ICO fines Ticketmaster for GDPR breach

UK – The Information Commissioner’s Office (ICO) has fined events firm Ticketmaster UK £1.25m for failing to keep customers’ personal data secure. 

Privacy abstract image

The ICO found that Ticketmaster had breached the General Data Protection Regulation (GDPR) by failing to put appropriate security measures in place to prevent a cyber-attack on a chat bot on the online payment page of the company’s website in 2018.

The resulting data breach included names, payment card numbers, expiry dates and card verification value (CVV) number, and potentially affected 9.4 million customers, including 1.5 million people in the UK.

The breach led to frauds on 60,000 payment cards belonging to Barclays Bank customers. Monzo Bank also replaced 6,000 cards due to suspected fraudulent use.

The cyber-attack began in February 2018, but the fine issued related to the period between the introduction of the GDPR on 25th May 2018 and the removal of the chat bot on 23rd June 2018.

The issue was raised with Ticketmaster by several banks, said the ICO, but the company took nine weeks in total to identify the issue.

The ICO found that Ticketmaster had failed to properly assess the risks of using the chat bot on its payment page, and had not identified and implemented appropriate security measures to reduced those risks.

The company also failed to identify the source of the fraudulent activity in a timely manner, according to the ICO.

James Dipple-Johnstone, deputy commissioner of the ICO, said: “When customers handed over their personal details, they expected Ticketmaster to look after them. But they did not.

“Ticketmaster should have done more to reduce the risk of a cyber-attack. Its failure to do so meant that millions of people in the UK and Europe were exposed to potential fraud.”

A spokesperson for Ticketmaster said the company “takes fans’ data privacy and trust very seriously” and that the company planned to appeal the ICO’s ruling.  

We hope you enjoyed this article.
Research Live is published by MRS.

The Market Research Society (MRS) exists to promote and protect the research sector, showcasing how research delivers impact for businesses and government.

Members of MRS enjoy many benefits including tailoured policy guidance, discounts on training and conferences, and access to member-only content.

For example, there's an archive of winning case studies from over a decade of MRS Awards.

Find out more about the benefits of joining MRS here.

0 Comments


Display name

Email

Join the discussion

Newsletter
Stay connected with the latest insights and trends...
Sign Up
Latest From MRS

Our latest training courses

Our new 2025 training programme is now launched as part of the development offered within the MRS Global Insight Academy

See all training

Specialist conferences

Our one-day conferences cover topics including CX and UX, Semiotics, B2B, Finance, AI and Leaders' Forums.

See all conferences

MRS reports on AI

MRS has published a three-part series on how generative AI is impacting the research sector, including synthetic respondents and challenges to adoption.

See the reports

Progress faster...
with MRS 
membership

Mentoring

CPD/recognition

Webinars

Codeline

Discounts