Slide 11 of 28
Part 2 · How It WorksSlide 11
Slide 11 · Real Incident
Ticketmaster / Magecart / Inbenta — 40,000 cards stolen through a trusted chatbot script.
February–June 2018. The attack ran undetected for four months. A bank’s fraud detection found it first.
📄 UK ICO · Inbenta blog post · RiskIQ Magecart research · 2018
TIMELINE
Ticketmaster UK — Magecart Group 9 — 2018

Before the attack: Ticketmaster UK integrated Inbenta’s customer support chatbot. The integration loaded a single JavaScript file from Inbenta’s CDN on multiple pages — including the payment and checkout pages. The script ran with full page access. Inbenta later stated that Ticketmaster had specifically asked them to use a JavaScript snippet that was not intended for payment pages and that Inbenta had not been informed it would be used there.

February 2018: Attackers — attributed to Magecart Group 9 by RiskIQ — gained access to Inbenta’s CDN. They modified the JavaScript file served to Ticketmaster to include a card-skimming payload. The modification was subtle: the skimmer was appended to the existing legitimate functionality of the widget, making it harder to detect by casual review.

February–June 2018: Every Ticketmaster UK customer who completed a purchase on an affected page had their card data captured by the skimmer and exfiltrated to an attacker-controlled server. The attack ran silently for approximately four months.

Discovery and aftermath: Monzo Bank, a UK digital bank, identified a pattern of fraudulent card transactions where the common preceding transaction was a Ticketmaster UK purchase. Monzo notified Ticketmaster on June 12, 2018. Ticketmaster disabled Inbenta’s script within hours and confirmed the breach on June 23, 2018. Approximately 9.4 million customers across Europe were notified. The UK ICO fined Ticketmaster £1.25 million in November 2020 for failing to protect customers’ payment card data. Inbenta stated the attack targeted only the customized script used by Ticketmaster and that no other Inbenta client was affected by this specific incident.
← Back Pattern 2: Redirect exploitation →