comment on the incident.

Leave a Reply

Your email address will not be published. Required fields are marked *