A seller on a Russian-language data-trading forum listed what they describe as an internal ticketing database on 2 September 2026, claiming 412,192 Latin American purchase records and more than 250,000 Brazilian CPF numbers, priced at $10,000. Ransomnews examined the published sample and found it consistent with genuine ticket-buyer data for The Town 2025, the São Paulo festival whose tickets were sold through Ticketmaster Brasil. Where the data was taken from is not established.
What is being sold
The listing is headed “SELLING NEW TICKETMASTER DATABASE” and describes a global ticketing platform, Latin America region, with an internal ticketing database as the source and a breach date of 28 August 2026. It advertises 412,192 rows across 34 columns. The country breakdown is dominated by Brazil at 251,557 records, or 61%, with Argentina at 219, Chile 155, Colombia 144, Peru 123 and Paraguay 72, plus nine more countries not itemised.

Pricing is $10,000 for the full set or $80 per thousand rows, with escrow offered. Against the 251,557 Brazilian records, the bulk price works out at roughly four cents per person.
The seller’s own notes are the part that should concern Brazilian readers most. Alongside the sales copy, the listing states that the CPF numbers work “for Brazilian bank fraud, loan apps and SIM registration”. That is not our characterisation of the risk. It is the seller describing the intended use of the file.

The data is from The Town 2025
The sample identifies its own event without ambiguity. Show dates are 6, 7, 12, 13 and 14 September 2025, matching The Town 2025 at the Autódromo de Interlagos in São Paulo. Product names are “Gramado”, “VIP” and “The Town Card”. Rate names are “Inteira”, “Meia-Entrada” and “Cortesia”, the last being complimentary entry.
The sales channels are the detail that ties the file to a specific seller of those tickets. The channel_name values include “Venda Geral” and “Pré-Venda Itaú”, which correspond to the sales phases published on ticketmaster.com.br for this event, where the general sale and the bank presale ran under those names. The Town is produced by Rock World SA, Roberto Medina’s company, which also runs Rock in Rio.
How we tested the sample
Most listings of this kind are fabricated, and we have called two of them fabricated in the past fortnight. Generated data tends to be too tidy: every field populated, every identifier well formed, and relationships between records that collapse under inspection. This sample behaves differently.
The purchase IDs run in order. Sort the 13 sampled records by purchase date and the purchase_id values ascend without a single inversion, from 52,308,017 on 20 February 2025 to 62,118,189 on 3 September 2025. That is what an auto-increment primary key does. For randomly generated identifiers to fall into date order by chance across 13 records is roughly a one in 6.2 billion event. The item_id column ascends independently in the same way.
The CPF numbers validate. Every Brazilian CPF in the sample passes the standard two-digit check-digit calculation. On its own this proves little, since the algorithm is public and every Brazilian test-data library implements it, but it is a necessary condition and the file meets it.
The telephone codes match the addresses. All 13 numbers carry a DDD area code consistent with the state on the same row, and they are not simply defaulting to São Paulo. Cerquilho carries 15, the Sorocaba region code rather than the metropolitan 11. Londrina carries 43, Belo Horizonte 31, Brasília 61, Rio de Janeiro 21. Every number also conforms to the Brazilian nine-digit mobile format.
The neighbourhoods belong to their cities. Gutierrez is in Belo Horizonte, Belenzinho in São Paulo, Barra da Tijuca in Rio de Janeiro, Setor Sudoeste in Brasília, Jundiapeba in Mogi das Cruzes, Brooklin Paulista in São Paulo. Producing that requires a real bairro gazetteer, not a name generator.
The pricing is internally exact. Full-price tickets are recorded at 975.00 and half-price at 487.50, precisely half, matching Brazil’s statutory meia-entrada entitlement. The Town Card entries sit at 447.50.
The timestamps agree across formats. The date_processed value 1759359941773, an epoch time in milliseconds, decodes exactly to 2025-10-01 23:05:41, the value carried in the adjacent date_processed_formatted column.
// Free tool
How does your own site score?
Run the same forty passive checks against your own domain — TLS and certificates, security headers, SPF and DMARC, cookies before consent, and what your stack quietly reveals. A grade out of 100 in about fifteen seconds.
No signup. Nothing installed. We only request what your site already serves publicly.
The file is ragged in the right places. Rows issued through the back office as complimentary tickets carry no name, email, CPF or telephone number at all, only the ticket type and show date. Fabricated sets are uniformly populated. Real ones carry the shape of the process that produced them.

Two further details point the same way. The payment methods listed include Pix, Brazil’s instant payment system, at 42,764 records, and Elo, the Brazilian domestic card network, at 3,952. Neither belongs to the vocabulary of a generic data generator. And the listing’s own arithmetic reconciles: 251,557 Brazilian records against a stated total of 412,192 is 61.03%, matching the claimed 61%, while the age-range breakdown totals 252,545 against a country breakdown of 252,270, two independently presented figures agreeing to within 275 rows.
Who lost the data is a separate question
The seller calls this a Ticketmaster breach. We are not able to confirm that, and the strongest clue in the file argues for caution.
Every record in the sample carries the same date_processed value, 1 October 2025 at 23:05:41, roughly two weeks after The Town closed. A live extract from a production database would not stamp every row with a single identical processing time. A report generated in one run would. That reads as a post-event buyer manifest rather than a database dump, and manifests of that kind are routinely produced for and shared with promoters, sponsors, payment partners and analytics suppliers.
So the data is real ticketing data, and the custodian is open. It could be Ticketmaster Brasil, Rock World, or any organisation that legitimately received an export. Until one of them says otherwise, describing this as a breach of Ticketmaster’s systems would be running ahead of the evidence.
Two other cautions apply. The 412,192 figure is the seller’s and we have seen 13 rows of it, so the scale is unverified. And the account offering it, “brokering”, registered on the forum on 27 August 2026 and states a breach date of 28 August, one day later, with six posts to its name. A new account is not evidence that data is fake, and our testing says this data is not fake, but it means there is no trading history to weigh.
What ticket buyers should do
If you bought tickets to The Town 2025, treat your CPF as exposed. A CPF cannot be reissued the way a password can, and the seller is explicitly marketing these numbers for credit and telecoms fraud.
- Check your CPF status and credit record. Registrato, run by the Banco Central, shows accounts and credit operations opened in your name. Serasa and SPC will show credit enquiries you did not make.
- Watch for SIM swap. The listing names SIM registration as a use case. If your mobile service drops unexpectedly and does not come back, contact your operator immediately rather than waiting.
- Expect targeted phishing. Whoever holds this file knows your name, your CPF, your telephone number, your neighbourhood, which festival days you attended, what you paid and how many instalments you chose. A message referencing your ticket purchase will look convincing.
- Do not confirm details to inbound callers. The combination of purchase history and identity data in this file is exactly what makes a cold call sound legitimate.
- Check whether your credentials are circulating separately. Our stealer-log lookup covers infostealer captures, a different exposure route that often affects the same people.
What this says about event data
A festival ticket is not obviously an identity document, but in Brazil it is close to one. The meia-entrada system requires proof of entitlement, and CPF collection at purchase is routine across Brazilian ticketing. The result is that a live-events company ends up holding a national identifier, a verified telephone number and a home neighbourhood for hundreds of thousands of people, which is a bank’s worth of identity data held by an industry that is not regulated or resourced like a bank.
The export timestamp matters for the same reason. Data that is well defended inside a ticketing platform becomes considerably less defended the moment it is exported to a spreadsheet and shared with the people who need to reconcile a festival. That handoff is where much of this category of loss happens, and it is the part that shows up in almost no incident reporting.
What we did not do
We did not access, probe or authenticate against any system belonging to Ticketmaster, Live Nation or Rock World, and we did not purchase the data set. Our analysis covers the free sample only. We did not validate any CPF, email address or telephone number against a live service, and we are not publishing the sample, its download location, the seller’s contact details, or any individual’s personal data. We wrote to Ticketmaster Brasil, to Rock World SA and to Brazil’s data protection authority, the ANPD, before publication, and offered to share the listing and the sample with their investigators at no cost. This article will be updated with any response.
Frequently asked questions
Was Ticketmaster breached?
Not established. The seller describes the file as a Ticketmaster database, and Ticketmaster Brasil sold the tickets for this event, but every record carries an identical processing timestamp two weeks after the festival, which points to an exported buyer manifest rather than a live database extract. Ransomnews contacted Ticketmaster Brasil and Rock World SA before publication.
Is the leaked ticketing data real?
The published sample is consistent with genuine ticketing data on every test we applied, including check-digit validation of the CPF numbers, telephone area codes matching the recorded state, neighbourhood-to-city mapping, exact half-price ticket arithmetic and a strictly ascending purchase-ID sequence. The claim of 412,192 records is separate and remains unverified.
What data is in the file?
Purchase IDs and dates, names, email addresses, CPF numbers, telephone numbers, city, state and neighbourhood, age range, ticket type and rate, sales channel, card brand, instalment count and show date. Complimentary tickets issued through the back office carry no personal data.
Why does a leaked CPF matter?
A CPF is a permanent Brazilian national identifier that cannot be reissued like a password or card number. Combined with a name, telephone number and address it supports credit applications, loan fraud and SIM registration in the victim’s name, which is precisely what the seller advertises it for.
How many people are affected?
Unknown. The seller claims 412,192 rows including 251,557 Brazilian records and more than 250,000 CPF numbers. Ransomnews reviewed 13 rows and cannot verify the total.
What should I do if I went to The Town 2025?
Treat your CPF as exposed. Check Registrato at the Banco Central and your Serasa or SPC record for credit operations you did not open, watch for unexplained loss of mobile service, and be sceptical of any call or message that references your ticket purchase.
Does this have to be reported to the ANPD?
Under Brazil’s LGPD, a controller must notify the ANPD and affected data subjects of an incident that may create relevant risk or damage. Which organisation carries that duty here depends on who held the data, which is the open question.
Sources and further reading
- Forum listing published 2 September 2026 by the handle “brokering”. Ransomnews does not link to data-trading listings or to sample downloads containing personal data.
- Ticketmaster Brasil sales pages for the event: Venda Geral and Pré-Venda Club
- The Town festival background and 2025 dates: Wikipedia
- Banco Central Registrato, for checking accounts and credit operations opened in your name: bcb.gov.br
- ANPD guidance on communicating a security incident: gov.br/anpd
- Related Ransomnews reporting on testing seller claims: the Love Electric driver database, the McDonald’s employee listing and the Stripe merchant API key dump
- More about the researchers behind this analysis: Ransomnews editorial team
The Ransomnews Monthly
One email a month. Original leak-site data, victim census updates, and the findings that did not make the articles. No spam, unsubscribe any time.
Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.
