Second-hand ticket marketplace Tixel confirms customer information stolen in data breach

Hackers are believed to have used AI to steal the personal details of customers.

Freddy Pawle
7NEWS
A major cyber security breach at Origin Energy has raised concerns about the vulnerability of personal data and the increasing sophistication of AI-powered scams.

A data breach of a business database has led to customers of a second-hand ticket marketplace having their information stolen.

The Melbourne-based ticket reseller, Tixel, sent an email to users on Friday night notifying them that their “email address and mobile number may have been accessed as part of this incident”.

However, Tixel also noted the breach did not impact any customer’s “passwords, credit card details, payment information or purchase history”.

Sign up to The Nightly's newsletters.

Get the first look at the digital newspaper, curated daily stories and breaking headlines delivered to your inbox.

Email Us
By continuing you agree to our Terms and Privacy Policy.

“Your account — including any tickets or listings — is unaffected,” the email reads.

“The two things worth watching for are spam and phishing — unwanted or scam messages by email, text or phone, especially any that pretend to be from Tixel.”

Crowd on the concert
Crowd on the concert Credit: kamisoka/Getty Images

The company added that it would never ask for a customer’s password or payment details by email or text.

It confirmed the data breach stemmed from third party analytics provider, Metabase, being “briefly accessed by an unauthorised party”.

Metabase confirmed in a blog post that the breach had occurred weeks prior on August 3.

Hack aided by AI

A “zero-day” vulnerability within the company’s cloud services was used to gain access to Metabase customers.

The blog post added that a review of the breach showed the hack most likely used a Large Language Model (LLM).

The email sent to Tixel customers notifying them their personal information may have been accessed in a cyber attack
The email sent to Tixel customers notifying them their personal information may have been accessed in a cyber attack Credit: 7NEWS.com.au

“Due to the complexity of this attack ... we believe this attack required significant LLM capabilities,” Metabase said.

“Given the extremely rapid increase in capabilities in LLM code scanning and its ability to weave together deep attack chains, we are hardening Metabase across the layers rather than stopping at fixing this one vulnerability.”

The company also confirmed just under three per cent of its customers had been impacted by the hack and had since launched an update to further secure its cloud services.

7NEWS.com.au has approached both Tixel and Metabase for further comment.

Originally published on 7NEWS

Latest Edition

The Nightly cover for 28-08-2026

Latest Edition

Edition Edition 28 August 202628 August 2026

How the rise in support for One Nation is causing chaos for the major parties.