Multiple class-action complaints followed Ticketmaster’s 2024 data-security incident, but the often-repeated figure of 560 million affected customers is an alleged hacker and plaintiff figure—not a number Ticketmaster has publicly confirmed. Ticketmaster says an unauthorized user accessed an isolated third-party cloud database containing limited information for some customers who bought tickets to events in the United States, Canada or Mexico.
The federal cases are coordinated in In re: Snowflake, Inc. Data Security Breach Litigation, MDL No. 3126, before Judge Brian Morris in the U.S. District Court for the District of Montana. The publicly identified court materials do not show a final Ticketmaster-specific settlement or an approved payout.
What happened in the Ticketmaster breach?
Live Nation said it identified unauthorized activity on May 20, 2024, in a third-party cloud database environment used primarily by Ticketmaster. Reports soon circulated that stolen Ticketmaster data was being offered for sale online. Ticketmaster’s customer notice says the database was isolated and that it saw no further unauthorized activity there after beginning its investigation.
Ticketmaster does not describe this as a compromise of its entire customer-account system. Its notice says customer accounts were not affected and that customers generally did not need to reset their Ticketmaster passwords because of this incident. Read the company’s notice at Ticketmaster’s incident-information page.
Recommended Free Tools
#1 Best Overall
How many people were affected?
The breach’s scale remains disputed:
| Figure | What it represents |
|---|---|
| Up to 560 million customers | A number attributed to an alleged ShinyHunters data listing and repeated in plaintiffs’ complaints; Ticketmaster has not publicly confirmed it. |
| Approximately 1.3 terabytes | The volume of data the Leal complaint says hackers claimed to possess. |
| Some North American customers | Ticketmaster’s narrower description of the potentially affected population: customers who bought tickets to events in the United States, Canada and/or Mexico. |
Using Ticketmaster does not prove that your information was in the affected database. Ticketmaster says it will contact customers it believes may have been affected.
What information may have been exposed?
Ticketmaster’s stated categories
Ticketmaster says the potentially involved information may include email addresses, phone numbers, encrypted credit-card information and other personal information supplied by customers. “Encrypted” does not mean that complete, usable card numbers were publicly exposed.
What plaintiffs allege
The complaints describe a broader alleged inventory, including names, addresses, email addresses, phone numbers, ticket-sales and event details, order information, and partial payment-card data such as cardholder names, last four digits and expiration dates. Those are allegations in a pleading, not a complete company-confirmed list.
Who sued Ticketmaster and Live Nation?
Several proposed class actions were filed in different federal courts rather than one original nationwide case. The transferred matters include cases styled Leal v. Ticketmaster, Live Nation and Snowflake, Miller v. Ticketmaster and Live Nation, Curry v. Ticketmaster, Ryan v. Ticketmaster, Getman v. Ticketmaster and Caballero v. Live Nation, among other related actions. The Judicial Panel on Multidistrict Litigation transferred the federal cases for coordinated pretrial proceedings. The transfer order lists the Ticketmaster- and Live Nation-related actions.
Depending on the complaint, defendants include Ticketmaster LLC, Live Nation Entertainment Inc. and Snowflake Inc., the cloud-data provider. The disputed issue includes how responsibility was divided between the customer-facing companies and the provider’s security controls.
What do the lawsuits allege?
Complaints generally claim that the defendants:
- failed to use reasonable safeguards for personally identifiable information;
- stored sensitive information in an inadequately protected cloud environment;
- failed to detect or stop unauthorized access promptly;
- delayed notifying customers; and
- caused losses, mitigation expenses, time costs, emotional distress and an increased risk of identity theft.
These allegations have not been established by a judgment. Filing a class-action complaint does not certify a class, prove liability or determine damages.
Where does the case stand?
The federal litigation is coordinated in MDL No. 3126, titled In re: Snowflake, Inc. Data Security Breach Litigation, before Judge Brian Morris. An MDL groups related cases for discovery, motions and other pretrial work; it is not automatically a nationwide class, a final ruling or a payment program.
The District of Montana’s MDL page lists case-management activity and outcomes involving some other Snowflake customers. The publicly identified material does not list a final Ticketmaster/Live Nation breach settlement, an approved Ticketmaster class or an open claims process.
Is there a Ticketmaster breach settlement or payout?
Do not assume you are entitled to money because a website, social-media post or email calls the matter a “class action.” A complaint may request damages without creating a fund or establishing eligibility. A legitimate settlement notice should identify the court, case name, docket number, class definition, deadlines and claims administrator. It should not demand an upfront fee, cryptocurrency, remote-access software or your full password.
This breach litigation is also separate from Live Nation or Ticketmaster antitrust, ticket-fee, pricing and securities cases. Those matters can have different plaintiffs, legal theories, class definitions and deadlines.
What Ticketmaster offered potentially affected customers
Ticketmaster says customers it believes may have been affected would receive notice by email or first-class mail. It also says relevant customers were offered 12 months of free credit or identity monitoring through a provider. Use contact details from a verified Ticketmaster channel rather than clicking an unsolicited message.
What customers should do now
- Check for a direct notice. A news report or an account history alone does not establish that your data was included. Review messages and postal mail sent through verified Ticketmaster channels.
- Monitor bank and card accounts. Look for unfamiliar transactions and contact the issuer using the number on your card or an official statement, not a number in a suspicious message.
- Expect phishing. Treat urgent “settlement” claims, attachments, unusual links and requests for passwords, Social Security numbers or payment details as warning signs.
- Change reused passwords. Ticketmaster says its accounts were not affected by this incident, but a password reused on another service remains a separate risk. Change it anywhere else it was used and use a unique password.
- Consider a credit freeze. A freeze is free through the three major U.S. credit bureaus and restricts access to your credit file for new accounts. Monitoring can alert you to suspicious activity but does not prevent every form of fraud.
- Keep records. Save breach notices, suspicious messages, account statements and documented expenses. Records may help if a future court-approved process sets eligibility rules, but keeping receipts does not guarantee compensation.
Questions customers commonly ask
Was my Ticketmaster account hacked?
Ticketmaster says customer accounts were not affected by this incident. That statement concerns the account system; it does not mean every person who used Ticketmaster was included in, or excluded from, the separate cloud database.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Best Value
Were full credit-card numbers exposed?
Ticketmaster says encrypted credit-card information may have been involved. Plaintiffs allege partial card details, including last four digits and expiration dates. The available sources do not establish that complete plaintext card numbers were exposed.
Do I have to reset my Ticketmaster password?
Ticketmaster says customers generally did not need to reset their passwords because of this incident. Change any password reused on other services, and change your Ticketmaster password if you independently suspect account misuse.
Will affected customers receive money?
No Ticketmaster-specific payment entitlement is established in the identified court materials. Wait for a court order or official claims-administrator notice before submitting information.
How can I check an alleged settlement email?
Verify the case and docket through the court’s MDL page and compare the message with Ticketmaster’s official notice. Do not pay an upfront fee or disclose a password, banking credentials or full payment-card details.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsQuick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




