Tixel Ticket Platform Confirms Data Breach via Metabase Zero-Day
User email addresses and mobile numbers were exposed after a vulnerability hit the platform's third-party analytics provider.
Ticket resale platform Tixel has confirmed a data breach that exposed sensitive customer contact information. The incident, which originated through a third-party service, highlights the ongoing security risks associated with integrated cloud analytics tools.
According to reports from 7NEWS, the breach occurred on August 3 and targeted Tixel's use of Metabase, a third-party analytics provider. The compromise was triggered by a zero-day vulnerability within Metabase's cloud services. Reports indicate that the exploitation of this flaw was reportedly aided by Large Language Model (LLM) capabilities, marking a sophisticated intersection of AI and cyberattacks.
Scope of the Leak
The stolen data specifically included user email addresses and mobile phone numbers. However, Tixel and investigators have confirmed that more sensitive financial and security data remained secure. Passwords, credit card details, payment information, and individual purchase histories were not impacted by the breach.
Industry Context
Tixel operates as a Melbourne-based marketplace designed to facilitate the secure resale of event tickets while combating fraud and scalping. Because the platform handles high volumes of personal identification and financial transactions, it is a high-value target for bad actors. This incident underscores a growing trend in the ticketing and e-commerce industries where the primary point of failure is not the company's own infrastructure, but a trusted third-party vendor.
Why It Matters
While the absence of leaked credit card data mitigates immediate financial loss, the exposure of emails and mobile numbers creates significant secondary risks. Users are now more susceptible to highly targeted phishing campaigns and SMS-based social engineering attacks. In these scenarios, attackers often use leaked contact details to impersonate official services, tricking users into revealing passwords or payment details through fraudulent links.
What's Next
Industry observers are now watching how Metabase addresses the zero-day vulnerability and whether other companies using the same cloud services were similarly affected. Tixel has not yet detailed the full scale of the user base impacted, and users are encouraged to remain vigilant against unsolicited communications claiming to be from the platform.