Slide 1 of 28
Part 1 · What Is It?Slide 1
Slide 1 · The Breach That Defined the Category
Ticketmaster trusted a third-party script. That script stole 40,000 payment cards.
Magecart / Inbenta — 2018. The attack didn’t target Ticketmaster’s API. It targeted a vendor Ticketmaster trusted.
📄 UK ICO · Inbenta Technologies · Magecart Group 9 research · 2018
THE INCIDENT
Ticketmaster UK — Magecart via Inbenta CDN — February–June 2018

Ticketmaster UK integrated Inbenta’s third-party customer support chatbot widget on their payment and checkout pages. The integration worked like most third-party JavaScript: Ticketmaster’s pages loaded a script tag pointing to a file on Inbenta’s CDN — <script src="https://inbenta.ticketmaster.net/...">. That script ran with full access to the page’s DOM, including any payment card fields the user was typing into.

Attackers — later attributed to Magecart Group 9 — compromised Inbenta’s CDN and modified the JavaScript file that Ticketmaster loaded. The modified script added a card-skimming payload that intercepted payment form submissions and exfiltrated card numbers, expiry dates, CVV codes, and billing addresses to an attacker-controlled server. The payload ran on Ticketmaster UK’s payment pages from February to June 2018 — four months.

Discovery and impact: A bank flagged fraudulent card transactions where the common purchase point was Ticketmaster UK. Ticketmaster was notified in June 2018 and took Inbenta’s script offline within hours. By then, approximately 40,000 UK customers and an unknown number of international customers had their payment card data stolen. Ticketmaster notified 9.4 million affected customers across Europe. The UK ICO fined Ticketmaster £1.25 million for failing to put appropriate security measures in place to prevent the attack. Inbenta stated that the compromised JavaScript had been specifically customized for Ticketmaster and was not used by any other Inbenta client.
The API10 lesson

Ticketmaster’s own payment processing was secure. Their API was not vulnerable. But they loaded a third-party script on their payment page and trusted that script implicitly — with no integrity verification, no monitoring for changes, and no sandboxing. The attacker didn’t break into Ticketmaster. They broke into a vendor Ticketmaster trusted, and used that trust as their entry point.

← All modules What is API10? →