Metabase: Second-hand ticket marketplace Tixel confirms customer information stolen in data breach

Metabase: Second-hand ticket marketplace Tixel confirms customer information stolen in data breach

Tixel Customers Affected by Data Breach via Third-Party Analytics Provider

A data breach at Melbourne-based second-hand ticket marketplace Tixel has exposed customers’ email addresses and mobile numbers after an unauthorized party accessed a third-party analytics provider, Metabase.

Tixel notified users via email on Friday night, confirming that while sensitive data including passwords, credit card details, payment information, and purchase history remained secure, affected individuals should monitor for spam and phishing attempts. The company emphasized it would never request passwords or payment details via email or text.

The breach originated from a zero-day vulnerability in Metabase’s cloud services, exploited on August 3. Metabase revealed in a blog post that the attack likely leveraged AI-driven tools, specifically a Large Language Model (LLM), to execute a complex, multi-layered intrusion. The company stated that only under 3% of its customers were impacted and has since released a security update to fortify its systems.

Both Tixel and Metabase have been contacted for additional details.

Source: https://7news.com.au/news/second-hand-ticket-marketplace-tixel-confirms-customer-information-stolen-in-data-breach-c-22794366

Metabase cybersecurity rating report: https://www.rankiteo.com/company/metabase

"id": "MET1787984684",
"linkid": "metabase",
"type": "Vulnerability",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Unknown (subset of Tixel’s '
                                              'customer base)',
                        'industry': 'E-commerce, Ticketing',
                        'location': 'Melbourne, Australia',
                        'name': 'Tixel',
                        'type': 'Second-hand ticket marketplace'},
                       {'customers_affected': 'Under 3% of Metabase’s '
                                              'customers',
                        'industry': 'Software, Data Analytics',
                        'name': 'Metabase',
                        'type': 'Analytics provider'}],
 'attack_vector': 'Third-Party Vendor Compromise',
 'customer_advisories': 'Monitor for spam and phishing attempts; avoid sharing '
                        'passwords or payment details via email/text',
 'data_breach': {'personally_identifiable_information': 'Email addresses, '
                                                        'mobile numbers',
                 'sensitivity_of_data': 'Low to moderate (no financial or '
                                        'password data exposed)',
                 'type_of_data_compromised': ['Email addresses',
                                              'Mobile numbers']},
 'date_detected': '2024-08-03',
 'description': 'A data breach at Melbourne-based second-hand ticket '
                'marketplace Tixel has exposed customers’ email addresses and '
                'mobile numbers after an unauthorized party accessed a '
                'third-party analytics provider, Metabase. Tixel confirmed '
                'that sensitive data including passwords, credit card details, '
                'payment information, and purchase history remained secure but '
                'warned affected individuals to monitor for spam and phishing '
                'attempts.',
 'impact': {'brand_reputation_impact': 'Potential impact due to data exposure',
            'data_compromised': 'Email addresses, mobile numbers',
            'identity_theft_risk': 'Monitoring for spam and phishing attempts '
                                   'advised',
            'payment_information_risk': 'None (payment details secure)',
            'systems_affected': 'Metabase (third-party analytics provider)'},
 'initial_access_broker': {'entry_point': 'Zero-day vulnerability in '
                                          'Metabase’s cloud services'},
 'investigation_status': 'Ongoing',
 'post_incident_analysis': {'corrective_actions': 'Security update released by '
                                                  'Metabase',
                            'root_causes': 'AI-driven tools (Large Language '
                                           'Model) used to exploit zero-day '
                                           'vulnerability'},
 'references': [{'source': 'Metabase Blog Post'}],
 'response': {'communication_strategy': 'Email notification to affected users',
              'containment_measures': 'Security update released by Metabase'},
 'title': 'Tixel Customers Affected by Data Breach via Third-Party Analytics '
          'Provider',
 'type': 'Data Breach',
 'vulnerability_exploited': 'Zero-day vulnerability in Metabase’s cloud '
                            'services'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.