Before the attack: Ticketmaster UK integrated Inbenta’s customer support chatbot. The integration loaded a single JavaScript file from Inbenta’s CDN on multiple pages — including the payment and checkout pages. The script ran with full page access. Inbenta later stated that Ticketmaster had specifically asked them to use a JavaScript snippet that was not intended for payment pages and that Inbenta had not been informed it would be used there.
February 2018: Attackers — attributed to Magecart Group 9 by RiskIQ — gained access to Inbenta’s CDN. They modified the JavaScript file served to Ticketmaster to include a card-skimming payload. The modification was subtle: the skimmer was appended to the existing legitimate functionality of the widget, making it harder to detect by casual review.
February–June 2018: Every Ticketmaster UK customer who completed a purchase on an affected page had their card data captured by the skimmer and exfiltrated to an attacker-controlled server. The attack ran silently for approximately four months.