{"id":2399,"date":"2025-03-06T10:10:00","date_gmt":"2025-03-06T10:10:00","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/03\/06\/two-hackers-arrested-for-stealing-taylor-swift-era-concert-tickets-worth-600k\/"},"modified":"2025-03-06T10:10:00","modified_gmt":"2025-03-06T10:10:00","slug":"two-hackers-arrested-for-stealing-taylor-swift-era-concert-tickets-worth-600k","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/03\/06\/two-hackers-arrested-for-stealing-taylor-swift-era-concert-tickets-worth-600k\/","title":{"rendered":"Two Hackers Arrested for Stealing Taylor Swift Era Concert Tickets Worth $600k"},"content":{"rendered":"<p>    Two Hackers Arrested for Stealing Taylor Swift Era Concert Tickets Worth $600k<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Two individuals were arrested this week in a sophisticated cybercrime operation targeting high-demand events. They were accused of orchestrating a $600,000 ticket theft scheme involving Taylor Swift\u2019s Eras Tour and other major concerts.\u00a0<\/p>\n<p>Queens District Attorney Melinda Katz revealed that Tyrone Rose, 34, and Shamara P. Simmons, 29, exploited security flaws in an offshore third-party ticket vendor\u2019s systems to intercept and resell over 900 digital tickets through StubHub.\u00a0<\/p>\n<p>The operation, which ran for nearly a year, leveraged <a href=\"https:\/\/cybersecuritynews.com\/anyrun-safebrowsing-extension\/\" target=\"_blank\" rel=\"noreferrer noopener\">URL session<\/a> hijacking and automated credential stuffing scripts to bypass vendor protections, marking one of the most technically complex ticket fraud cases in recent memory.<\/p>\n<p>As stated by Deadline, the hackers allegedly targeted a Jamaica-based contractor responsible for managing ticket transfers for StubHub.\u00a0<\/p>\n<h2 class=\"wp-block-heading\"><strong>Technical Exploitation of Vendor Systems<\/strong><\/h2>\n<p>Forensic analysts identified that the defendants used Python-based scraping tools to exploit insecure <a href=\"https:\/\/cybersecuritynews.com\/1025-explosion-in-api-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">API endpoints<\/a> within the vendor\u2019s platform. <\/p>\n<p>One script utilized the requests library to systematically harvest valid ticket URLs.<\/p>\n<p>The script allegedly extracted direct ticket URLs by impersonating authorized users through compromised OAuth tokens.\u00a0<\/p>\n<p>The stolen links were then transmitted to co-conspirators in Queens, who used Selenium automation to mass-download PDF tickets and list them on StubHub under fraudulent accounts. Security experts noted the operation combined social engineering and infrastructure vulnerabilities.<\/p>\n<p>The offshore vendor\u2019s lack of IP rate-limiting and multi-factor authentication (MFA) allowed the hackers to brute-force employee credentials.\u00a0<\/p>\n<p>Once inside, they deployed <a href=\"https:\/\/cybersecuritynews.com\/moveit-sqli-flaws\/\" target=\"_blank\" rel=\"noreferrer noopener\">SQL injection payloads<\/a> to extract customer transaction records. This data enabled targeted attacks on high-value tickets, with resale prices averaging 300% above face value for Eras Tour seats.<\/p>\n<p>The DA\u2019s cybercrime unit traced $612,000 in illicit profits through cryptocurrency wallets linked to Rose\u2019s Coinbase account.<\/p>\n<p>Rose and Simmons face 15 felony counts, including first-degree computer trespass (NY Penal Law \u00a7 156.10) and grand larceny via unauthorized access (\u00a7 155.30).\u00a0<\/p>\n<p>Prosecutors emphasized the defendants\u2019 use of offshore proxy servers and encrypted <a href=\"https:\/\/cybersecuritynews.com\/new-go-based-malware-exploits-telegram-and-use-it-as-c2-channel\/\" target=\"_blank\" rel=\"noreferrer noopener\">Telegram channels<\/a> to obscure their activities. StubHub has since mandated JWT token validation and reCAPTCHA v3 implementation for third-party integrations.\u00a0<\/p>\n<p>The Queens DA\u2019s Economic Crimes Bureau is collaborating with INTERPOL to identify additional conspirators in Jamaica.\u00a0 Of the 917 stolen tickets, 68% were tied to Eras Tour dates at MetLife Stadium and SoFi Arena.<\/p>\n<p>Affected fans may file claims under New York\u2019s Cybercrime Victim Restoration Act, though legal experts warn reimbursement could take 18\u201324 months.<\/p>\n<p>As Swift\u2019s tour continues until 2025, industry leaders encourage fans to buy using verified platforms that use DMARC-certified email validation and <a href=\"https:\/\/cybersecuritynews.com\/6-trends-shaping-cryptocurrency-and-blockchain-in-2025\/\" target=\"_blank\" rel=\"noreferrer noopener\">blockchain-based<\/a> NFT tickets.<\/p>\n<p>This case highlights the rising conflict between cyber criminals and live-event cybersecurity professionals in the post-pandemic concert industry.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 93%,rgb(169,184,195) 100%)\"><strong><strong><code>Collect Threat Intelligence on the Latest Malware and Phishing Attacks with ANY.RUN TI Lookup -&gt;\u00a0<a href=\"https:\/\/intelligence.any.run\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=new-stegocampaign-attack&amp;utm_content=intelligence.any.run&amp;utm_term=040325\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try for free<\/a><\/code><\/strong><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/taylor-swift-era-concert-tickets-hack\/\">Two Hackers Arrested for Stealing Taylor Swift Era Concert Tickets Worth $600k<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Kaaviya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/taylor-swift-era-concert-tickets-hack\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Two Hackers Arrested for Stealing Taylor Swift Era Concert Tickets Worth $600k Two individuals were arrested this week in a sophisticated cybercrime operation targeting high-demand events. They were accused of orchestrating a $600,000 ticket theft scheme involving Taylor Swift\u2019s Eras Tour and other major concerts.\u00a0 Queens District Attorney Melinda Katz revealed that Tyrone Rose, 34, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,416],"tags":[130],"class_list":["post-2399","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerabilities","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2399"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=2399"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2399\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=2399"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=2399"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=2399"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}