throbber
Case 2:24-cv-04482-SPG-MAA Document 1 Filed 05/29/24 Page 1 of 37 Page ID #:1
`
`CLARKSON LAW FIRM, P.C.
`Ryan J. Clarkson (SBN 257074)
`rclarkson@clarksonlawfirm.com
`Yana Hart (SBN 306499)
`yhart@clarksonlawfirm.com
`Tiara Avaness (SBN 343928)
`tavaness@clarksonlawfirm.com
`22525 Pacific Coast Highway
`Malibu, CA 90265
`Tel: (213) 788-4050
`Fax: (213) 788-4070
`
`Counsel for Plaintiffs and the Proposed Classes
`
`UNITED STATES DISTRICT COURT
`CENTRAL DISTRICT OF CALIFORNIA
`
`CYNTHIA RYAN and ROSALIA
`GARCIA, on behalf of themselves and all
`others who are similarly situated,
`Plaintiffs,
`
`v.
`TICKETMASTER, LLC., and LIVE
`NATION ENTERTAINMENT, INC.
`Defendants.
`
`2:24-cv-4482
`Case No.
`CLASS ACTION COMPLAINT
`1. NEGLIGENCE
`2. NEGLIGENCE PER SE
`
`3. BREACH OF FIDUCIARY
`DUTY
`
`4. UNJUST ENRICHMENT
`
`5. BREACH OF IMPLIED
`CONTRACT
`
`6. VIOLATION OF THE
`CALIFORNIA CONSUMER
`PRIVACY ACT OF 2018 Cal.
`Civ. Code §§ 1798.100 et seq.
`(“CCPA”)
`
`7. VIOLATION OF THE
`CALIFORNIA CONSUMER
`
`CLASS ACTION COMPLAINT
`
`1
`2
`3
`4
`5
`6
`7
`8
`9
`10
`11
`12
`13
`14
`15
`16
`17
`18
`19
`20
`21
`22
`23
`24
`25
`26
`27
`28
`
`Clarkson Law Firm, P.C. | 22525 Pacific Coast Highway, Malibu, CA 90265 | P: (213) 788-4050 F: (213) 788-4070 | clarksonlawfirm.com
`
`

`

`Case 2:24-cv-04482-SPG-MAA Document 1 Filed 05/29/24 Page 2 of 37 Page ID #:2
`
`
`
`LEGAL REMEDIES ACT Cal.
`Civ. Code §§ 1750 et seq.
`(“CLRA”)
`
`8. VIOLATION OF THE
`CALIFORNIA UNFAIR
`COMPETITION LAW Cal.
`Bus. and Prof. Code §§ 17200,
`et seq. (“UCL”)
`
`DEMAND FOR JURY TRIAL
`
`
`CLASS ACTION COMPLAINT
`
`1
`2
`3
`4
`5
`6
`7
`8
`9
`10
`11
`12
`13
`14
`15
`16
`17
`18
`19
`20
`21
`22
`23
`24
`25
`26
`27
`28
`
`
`
`
`
`Clarkson Law Firm, P.C. | 22525 Pacific Coast Highway, Malibu, CA 90265 | P: (213) 788-4050 F: (213) 788-4070 | clarksonlawfirm.com
`
`
`
`

`

`Case 2:24-cv-04482-SPG-MAA Document 1 Filed 05/29/24 Page 3 of 37 Page ID #:3
`
`
`
`CLASS ACTION COMPLAINT
`Plaintiffs Cynthia Ryan and Rosalia Garcia (collectively, “Plaintiffs”)
`individually and on behalf of all others similarly situated, bring this Class Action
`Complaint (the “Complaint”), and allege
`the following against Defendants
`Ticketmaster, LLC (“Ticketmaster”) and Live Nation Entertainment, Inc. (“Live
`Nation”) (collectively, “Defendants”), based upon personal knowledge with respect to
`themselves and upon information and belief derived from, among other things,
`investigation of counsel and review of public documents as to all other matters.
`NATURE OF THE ACTION
`Plaintiffs bring this class action against Defendants for their failure to
`1.
`properly secure and safeguard Plaintiffs’ and other similar situated individuals’ personal
`identifiable information (“PII”), including but not limited to “full names, addresses,
`email addresses, phone numbers, ticket sales and event details, order information, and
`partial payment card data. [The] compromised payment data includes customer names,
`the last four digits of card numbers, expiration dates, and even customer fraud details”
`(collectively, “Private Information”).1
`2. This class action arises out of the recent targeted cyberattack against
`Ticketmaster that enabled a third party to access Defendants’ computer systems and data,
`resulting in the compromise of highly sensitive Private Information (the “Data
`Breach”).2
`3. Due to the Data Breach, Plaintiffs and Class Members suffered ascertainable
`losses in the form of the benefit of their bargain, out-of-pocket expenses and the value of
`their time reasonably incurred to remedy or mitigate the effects of the attack, emotional
`
`
`1 Waqas, Hackers Claim Ticketmaster Data Breach: 560M Users’ Info for Sale at $500k,
`HACKREAD (May 29, 2024), https://hackread.com/hackers-ticketmaster-data-breach-
`560m-users-sale/.
`2 Id.
`
`1
`CLASS ACTION COMPLAINT
`
`1
`2
`3
`4
`5
`6
`7
`8
`9
`10
`11
`12
`13
`14
`15
`16
`17
`18
`19
`20
`21
`22
`23
`24
`25
`26
`27
`28
`
`
`
`Clarkson Law Firm, P.C. | 22525 Pacific Coast Highway, Malibu, CA 90265 | P: (213) 788-4050 F: (213) 788-4070 | clarksonlawfirm.com
`
`
`
`

`

`Case 2:24-cv-04482-SPG-MAA Document 1 Filed 05/29/24 Page 4 of 37 Page ID #:4
`
`
`
`distress, and the imminent risk of future harm caused by the compromise of their Private
`Information.
`4. The Data Breach was a direct result of Defendants’ failure to implement
`adequate and reasonable cybersecurity procedures and protocols necessary to protect
`consumers’ Private Information.
`5. On or around May 28, 2024, the Private Information of 560,000,000
`Ticketmaster customers was compromised and listed for sale.3 The notorious hacker
`group known only by its alias “ShinyHunters” claimed that it had stolen 1.3 terabytes of
`personal data and is reportedly ready to sell, or has already sold, such information to
`nefarious dark web users for $500,000, as illustrated by their post on BreachForums, a
`dark-web marketplace for stolen data:
`
`6. This Data Breach occurred because Ticketmaster enabled an unauthorized
`third party to gain access to and obtain former and current Ticketmaster customers’
`Private Information from Ticketmaster’s internal computer systems.4
`7. As of May 29, 2024, Defendants have not released a statement nor notified
`its customers that their Private Information has been compromised and is likely in the
`
`
`3 Georgie Hewson, Home Affairs Department confirms cyber incident impacting
`Ticketmaster customers, ABC NEWS (May 29, 2024), https://www.abc.net.au/news/2024-
`05-29/ticketmaster-hack-allegedlyshinyhunter-customers-data-leaked/103908614.
`4 Id.
`
`2
`CLASS ACTION COMPLAINT
`
`1
`2
`3
`4
`5
`6
`7
`8
`9
`10
`11
`12
`13
`14
`15
`16
`17
`18
`19
`20
`21
`22
`23
`24
`25
`26
`27
`28
`
`
`
`Clarkson Law Firm, P.C. | 22525 Pacific Coast Highway, Malibu, CA 90265 | P: (213) 788-4050 F: (213) 788-4070 | clarksonlawfirm.com
`
`
`
`

`

`Case 2:24-cv-04482-SPG-MAA Document 1 Filed 05/29/24 Page 5 of 37 Page ID #:5
`
`
`
`hands of threat actors. Ticketmaster consumers are in the dark, unaware that their Private
`Information may be used to effectuate identity theft, phishing scams, plunging credit
`scores and related cybercrimes.
`8. The Data Breach was a direct result of Defendants’ failure to implement
`adequate and reasonable cybersecurity procedures and protocols, consistent with the
`industry standard, necessary to protect Private Information from the foreseeable threat of
`a cyberattack.
`9. By acquiring Plaintiffs’ and class members’ Private Information for their
`own pecuniary benefit, Defendants assumed a duty to Plaintiffs and Class Members to
`implement and maintain reasonable and adequate security measures to secure, protect,
`and safeguard Plaintiffs’ and Class Members’ Private Information against unauthorized
`access and disclosure.
`10. Defendants also had a duty to adequately safeguard this Private Information
`under controlling case law, as well as pursuant to industry standards and duties imposed
`by statutes, including Section 5 of the Federal Trade Commission Act (the “FTC Act”).
`11. Defendants breached those duties and disregarded the rights of Plaintiffs and
`the Class Members by intentionally, willfully, recklessly, or negligently failing to
`implement proper and reasonable measures to safeguard consumers’ Private Information;
`failing to take available and necessary steps to prevent unauthorized disclosure of data;
`and failing to follow applicable, required, and proper protocols, policies, and procedures
`regarding the encryption of data.
`12. As a result of Defendants’ inadequate security and breach of their duties and
`obligations, the Private Information of Plaintiffs and Class Members was compromised
`through disclosure to an unauthorized criminal third party. Plaintiffs and Class Members
`have suffered injuries as a direct and proximate result of Defendants’ conduct. These
`injuries include: (i) diminution in value and/or lost value of Private Information, a form
`of property that Defendants obtained from Plaintiffs and Class Members; (ii) out-of-
`
`3
`CLASS ACTION COMPLAINT
`
`1
`2
`3
`4
`5
`6
`7
`8
`9
`10
`11
`12
`13
`14
`15
`16
`17
`18
`19
`20
`21
`22
`23
`24
`25
`26
`27
`28
`
`
`
`Clarkson Law Firm, P.C. | 22525 Pacific Coast Highway, Malibu, CA 90265 | P: (213) 788-4050 F: (213) 788-4070 | clarksonlawfirm.com
`
`
`
`

`

`Case 2:24-cv-04482-SPG-MAA Document 1 Filed 05/29/24 Page 6 of 37 Page ID #:6
`
`
`
`pocket expenses associated with preventing, detecting, and remediating identity theft,
`social engineering, and other unauthorized use of their Private Information; (iii)
`opportunity costs associated with attempting to mitigate the actual consequences of the
`Data Breach, including but not limited to lost time; (iv) the continued, long term, and
`certain increased risk that unauthorized persons will access and abuse Plaintiffs’ and
`Class Members’ Private Information; (v) the continued and certain increased risk that the
`Private Information that remains in Defendants’ possession is subject to further
`unauthorized disclosure for so long as Defendants fail to undertake proper measures to
`protect the Private Information; (v) invasion of privacy and increased risk of fraud and
`identity theft; and (vi) theft of their Private Information and the resulting loss of privacy
`rights in that information. This action seeks to remedy these failings and their
`consequences. Plaintiffs and Class Members have a continuing interest in ensuring that
`their Private Information is and remains safe, and they should be entitled to injunctive
`and other equitable relief.
`13. Despite having been accessed and exfiltrated by unauthorized criminal
`actors, Plaintiffs’ and Class Members’ sensitive and confidential Private Information
`remains in the possession of Defendants. Absent additional safeguards and independent
`review and oversight, the information remains vulnerable to further cyberattacks and
`theft. The aggregate data compromised in the Data Breach, taken as a whole, including
`but not limited to: full names, addresses, email addresses, phone numbers, ticket sales
`and event details, order information, and partial payment card data including customer
`names, the last four digits of card numbers, expiration dates, and customer fraud details,
`increases the risk of harm, making identity theft a likely outcome.
`14. Defendants disregarded the rights of Plaintiffs and Class Members by, inter
`alia, failing to take adequate and reasonable measures to ensure their data systems were
`protected against unauthorized intrusions; failing to disclose that they did not have
`adequately robust computer systems and security practices to safeguard Private
`
`4
`CLASS ACTION COMPLAINT
`
`1
`2
`3
`4
`5
`6
`7
`8
`9
`10
`11
`12
`13
`14
`15
`16
`17
`18
`19
`20
`21
`22
`23
`24
`25
`26
`27
`28
`
`
`
`Clarkson Law Firm, P.C. | 22525 Pacific Coast Highway, Malibu, CA 90265 | P: (213) 788-4050 F: (213) 788-4070 | clarksonlawfirm.com
`
`
`
`

`

`Case 2:24-cv-04482-SPG-MAA Document 1 Filed 05/29/24 Page 7 of 37 Page ID #:7
`
`
`
`Information; failing to take standard and reasonably available steps to prevent the Data
`Breach; and failing to properly train its staff and employees on proper security measures.
`In addition, Defendants failed to properly monitor the computer network and
`15.
`systems that housed the Private Information. Had Defendants properly monitored these
`electronic systems, Defendants would have discovered the intrusion sooner or prevented
`it altogether.
`16. The security of Plaintiffs’ and Class Members’ identities is now at substantial
`risk because of Defendants’ wrongful conduct as the Private Information that Defendants
`collected and maintained are now in the hands of data thieves. This present risk will
`continue for the course of their lives.
`17. Armed with the Private Information accessed in the Data Breach, data thieves
`can commit a wide range of crimes.
`18. As a result of the Data Breach, Plaintiffs and Class Members have been
`exposed to a present and imminent risk of fraud and identity theft. Among other
`measures, Plaintiffs and Class Members must now and in the future closely monitor their
`financial accounts to guard against identity theft. Further, Plaintiffs and Class Members
`will incur out-of-pocket costs to purchase adequate credit monitoring and identity theft
`protection and insurance services, credit freezes, credit reports, or other protective
`measures to deter and detect identity theft.
`19. Plaintiffs and Class Members will also be forced to expend additional time
`to review credit reports and monitor their financial accounts for fraud or identity theft.
`And because they exposed other immutable personal details, the risk of identity theft and
`fraud will persist throughout their lives.
`20. Plaintiffs bring this lawsuit on behalf of themselves and all those similarly
`situated to address Defendants’ inadequate safeguarding of Class Members’ Private
`Information that they collected and maintained.
`
`5
`CLASS ACTION COMPLAINT
`
`1
`2
`3
`4
`5
`6
`7
`8
`9
`10
`11
`12
`13
`14
`15
`16
`17
`18
`19
`20
`21
`22
`23
`24
`25
`26
`27
`28
`
`
`
`Clarkson Law Firm, P.C. | 22525 Pacific Coast Highway, Malibu, CA 90265 | P: (213) 788-4050 F: (213) 788-4070 | clarksonlawfirm.com
`
`
`
`

`

`Case 2:24-cv-04482-SPG-MAA Document 1 Filed 05/29/24 Page 8 of 37 Page ID #:8
`
`
`
`21. Plaintiffs, on behalf of themselves and all other Class Members, bring claims
`for negligence, negligence per se, breach of implied contract, breach of fiduciary duty,
`unjust enrichment, and for declaratory and injunctive relief. To remedy these violations
`of law, Plaintiffs and Class Members thus seek actual damages, statutory damages,
`restitution, and injunctive and declaratory relief (including significant improvements to
`Defendants’ data security protocols and employee training practices), reasonable
`attorneys’ fees, costs, and expenses incurred in bringing this action, and all other
`remedies this Court deems just and proper.
`JURISDICTION AND VENUE
`22. This Court has subject matter jurisdiction over this action pursuant to the
`Class Action Fairness Act of 2005, 28 U.S.C. § 1332(d)(2), because: (i) the amount in
`controversy exceeds $5 million, exclusive of interest and costs; (ii) the number of class
`members exceeds 100 and (iii) minimal diversity exists because many class members,
`have different citizenship from Defendants.
`23. This Court has personal jurisdiction over Defendants because Defendants
`have purposefully availed themselves of the laws, rights, and benefits of the State of
`California. Defendants are headquartered in California and have engaged in activities
`including (i) directly and/or through its parent companies, affiliates and/or agents
`providing services throughout the United States in this judicial district; (ii) conducting
`substantial business in this forum; and/or (iii) engaging in other persistent courses of
`conduct and/or deriving substantial revenue from services provided in California and in
`this judicial District.
`24. Venue is proper in this Court pursuant to 28 U.S.C. § 1391(a)(1) because a
`substantial part of the events giving rise to this action occurred in this District. Moreover,
`Defendants are based in this District, maintain Plaintiffs’ and Class Members’ Private
`Information in this District, and has caused harm to Plaintiffs and Class Members in this
`District.
`
`6
`CLASS ACTION COMPLAINT
`
`1
`2
`3
`4
`5
`6
`7
`8
`9
`10
`11
`12
`13
`14
`15
`16
`17
`18
`19
`20
`21
`22
`23
`24
`25
`26
`27
`28
`
`
`
`Clarkson Law Firm, P.C. | 22525 Pacific Coast Highway, Malibu, CA 90265 | P: (213) 788-4050 F: (213) 788-4070 | clarksonlawfirm.com
`
`
`
`

`

`Case 2:24-cv-04482-SPG-MAA Document 1 Filed 05/29/24 Page 9 of 37 Page ID #:9
`
`
`
`PARTIES
`
`Plaintiff Cynthia Ryan
`25. Plaintiff Cynthia Ryan is a citizen of the State of California. At all relevant
`times, Plaintiff has resided in the county of Los Angeles, California.
`26. Since at least 2012, Plaintiff Ryan has been Defendants’ customer and
`Ticketmaster account holder. Plaintiff provided her Private Information to Defendants,
`including her credit card. In receiving and maintaining her Private Information for its
`business purposes, Defendants expressly and impliedly promised, and undertook a duty,
`to act reasonably in its handling of Plaintiff Ryan’s Private Information. Defendants,
`however, did not take proper care of Plaintiff Ryan’s Private Information, leading to its
`exposure to and exfiltration by cybercriminals as a direct result of Defendants’
`inadequate cybersecurity measures.
`27. Plaintiff Ryan is deeply concerned by the Data Breach because she and her
`family frequently use Ticketmaster to purchase concert tickets. Plaintiff Ryan continues
`to worry about her Private Information, as it is readily available for cybercriminals to
`sell, buy, and exchange, on the Dark Web.
`28. Since learning about the Data Breach, Plaintiff anticipates needing to spend
`substantial time to determine the extent and gravity of the Data Breach and to mitigate
`damages. Plaintiff will need to review for fraudulent activity and closely monitor her
`financial information.
`29. Plaintiff Ryan suffers a substantially increased risk of fraud, identity theft,
`and data misuse resulting from her Private Information being leaked on to the Dark Web
`and subjected to unauthorized third parties/criminals.
`30. Plaintiff Ryan has a continuing interest in ensuring that her Private
`Information, which remains in Defendants’ possession, is protected and safeguarded
`from future breaches.
`
`7
`CLASS ACTION COMPLAINT
`
`1
`2
`3
`4
`5
`6
`7
`8
`9
`10
`11
`12
`13
`14
`15
`16
`17
`18
`19
`20
`21
`22
`23
`24
`25
`26
`27
`28
`
`
`
`Clarkson Law Firm, P.C. | 22525 Pacific Coast Highway, Malibu, CA 90265 | P: (213) 788-4050 F: (213) 788-4070 | clarksonlawfirm.com
`
`
`
`

`

`Case 2:24-cv-04482-SPG-MAA Document 1 Filed 05/29/24 Page 10 of 37 Page ID #:10
`
`
`
`Plaintiff Rosalia Garcia
`31. Plaintiff Rosalia Garcia is a citizen of the State of California. At all relevant
`times, Plaintiff Garcia has resided in the county of Los Angeles, California.
`32. Since at least 2019, Plaintiff Garcia has been Defendants’ customer and
`Ticketmaster account holder. Plaintiff provided her Private Information to Defendants.
`In receiving and maintaining her Private Information for its business purposes,
`Defendants expressly and impliedly promised, and undertook a duty, to act reasonably in
`its handling of Plaintiff Garcia’s Private Information. Defendants, however, did not take
`proper care of Plaintiff Garcia’s Private Information, leading to its exposure to and
`exfiltration by cybercriminals as a direct result of Defendants’ inadequate cybersecurity
`measures.
`33. Plaintiff Garcia is deeply concerned by the Data Breach because she
`frequently uses Ticketmaster to purchase tickets. Plaintiff Garcia continues to worry
`about her Private Information, as it is readily available for cybercriminals to sell, buy,
`and exchange, on the Dark Web.
`34. Since learning about the Data Breach, Plaintiff anticipates needing to spend
`substantial time to determine the extent and gravity of the Data Breach and to mitigate
`damages. Plaintiff will need to review for fraudulent activity and closely monitor her
`financial information.
`35. Plaintiff Garcia suffers a substantially increased risk of fraud, identity theft,
`and data misuse resulting from her Private Information being leaked onto the Dark Web
`and subjected to unauthorized third parties/criminals.
`36. Plaintiff Garcia has a continuing interest in ensuring that her Private
`Information, which remains in Defendants’ possession, is protected and safeguarded
`from future breaches.
`
`8
`CLASS ACTION COMPLAINT
`
`1
`2
`3
`4
`5
`6
`7
`8
`9
`10
`11
`12
`13
`14
`15
`16
`17
`18
`19
`20
`21
`22
`23
`24
`25
`26
`27
`28
`
`
`
`Clarkson Law Firm, P.C. | 22525 Pacific Coast Highway, Malibu, CA 90265 | P: (213) 788-4050 F: (213) 788-4070 | clarksonlawfirm.com
`
`
`
`

`

`Case 2:24-cv-04482-SPG-MAA Document 1 Filed 05/29/24 Page 11 of 37 Page ID #:11
`
`
`
`Defendant Ticketmaster, LLC.
`37. Defendant Ticketmaster, LLC. is a wholly owned subsidiary of Defendant
`Live Nation Entertainment, Inc. headquartered in California with its principal executive
`office located at 9348 Civic Center Drive, Beverly Hills, CA 90210.
`38. Ticketmaster and Live Nation Entertainment completed their merger on
`January 25, 2010.5
`39. Ticketmaster “operates as a ticket distribution company. [Ticketmaster]
`buys, transfers, and sells tickets for live music, sporting, arts, theater, and family events.
`Ticketmaster serves clients worldwide.”6
`40. Plaintiffs and Class Members are current and former customers of
`Ticketmaster and account holders on Ticketmaster.com.
`41. Due to the nature of the services Ticketmaster provides, it receives and is
`entrusted with securely storing consumers’ Private Information, which includes, inter
`alia, individuals’ full name, payment information, occasional location data, and other
`sensitive information. Ticketmaster promised to provide confidentiality and adequate
`security for the data it collected from customers through its applicable privacy policy and
`through other disclosures in compliance with statutory privacy requirements.
`Defendant Live Nation Entertainment, Inc.
`42. Defendant Live Nation Entertainment, Inc. is a Delaware corporation
`
`headquartered in California with its principal executive office located at 9348 Civic
`
`Center Drive, Beverly Hills, CA 90210.
`
`
`5 Live Nation and Ticketmaster Entertainment Complete Merger, SECURITIES AND
`EXCHANGE
`COMMISSION
`(Jan.
`25,
`2010),
`https://www.sec.gov/Archives/edgar/data/1335258/000119312510012287/dex991.htm.
`6
`LLC,
`BLOOMBERG,
`Ticketmaster
`https://www.bloomberg.com/profile/company/0009574D:US (last visited May 29,
`2024).
`
`9
`CLASS ACTION COMPLAINT
`
`1
`2
`3
`4
`5
`6
`7
`8
`9
`10
`11
`12
`13
`14
`15
`16
`17
`18
`19
`20
`21
`22
`23
`24
`25
`26
`27
`28
`
`
`
`Clarkson Law Firm, P.C. | 22525 Pacific Coast Highway, Malibu, CA 90265 | P: (213) 788-4050 F: (213) 788-4070 | clarksonlawfirm.com
`
`
`
`

`

`Case 2:24-cv-04482-SPG-MAA Document 1 Filed 05/29/24 Page 12 of 37 Page ID #:12
`
`
`
`43. Live Nation Entertainment is a publicly traded corporation listed on the New
`
`York Stock Exchange with revenues totaling approximately $3.8 billion for the three
`
`months ended on March 31, 2024.7
`
`44. Live Nation is “the largest live entertainment company in the world,
`
`connecting over 765 million fans across all of our concerts and ticketing platforms in 49
`
`countries during 2023.”8
`
`45. Due to the nature of the services Live Nation provides, it receives and is
`entrusted with securely storing consumers’ Private Information, which includes, inter
`alia, individuals’ full name, payment information, occasional location data, and other
`sensitive information. Live Nation promised to provide confidentiality and adequate
`security for the data it collected from customers through its applicable privacy policy and
`through other disclosures in compliance with statutory privacy requirements.
`FACTUAL ALLEGATIONS
`A. The Data Breach, and Defendants Unsecure Data Management.
`46. On May 28, 2024, threat actors posted that 1.4 terabytes of Private
`Information were available for purchase on the hacking website Breach Forums.9 The
`notorious hacking group ShinyHunters offered the trove of Plaintiffs’ and Class
`Members’ Private Information for $500,000.
`
`
`7 Form 10-Q Quarterly Report for Live Nation Entertainment, Inc., BAMSEC,
`https://www.bamsec.com/filing/133525824000071?cik=1335258 (last visited May 29,
`2024).
`8 Form 10-K Annual Report for Live Nation Entertainment, Inc., BAMSEC,
`https://www.bamsec.com/filing/133525824000017?cik=1335258 (last visited May 29,
`2024).
`9 Waqas, supra note 1.
`
`10
`CLASS ACTION COMPLAINT
`
`1
`2
`3
`4
`5
`6
`7
`8
`9
`10
`11
`12
`13
`14
`15
`16
`17
`18
`19
`20
`21
`22
`23
`24
`25
`26
`27
`28
`
`
`
`Clarkson Law Firm, P.C. | 22525 Pacific Coast Highway, Malibu, CA 90265 | P: (213) 788-4050 F: (213) 788-4070 | clarksonlawfirm.com
`
`
`
`

`

`Case 2:24-cv-04482-SPG-MAA Document 1 Filed 05/29/24 Page 13 of 37 Page ID #:13
`
`
`
`47. Defendants are yet to make a statement or inform consumers that their data
`is available on the dark web. Such data includes, according to the hackers’ forum post,
`“560 million customers [sic] full details (name, address, email, phone) – Ticket sales,
`event information, order details – CC [credit card] detail [sic] – customer, last 4 of card,
`expiration date. Customer fraud details – much more.”10
`48. Prior to the Data Breach in May 2024, Plaintiffs and Class Members had
`provided their Private Information to Ticketmaster with the reasonable expectation and
`mutual understanding that Ticketmaster would comply with its obligations to keep such
`information confidential and secure from unauthorized access. In particular, Plaintiffs
`and Class Members provided their names, emails, phone numbers, location data and
`credit card information to Ticketmaster in order to register for an account and purchase
`event tickets on Ticketmaster.com.
`49. PII is a valuable property right.11 “Firms are now able to attain significant
`market valuations by employing business models predicated on the successful use of
`personal data within the existing legal and regulatory frameworks.”12 It is estimated that
`American companies have spent over $19 billion on acquiring personal data of
`consumers in 2018.13 It is so valuable to identity thieves that once PII has been disclosed,
`criminals often trade it on the “cyber black-market,” or the “dark web,” for many years.
`
`
`10 Id.
`11 See Marc van Lieshout, The Value of Personal Data, 457 IFIP ADVANCES IN
`INFORMATION
`AND COMMUNICATION
`TECHNOLOGY
`26-38
`(May
`2015),
`https://www.researchgate.net/publication/283668023_
`The_Value_of_Personal_Data
`(“The value of [personal] information is well understood by marketers who try to collect
`as much data about personal conducts and preferences as possible...”).
`12 Exploring the Economics of Personal Data: A Survey of Methodologies for Measuring
`Monetary Value, OECD No. 220 (Apr. 2, 2013), https://www.oecd-ilibrary.org/science-
`and-technology/exploring-the-economics-of-personal-data_5k486qtxldmq-en.
`13 U.S. Firms to Spend Nearly $19.2 Billion on Third-Party Audience Data and Data-Use
`Solutions in 2018, Up 17.5% from 2017, INTERACTIVE ADVERTISING BUREAU (Dec. 5,
`2018), https://www.iab.com/news/2018-state-of-data-report/.
`
`11
`CLASS ACTION COMPLAINT
`
`1
`2
`3
`4
`5
`6
`7
`8
`9
`10
`11
`12
`13
`14
`15
`16
`17
`18
`19
`20
`21
`22
`23
`24
`25
`26
`27
`28
`
`
`
`Clarkson Law Firm, P.C. | 22525 Pacific Coast Highway, Malibu, CA 90265 | P: (213) 788-4050 F: (213) 788-4070 | clarksonlawfirm.com
`
`
`
`

`

`Case 2:24-cv-04482-SPG-MAA Document 1 Filed 05/29/24 Page 14 of 37 Page ID #:14
`
`
`
`Indeed, the threat actor who compromised Defendants’ systems is seeking a one-time
`payment of half a million dollars in exchange for this Private Information.
`50. Plaintiffs and the Class’s Private Information exposed in the Data Breach has
`been exposed on the Dark Web.
`51. Ticketmaster promised consumers it would keep their data secure and
`private. Data security is purportedly a critical component of Ticketmaster’s business
`model. On a section of its website, Ticketmaster confidently asserts the following
`statements:
`
`“We’re always taking steps to make sure your information is
`protected and deleted securely,” “[we] have security measure in
`place to protect your information,”14 and “[the] security of our
`fans’ information is a priority for us. We take all necessary
`security measures to protect personal information that’s shared
`and stored with us.”15
`
`52. On its website, Ticketmaster maintains an “Our Commitments” section,
`including “Security & Confidentiality” as one of “10 commitments that drive
`[Ticketmaster’s] privacy program, globally”.16
`53. Contrary to Ticketmaster’s various express assurances that it would take
`reasonable measures to safeguard the sensitive information entrusted to it, an
`“unauthorized” person or persons was able to access its network servers.
`54. To date, Ticketmaster has not disclosed complete specifics of the attack, such
`as whether ransomware has been used.
`55. As such, Ticketmaster, and its parent company Live Nation, have failed to
`secure the PII of the individuals that provided their sensitive information. Defendants
`
`
`14 Privacy Policy, TICKETMASTER, https://privacy.ticketmaster.com/privacy-policy (last
`visited May 29, 2024).
`15 Our Commitments, TICKETMASTER,
`commitments (last visited May 29, 2024).
`16 Id.
`
`https://privacy.ticketmaster.com/en/our-
`
`12
`CLASS ACTION COMPLAINT
`
`1
`2
`3
`4
`5
`6
`7
`8
`9
`10
`11
`12
`13
`14
`15
`16
`17
`18
`19
`20
`21
`22
`23
`24
`25
`26
`27
`28
`
`
`
`Clarkson Law Firm, P.C. | 22525 Pacific Coast Highway, Malibu, CA 90265 | P: (213) 788-4050 F: (213) 788-4070 | clarksonlawfirm.com
`
`
`
`

`

`Case 2:24-cv-04482-SPG-MAA Document 1 Filed 05/29/24 Page 15 of 37 Page ID #:15
`
`
`
`failed to take appropriate steps to protect the PII of Plaintiffs and other Class Members
`from being disclosed.
`B. Defendants Failed to Comply with FTC Guidelines
`56. Defendants were prohibited by the Federal Trade Commission Act (the
`“FTC Act”) (15 U.S.C. § 45) from engaging in “unfair or deceptive acts or practices in
`or affecting commerce.” The Federal Trade Commission (the “FTC”) has concluded that
`a company’s failure to maintain reasonable and appropriate data security for consumers’
`sensitive personal information is an “unfair practice” in violation of the FTC Act. See,
`e.g., FTC v. Wyndham Worldwide Corp., 799 F.3d 236 (3d Cir. 2015).
`57. The FTC has promulgated numerous guides for businesses which highlight
`the importance of implementing reasonable data security practices. According to the
`FTC, the need for data security should be factored into all business decision-making.
`In 2016, the FTC updated its publication, Protecting Personal Information: A
`58.
`Guide for Business, which established cyber-security guidelines for businesses. The
`guidelines note that businesses should protect the personal customer information that they
`keep; properly dispose of personal information that is no longer needed; encrypt
`information stored on computer networks; understand their network’s vulnerabilities; and
`implement policies to correct any security problems.17 The guidelines also recommend
`that businesses use an intrusion detection system to expose a breach as soon as it occurs;
`monitor all incoming traffic for activity indicating someone is attempting to hack the
`system; watch for large amounts of data being transmitted from the system; and have a
`response plan ready in the event of a breach.18
`
`17 Protecting Personal Information: A Guide for Business, FEDERAL TRADE COMMISSION
`(Oct.
`2016),
`https://www.ftc.gov/business-guidance/resources/protecting-personal-
`information-guide-business.
`18 Id.
`
`13
`CLASS ACTION COMPLAINT
`
`1
`2
`3
`4
`5
`6
`7
`8
`9
`10
`11
`12
`13
`14
`15
`16
`17
`18
`19
`20
`21
`22
`23
`24
`25
`26
`27
`28
`
`
`
`Clarkson Law Firm, P.C. | 22525 Pacific Coast Highway, Malibu, CA 90265 | P: (213) 788-4050 F: (213) 788-4070 | clarksonlawfirm.com
`
`
`
`

`

`Case 2:24-cv-04482-SPG-MAA Document 1 Filed 05/29/24 Page 16 of 37 Page ID #:16
`
`
`
`59. The FTC further recommends that companies not maintain PII longer than is
`needed for authorization of a transaction; limit access to sensitive data; require complex
`passwords to be used on networks; use industry-tested methods for security; monitor for
`suspicious activity on the network; and verify that third-party service providers have
`implemented reasonable security measures.
`60. The FTC has brought enforcement actions against businesses for failing to
`adequately and reasonably protect customer data, treating the failure to employ
`reasonable and appropriate measures to protect against unauthorized access to
`confidential consumer data as an unfair act or practice prohibited by Section 5 of the
`Federal Trade Commission Act (“FTCA”), 15 U.S.C. § 45. Orders resulting from these
`actions further clarify the measures businesses must take to meet their data security
`obligations.
`61. These FTC enforcement actions include actions agai

This document is available on Docket Alarm but you must sign up to view it.


Or .

Accessing this document will incur an additional charge of $.

After purchase, you can access this document again without charge.

Accept $ Charge
throbber

Still Working On It

This document is taking longer than usual to download. This can happen if we need to contact the court directly to obtain the document and their servers are running slowly.

Give it another minute or two to complete, and then try the refresh button.

throbber

A few More Minutes ... Still Working

It can take up to 5 minutes for us to download a document if the court servers are running slowly.

Thank you for your continued patience.

This document could not be displayed.

We could not find this document within its docket. Please go back to the docket page and check the link. If that does not work, go back to the docket and refresh it to pull the newest information.

Your account does not support viewing this document.

You need a Paid Account to view this document. Click here to change your account type.

Your account does not support viewing this document.

Set your membership status to view this document.

With a Docket Alarm membership, you'll get a whole lot more, including:

  • Up-to-date information for this case.
  • Email alerts whenever there is an update.
  • Full text search for other cases.
  • Get email alerts whenever a new case matches your search.

Become a Member

One Moment Please

The filing “” is large (MB) and is being downloaded.

Please refresh this page in a few minutes to see if the filing has been downloaded. The filing will also be emailed to you when the download completes.

Your document is on its way!

If you do not receive the document in five minutes, contact support at support@docketalarm.com.

Sealed Document

We are unable to display this document, it may be under a court ordered seal.

If you have proper credentials to access the file, you may proceed directly to the court's system using your government issued username and password.


Access Government Site

We are redirecting you
to a mobile optimized page.





Document Unreadable or Corrupt

Refresh this Document
Go to the Docket

We are unable to display this document.

Refresh this Document
Go to the Docket