Security1 distinct publisher2 min readPublished
Ransomnews validated the sample as real The Town 2025 buyer data, down to the 487.50-real student ticket, but every row carries a single export timestamp that points away from Ticketmaster and at an unnamed partner.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The authentication work is the part worth reading, because these checks fail fast on fabrications. Purchase IDs across the sample rise in strict chronological order, which is what an auto-incrementing database key produces [8]. Every CPF in the sample passes Brazil's official check-digit validation, phone area codes track the state listed on each row instead of collapsing to one city, and neighborhood names map onto their stated cities [9]. Full-price rows show 975 reais and discounted rows 487.50, exactly half, matching Brazil's legal student discount [10][20]. Pix and Elo appear as payment methods [10]. Complimentary tickets issued by the festival back office carry only a ticket type and a date, no name and no CPF, the sort of ragged edge a generator does not produce [11].
One field argues the other way. A live dump off a production system carries a spread of processing times; a single value across the whole file describes one batch export, run to reconcile ticket sales with a promoter, sponsor or payment provider [13][22]. Ransomnews says naming Ticketmaster as the breached party goes beyond what the evidence supports [14]. The listing does not settle it either: the claimed breach date is 28 August 2026 [1], roughly eleven months after the export timestamp sitting inside the data [21].
The pricing says who the file is for. Ten thousand dollars for 412,192 rows works out to 2.4 cents a row [18]. The $80-per-1,000 option is 8 cents a record, so a bulk buyer pays about 30 percent of the slice rate [19]. Escrow is on offer [4]. Ransomnews puts the effective figure at around four cents per person once the Brazilian share of the file is counted [17].
Brazilian ticketing collects CPF to enforce discount eligibility [15]. That leaves a live-events company holding a national identity number, a verified phone and a home neighborhood for hundreds of thousands of buyers, inside an industry with nothing like a bank's security requirements [15]. The export that makes that data portable is ordinary reconciliation work with a partner, and it happens constantly [22]. What is absent is a party. No organisation has been confirmed as the holder [5], so the only guidance in circulation is Ransomnews's: buyers of The Town 2025 tickets should treat the CPF as exposed, and a CPF cannot be reissued the way a password can [16].
Ranked by verification strength, evidence, and original report placement.
A seller on a Russian-language data-trading forum listed the file on 2 September under the heading SELLING NEW TICKETMASTER DATABASE, describing a global ticketing platform, Latin America region, an internal ticketing database as the source, and a breach date of 28 August 2026.
Country breakdown is dominated by Brazil at 251,557 records, or 61%, with Argentina at 219, Chile 155, Colombia 144, Peru 123 and Paraguay 72, plus nine more countries not itemised.
The seller asks $10,000 for the full database, or $80 for every 1,000 records, with escrow available.
Ransomnews's analysis confirms the sample is genuine ticket-buyer data from The Town 2025, the Sao Paulo music festival, though who lost the data and how remains unconfirmed.
The data includes names, email addresses, CPF numbers, phone numbers, neighborhoods, ticket types and payment details.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 3, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Orphan-free quote references place the Love Electric sample inside a production database1 distinct publisher
product
A DOJ probe of a16z board seats asks whether venture portfolios are interlocking directorates1 distinct publisher
security
Stolen logins, not a SaaS breach: nine enterprises' Entra directories are now for sale5 distinct publishers
security
A $5.80 deposit buys remote execution on hosts BraZetsu has already catalogued1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Forensically specific, entirely unwitnessed
The technical work is the strong part: check-digit-valid CPFs, area codes that track each row's state, a 487.50-real ticket that is exactly half of 975, comp tickets with the name field empty. Those are hard details a fabricator gets wrong. But all of it is one researcher's reading of one sample, relayed by one outlet, with the 412,192-row total taken from the sales copy and no party — platform, promoter, regulator — on the record about anything.
One listing, no buyer on the record
What exists in the world is a priced advertisement with escrow on offer and a validated sample. There is no confirmed sale, no victim notification, no reported downstream fraud tied to these CPFs, and no named partner acknowledging the export. The data's reach is real but its circulation is, so far, one forum thread.
The reporting talks quieter than the file
The loud claim in this story belongs to the criminal, not the journalist. A seller stamped Ticketmaster's name on the header and dated the breach 28 August 2026, eleven months after the data's own timestamp; the reporting takes the name out of the finding, points at an unnamed partner instead, and labels the fraud pitch as sales copy. If anything the restraint undersells the confirmed part — a quarter of a million real, permanent Brazilian identity numbers priced at four cents each.
A brand name is part of the asking price
Attaching "Ticketmaster" to a Latin American festival extract is worth money to whoever wrote that header, and the whole framing of this story originates in a document written to sell something. On the other side, the validation comes from a threat-intelligence outlet whose visibility rises with the significance of what it validates — which cuts both ways here, since it is also the party insisting the platform not be blamed. No one with a reason to deny anything was asked.
Confident about the data, blank about the culprit
Two very different confidence levels sit in this story. That the records are real The Town 2025 purchases is well argued and internally coherent. Who lost them is genuinely unresolved: the timestamp rules the seller's story out without ruling anyone else in, and the partner theory names no partner. Read the forensics as solid and the attribution as an open question.