Mystery database left open turns out to be massive Groupon fraud ticket fraud ring

Mystery database left open turns out to be massive Groupon fraud ticket fraud ring

Yes, turns out people still use this voucher biz – who knew?


We have a new twist on the "researchers find unprotected public-facing cloud-hosted database" story, as one recently uncovered archive turned out to be at the heart of a years-long fraud operation.


The team at VPNmentor said they were confused when first encountering the mystery database that contained details on scores of accounts from ticket purchasing sites. The profiles, all seemingly used for small, independent theaters and music venues, contained payment details for around 17 million ticket purchases.


"The breach seemed to give access to personal details of anyone purchasing tickets from a website using Neuroticket," explained the VPNmentor team, headed up to Noam Rotem and Ran Locar, on Wednesday.


"Initially, we believed this vulnerability compromised customers on these we ..