Info was stolen by infiltrating Paylogic's ticketing system

Oct 29, 2018 18:24 GMT  ·  By

The private information of approximately 64,000 electronic dance music (EDM) fans who attended the 2014 Tomorrowland festival was stolen by hackers who managed to compromise Paylogic's ticketing system used by the festival to sell tickets online.

Tomorrowland is a Boom, Belgium electronic dance music festival that was first held in 2005, later becoming one of the world's largest music festivals with an attendance of 400,000 in 2018.

"The dates are limited to a part of the festival goers of 2014 and only contain their name, e-mail address, gender, age and postal code. The payment details, passwords and addresses of the users are not included," said spokesperson Debby Wilmsen to De Standaard.

Although the crooks haven't been able to steal sensitive information such as credit card payment details or social security numbers, they might still be able to attempt identity theft attacks if they have sufficient data.

'The administrators of the Paylogic ticketing system noticed unusual activity on an outdated system. After an extensive analysis, an old data file of Tomorrowland 2014 appeared on it. The server involved was taken offline immediately," spokesperson Wilmsen also said.

Out of the 360,000 people who attended Tomorrowland in 2014, roughly 64,000 of them had their personal information stolen

After being informed by Paylogic that their systems were compromised, Tomorrowland first notified the privacy commision and then sent e-mail alerts to all affected festival goers telling them about the data breach and the information the hackers managed to steal.

According to Paylogic, the data breach only affected Tomorrowland attendees who signed up for tickets in 2014, with all other Paylogic customers apparently being unaffected.

This hints at the possibility that the hackers have infiltrated the Paylogic sign up page on Tomorrowland's website, although there were no specifics mentioned in Paylogic's statement.

"We ask to be vigilant when receiving e-mails about ticket sales, promotions or other addresses that do not come from official Paylogic or Tomorrowland communication channels," also declared Wilmsen. 

"All communication from Tomorrowland is led by tomorrowland.com. Links to Tomorrowland ticket sales can only be found via my.tomorrowland.com or official travel partners."