Data of 412,000 The Town 2025 Ticket Buyers Leaked on Dark Web
A massive dataset containing sensitive Brazilian national IDs is being marketed for bank fraud and identity theft.
Personal information belonging to approximately 412,000 ticket buyers for The Town 2025 music festival in São Paulo has been leaked. The data appeared on a Russian-language data-trading forum, where it is being marketed specifically for financial fraud.
According to Security Affairs, 412,192 records across 34 columns were listed for sale on September 2, 2026. The dataset is heavily concentrated in South America, with Brazil accounting for 61% of the leak (251,557 records), followed by buyers from Argentina, Chile, Colombia, Peru, and Paraguay. The exposed information is comprehensive, including full names, email addresses, phone numbers, neighborhoods, ticket types, and payment details. Most critically, the leak includes CPF numbers, the Brazilian national identity identifier.
The seller is currently asking $10,000 for the full database, or offering smaller batches at $80 per 1,000 records. While the seller claims the data originated from Ticketmaster, analysis suggests a different point of failure. Security researchers noted that the records share identical processing timestamps from October 1, 2025, indicating the data was likely a single batch export shared with a third-party partner, such as a promoter, sponsor, or payment provider, rather than a direct breach of a live database.
The Risk of CPF Exposure
This breach is particularly severe due to the nature of Brazilian ticketing regulations. Platforms in Brazil are required to collect CPF numbers to verify eligibility for legal student discounts. This mandate forces event organizers to hold highly sensitive national identity data, which is frequently exported into less secure formats, such as spreadsheets, for partner reconciliation.
Because CPF numbers cannot be reissued, the exposure creates a permanent vulnerability for the victims. The seller is explicitly marketing the dataset for "Brazilian bank fraud, loan apps and SIM registration." This puts hundreds of thousands of individuals at immediate risk of identity theft, unauthorized loan applications, and SIM-swapping attacks, which can be used to bypass two-factor authentication on banking and social media accounts.
What's Next
Victims are being urged to exercise extreme caution. Ransomnews warned that anyone who purchased tickets to The Town 2025 should treat their CPF as exposed. It remains to be confirmed which specific partner or vendor was responsible for the batch export that led to the leak. Industry observers will be watching to see if this prompts a shift in how sensitive national IDs are handled and shared between event organizers and their third-party affiliates in the region.