Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Adele Tickets Site Security Breach
News & Analysis

Adele Tickets Site Security Breach

ISBuzz TeamBy ISBuzz TeamDecember 4, 20155 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Adele Tickets Site Security Breach
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Fans buying tickets for Adele’s tour have told the BBC they were shown the address and credit card details of customers other than themselves. Advance tickets were made available to members of Adele.com this morning.

Ticketing company Songkick said due to the “extreme load” on the site some customers could see others’ account details. It apologised for any “alarm”. Security experts from ESET, Lieberman Software and Veracode have the following comments on it.

[su_note note_color=”#ffffcc” text_color=”#00000″]Jonathan Sander, VP of Product Strategy at Lieberman Software :

What can go wrong even without hackers involved? What should companies do to prevent details being released in such glitches?

“Issues like the one Songkick experienced are a classic example of why quality assurance testing is so important. The Songkick issue will be lumped in with data breaches and privacy, but I’m betting that’s not where it belongs. It’s likely simply some coding errors which have had a privacy impact. This is the kind of thing that only extensive, detailed test plans that are well executed will uncover.”

Is this just providing cybercriminals details on a plate and can they exploit this glitch further?

“Without understanding the exact nature of the flaw, it’s hard to say if bad guys could use it to gain some advantage. One thing that sure is that given the thorough, automated approaches that today’s attackers use, if it was something that could be exploited it may already have been.”

What advice should be given to companies selling online?

“The advice for anyone running a website is the same “eat right and exercise” style advice security folks have been giving for decades. There are well known things people can do to protect their website assets, and most of it is simply good hygiene in the development and operations processes. Organizations looking for a good, specific, prescriptive guide to this security would do well to go to the OWASP top ten list, where they maintain the most urgent threats to website security.”

How important is website security?

“As more business is done on websites and they get stuffed full of juicy bits of data used to fuel those transactions, websites will become a more serious target. Websites have always been a target because they were out in the open and easy to attack, and they have suffered from many well-known, easily exploited flaws, e.g. cross site scripting and SQL injection. In the past, though, the goal of attacking a website was often similar to the goal of graffiti. Online shopping, online banking, online everything important in our lives have changed the stakes of the game.[/su_note]

[su_note note_color=”#ffffcc” text_color=”#00000″]Paul Farrington, Senior Solution Architect at Veracode :

Adele has been away from the public eye since winning the Oscar for Skyfall in March 2013. She’s returned with a number one single and album as well. Tickets went on sale for her first tour in four years, and the predictable happened… there are many reports of the site experiencing severe demand, leading to loss of service. As with any phenomenon, it’s hard to plan being so popular. A more worrying disclosure is that fans report seeing other fans personal details when attempting to buy tickets. This is a little like a patient going into a doctor’s waiting room and being shown another patient’s details. Regardless of how busy a service gets, this type of unauthorised information disclosure is a security design fault rather than a problem with the number of servers that should have been ordered to host the site.

If a site can be made to disclose sensitive data just by experiencing spikes in load, this is a failure of security design and process. It’s very likely that a combination of code review and Automated Static Analysis would have uncovered this problem before Adele arrived back at the top of the charts. Testing automation can help assess sites in minutes, giving developers peace of mind before their software encounters the public. Adversaries will be watching for other sites that use the same underlying ticketing technology to see if this discovery facilitates further data leakage.[/su_note]

[su_note note_color=”#ffffcc” text_color=”#00000″]Mark James, Security Specialist at IT Security Firm ESET :

“With so many headlines of another breach or more of your important data being exposed to the dark side of the internet it’s very difficult for the average public to determine what they should and should not be worried about.

This latest glitch to hit the headlines is another example of poor security or badly configured software, not necessarily a breach as such but the perception from the public point of view is almost as bad. The server under heavy load was displaying other people’s shopping cart and checkout options; this should never (ever) happen. It should be technically impossible for this happen but when servers are under very heavy loads, processes used to speed up the average browsing session could be responsible for serving up duplicated or incorrect data. The public sees private information from someone else and immediately thinks the worst. The chances of someone actually using this information for ill gains is quite slim but even so it’s an indication that something is very wrong somewhere.

Companies are under constant pressure to protect our data and show the public that they value the said data. This latest incident will do nothing to put our minds to rest, will it stop people ordering tickets to see a blockbusting megastar sing, probably not but you should take measures to protect yourself where possible. Use a separate credit card for internet purchases, one that is easily cancelled if compromised, keep your everyday finances away from it and review your financial statements as regularly as you can.”[/su_note]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Roblox Under Fire: Lawsuit Alleges Secret Data Tracking of Kids

May 13, 20254 Mins Read

Understanding Cloud Access Security Brokers (CASB)

March 28, 202410 Mins Read

Decoding Cloud Security Posture Management (CSPM)

March 28, 202411 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}