`
`CLARKSON LAW FIRM, P.C.
`Ryan J. Clarkson (SBN 257074)
`rclarkson@clarksonlawfirm.com
`Yana Hart (SBN 306499)
`yhart@clarksonlawfirm.com
`Tiara Avaness (SBN 343928)
`tavaness@clarksonlawfirm.com
`22525 Pacific Coast Highway
`Malibu, CA 90265
`Tel: (213) 788-4050
`Fax: (213) 788-4070
`
`Counsel for Plaintiffs and the Proposed Classes
`
`UNITED STATES DISTRICT COURT
`CENTRAL DISTRICT OF CALIFORNIA
`
`CYNTHIA RYAN and ROSALIA
`GARCIA, on behalf of themselves and all
`others who are similarly situated,
`Plaintiffs,
`
`v.
`TICKETMASTER, LLC., and LIVE
`NATION ENTERTAINMENT, INC.
`Defendants.
`
`2:24-cv-4482
`Case No.
`CLASS ACTION COMPLAINT
`1. NEGLIGENCE
`2. NEGLIGENCE PER SE
`
`3. BREACH OF FIDUCIARY
`DUTY
`
`4. UNJUST ENRICHMENT
`
`5. BREACH OF IMPLIED
`CONTRACT
`
`6. VIOLATION OF THE
`CALIFORNIA CONSUMER
`PRIVACY ACT OF 2018 Cal.
`Civ. Code §§ 1798.100 et seq.
`(“CCPA”)
`
`7. VIOLATION OF THE
`CALIFORNIA CONSUMER
`
`CLASS ACTION COMPLAINT
`
`1
`2
`3
`4
`5
`6
`7
`8
`9
`10
`11
`12
`13
`14
`15
`16
`17
`18
`19
`20
`21
`22
`23
`24
`25
`26
`27
`28
`
`Clarkson Law Firm, P.C. | 22525 Pacific Coast Highway, Malibu, CA 90265 | P: (213) 788-4050 F: (213) 788-4070 | clarksonlawfirm.com
`
`
`
`Case 2:24-cv-04482-SPG-MAA Document 1 Filed 05/29/24 Page 2 of 37 Page ID #:2
`
`
`
`LEGAL REMEDIES ACT Cal.
`Civ. Code §§ 1750 et seq.
`(“CLRA”)
`
`8. VIOLATION OF THE
`CALIFORNIA UNFAIR
`COMPETITION LAW Cal.
`Bus. and Prof. Code §§ 17200,
`et seq. (“UCL”)
`
`DEMAND FOR JURY TRIAL
`
`
`CLASS ACTION COMPLAINT
`
`1
`2
`3
`4
`5
`6
`7
`8
`9
`10
`11
`12
`13
`14
`15
`16
`17
`18
`19
`20
`21
`22
`23
`24
`25
`26
`27
`28
`
`
`
`
`
`Clarkson Law Firm, P.C. | 22525 Pacific Coast Highway, Malibu, CA 90265 | P: (213) 788-4050 F: (213) 788-4070 | clarksonlawfirm.com
`
`
`
`
`
`Case 2:24-cv-04482-SPG-MAA Document 1 Filed 05/29/24 Page 3 of 37 Page ID #:3
`
`
`
`CLASS ACTION COMPLAINT
`Plaintiffs Cynthia Ryan and Rosalia Garcia (collectively, “Plaintiffs”)
`individually and on behalf of all others similarly situated, bring this Class Action
`Complaint (the “Complaint”), and allege
`the following against Defendants
`Ticketmaster, LLC (“Ticketmaster”) and Live Nation Entertainment, Inc. (“Live
`Nation”) (collectively, “Defendants”), based upon personal knowledge with respect to
`themselves and upon information and belief derived from, among other things,
`investigation of counsel and review of public documents as to all other matters.
`NATURE OF THE ACTION
`Plaintiffs bring this class action against Defendants for their failure to
`1.
`properly secure and safeguard Plaintiffs’ and other similar situated individuals’ personal
`identifiable information (“PII”), including but not limited to “full names, addresses,
`email addresses, phone numbers, ticket sales and event details, order information, and
`partial payment card data. [The] compromised payment data includes customer names,
`the last four digits of card numbers, expiration dates, and even customer fraud details”
`(collectively, “Private Information”).1
`2. This class action arises out of the recent targeted cyberattack against
`Ticketmaster that enabled a third party to access Defendants’ computer systems and data,
`resulting in the compromise of highly sensitive Private Information (the “Data
`Breach”).2
`3. Due to the Data Breach, Plaintiffs and Class Members suffered ascertainable
`losses in the form of the benefit of their bargain, out-of-pocket expenses and the value of
`their time reasonably incurred to remedy or mitigate the effects of the attack, emotional
`
`
`1 Waqas, Hackers Claim Ticketmaster Data Breach: 560M Users’ Info for Sale at $500k,
`HACKREAD (May 29, 2024), https://hackread.com/hackers-ticketmaster-data-breach-
`560m-users-sale/.
`2 Id.
`
`1
`CLASS ACTION COMPLAINT
`
`1
`2
`3
`4
`5
`6
`7
`8
`9
`10
`11
`12
`13
`14
`15
`16
`17
`18
`19
`20
`21
`22
`23
`24
`25
`26
`27
`28
`
`
`
`Clarkson Law Firm, P.C. | 22525 Pacific Coast Highway, Malibu, CA 90265 | P: (213) 788-4050 F: (213) 788-4070 | clarksonlawfirm.com
`
`
`
`
`
`Case 2:24-cv-04482-SPG-MAA Document 1 Filed 05/29/24 Page 4 of 37 Page ID #:4
`
`
`
`distress, and the imminent risk of future harm caused by the compromise of their Private
`Information.
`4. The Data Breach was a direct result of Defendants’ failure to implement
`adequate and reasonable cybersecurity procedures and protocols necessary to protect
`consumers’ Private Information.
`5. On or around May 28, 2024, the Private Information of 560,000,000
`Ticketmaster customers was compromised and listed for sale.3 The notorious hacker
`group known only by its alias “ShinyHunters” claimed that it had stolen 1.3 terabytes of
`personal data and is reportedly ready to sell, or has already sold, such information to
`nefarious dark web users for $500,000, as illustrated by their post on BreachForums, a
`dark-web marketplace for stolen data:
`
`6. This Data Breach occurred because Ticketmaster enabled an unauthorized
`third party to gain access to and obtain former and current Ticketmaster customers’
`Private Information from Ticketmaster’s internal computer systems.4
`7. As of May 29, 2024, Defendants have not released a statement nor notified
`its customers that their Private Information has been compromised and is likely in the
`
`
`3 Georgie Hewson, Home Affairs Department confirms cyber incident impacting
`Ticketmaster customers, ABC NEWS (May 29, 2024), https://www.abc.net.au/news/2024-
`05-29/ticketmaster-hack-allegedlyshinyhunter-customers-data-leaked/103908614.
`4 Id.
`
`2
`CLASS ACTION COMPLAINT
`
`1
`2
`3
`4
`5
`6
`7
`8
`9
`10
`11
`12
`13
`14
`15
`16
`17
`18
`19
`20
`21
`22
`23
`24
`25
`26
`27
`28
`
`
`
`Clarkson Law Firm, P.C. | 22525 Pacific Coast Highway, Malibu, CA 90265 | P: (213) 788-4050 F: (213) 788-4070 | clarksonlawfirm.com
`
`
`
`
`
`Case 2:24-cv-04482-SPG-MAA Document 1 Filed 05/29/24 Page 5 of 37 Page ID #:5
`
`
`
`hands of threat actors. Ticketmaster consumers are in the dark, unaware that their Private
`Information may be used to effectuate identity theft, phishing scams, plunging credit
`scores and related cybercrimes.
`8. The Data Breach was a direct result of Defendants’ failure to implement
`adequate and reasonable cybersecurity procedures and protocols, consistent with the
`industry standard, necessary to protect Private Information from the foreseeable threat of
`a cyberattack.
`9. By acquiring Plaintiffs’ and class members’ Private Information for their
`own pecuniary benefit, Defendants assumed a duty to Plaintiffs and Class Members to
`implement and maintain reasonable and adequate security measures to secure, protect,
`and safeguard Plaintiffs’ and Class Members’ Private Information against unauthorized
`access and disclosure.
`10. Defendants also had a duty to adequately safeguard this Private Information
`under controlling case law, as well as pursuant to industry standards and duties imposed
`by statutes, including Section 5 of the Federal Trade Commission Act (the “FTC Act”).
`11. Defendants breached those duties and disregarded the rights of Plaintiffs and
`the Class Members by intentionally, willfully, recklessly, or negligently failing to
`implement proper and reasonable measures to safeguard consumers’ Private Information;
`failing to take available and necessary steps to prevent unauthorized disclosure of data;
`and failing to follow applicable, required, and proper protocols, policies, and procedures
`regarding the encryption of data.
`12. As a result of Defendants’ inadequate security and breach of their duties and
`obligations, the Private Information of Plaintiffs and Class Members was compromised
`through disclosure to an unauthorized criminal third party. Plaintiffs and Class Members
`have suffered injuries as a direct and proximate result of Defendants’ conduct. These
`injuries include: (i) diminution in value and/or lost value of Private Information, a form
`of property that Defendants obtained from Plaintiffs and Class Members; (ii) out-of-
`
`3
`CLASS ACTION COMPLAINT
`
`1
`2
`3
`4
`5
`6
`7
`8
`9
`10
`11
`12
`13
`14
`15
`16
`17
`18
`19
`20
`21
`22
`23
`24
`25
`26
`27
`28
`
`
`
`Clarkson Law Firm, P.C. | 22525 Pacific Coast Highway, Malibu, CA 90265 | P: (213) 788-4050 F: (213) 788-4070 | clarksonlawfirm.com
`
`
`
`
`
`Case 2:24-cv-04482-SPG-MAA Document 1 Filed 05/29/24 Page 6 of 37 Page ID #:6
`
`
`
`pocket expenses associated with preventing, detecting, and remediating identity theft,
`social engineering, and other unauthorized use of their Private Information; (iii)
`opportunity costs associated with attempting to mitigate the actual consequences of the
`Data Breach, including but not limited to lost time; (iv) the continued, long term, and
`certain increased risk that unauthorized persons will access and abuse Plaintiffs’ and
`Class Members’ Private Information; (v) the continued and certain increased risk that the
`Private Information that remains in Defendants’ possession is subject to further
`unauthorized disclosure for so long as Defendants fail to undertake proper measures to
`protect the Private Information; (v) invasion of privacy and increased risk of fraud and
`identity theft; and (vi) theft of their Private Information and the resulting loss of privacy
`rights in that information. This action seeks to remedy these failings and their
`consequences. Plaintiffs and Class Members have a continuing interest in ensuring that
`their Private Information is and remains safe, and they should be entitled to injunctive
`and other equitable relief.
`13. Despite having been accessed and exfiltrated by unauthorized criminal
`actors, Plaintiffs’ and Class Members’ sensitive and confidential Private Information
`remains in the possession of Defendants. Absent additional safeguards and independent
`review and oversight, the information remains vulnerable to further cyberattacks and
`theft. The aggregate data compromised in the Data Breach, taken as a whole, including
`but not limited to: full names, addresses, email addresses, phone numbers, ticket sales
`and event details, order information, and partial payment card data including customer
`names, the last four digits of card numbers, expiration dates, and customer fraud details,
`increases the risk of harm, making identity theft a likely outcome.
`14. Defendants disregarded the rights of Plaintiffs and Class Members by, inter
`alia, failing to take adequate and reasonable measures to ensure their data systems were
`protected against unauthorized intrusions; failing to disclose that they did not have
`adequately robust computer systems and security practices to safeguard Private
`
`4
`CLASS ACTION COMPLAINT
`
`1
`2
`3
`4
`5
`6
`7
`8
`9
`10
`11
`12
`13
`14
`15
`16
`17
`18
`19
`20
`21
`22
`23
`24
`25
`26
`27
`28
`
`
`
`Clarkson Law Firm, P.C. | 22525 Pacific Coast Highway, Malibu, CA 90265 | P: (213) 788-4050 F: (213) 788-4070 | clarksonlawfirm.com
`
`
`
`
`
`Case 2:24-cv-04482-SPG-MAA Document 1 Filed 05/29/24 Page 7 of 37 Page ID #:7
`
`
`
`Information; failing to take standard and reasonably available steps to prevent the Data
`Breach; and failing to properly train its staff and employees on proper security measures.
`In addition, Defendants failed to properly monitor the computer network and
`15.
`systems that housed the Private Information. Had Defendants properly monitored these
`electronic systems, Defendants would have discovered the intrusion sooner or prevented
`it altogether.
`16. The security of Plaintiffs’ and Class Members’ identities is now at substantial
`risk because of Defendants’ wrongful conduct as the Private Information that Defendants
`collected and maintained are now in the hands of data thieves. This present risk will
`continue for the course of their lives.
`17. Armed with the Private Information accessed in the Data Breach, data thieves
`can commit a wide range of crimes.
`18. As a result of the Data Breach, Plaintiffs and Class Members have been
`exposed to a present and imminent risk of fraud and identity theft. Among other
`measures, Plaintiffs and Class Members must now and in the future closely monitor their
`financial accounts to guard against identity theft. Further, Plaintiffs and Class Members
`will incur out-of-pocket costs to purchase adequate credit monitoring and identity theft
`protection and insurance services, credit freezes, credit reports, or other protective
`measures to deter and detect identity theft.
`19. Plaintiffs and Class Members will also be forced to expend additional time
`to review credit reports and monitor their financial accounts for fraud or identity theft.
`And because they exposed other immutable personal details, the risk of identity theft and
`fraud will persist throughout their lives.
`20. Plaintiffs bring this lawsuit on behalf of themselves and all those similarly
`situated to address Defendants’ inadequate safeguarding of Class Members’ Private
`Information that they collected and maintained.
`
`5
`CLASS ACTION COMPLAINT
`
`1
`2
`3
`4
`5
`6
`7
`8
`9
`10
`11
`12
`13
`14
`15
`16
`17
`18
`19
`20
`21
`22
`23
`24
`25
`26
`27
`28
`
`
`
`Clarkson Law Firm, P.C. | 22525 Pacific Coast Highway, Malibu, CA 90265 | P: (213) 788-4050 F: (213) 788-4070 | clarksonlawfirm.com
`
`
`
`
`
`Case 2:24-cv-04482-SPG-MAA Document 1 Filed 05/29/24 Page 8 of 37 Page ID #:8
`
`
`
`21. Plaintiffs, on behalf of themselves and all other Class Members, bring claims
`for negligence, negligence per se, breach of implied contract, breach of fiduciary duty,
`unjust enrichment, and for declaratory and injunctive relief. To remedy these violations
`of law, Plaintiffs and Class Members thus seek actual damages, statutory damages,
`restitution, and injunctive and declaratory relief (including significant improvements to
`Defendants’ data security protocols and employee training practices), reasonable
`attorneys’ fees, costs, and expenses incurred in bringing this action, and all other
`remedies this Court deems just and proper.
`JURISDICTION AND VENUE
`22. This Court has subject matter jurisdiction over this action pursuant to the
`Class Action Fairness Act of 2005, 28 U.S.C. § 1332(d)(2), because: (i) the amount in
`controversy exceeds $5 million, exclusive of interest and costs; (ii) the number of class
`members exceeds 100 and (iii) minimal diversity exists because many class members,
`have different citizenship from Defendants.
`23. This Court has personal jurisdiction over Defendants because Defendants
`have purposefully availed themselves of the laws, rights, and benefits of the State of
`California. Defendants are headquartered in California and have engaged in activities
`including (i) directly and/or through its parent companies, affiliates and/or agents
`providing services throughout the United States in this judicial district; (ii) conducting
`substantial business in this forum; and/or (iii) engaging in other persistent courses of
`conduct and/or deriving substantial revenue from services provided in California and in
`this judicial District.
`24. Venue is proper in this Court pursuant to 28 U.S.C. § 1391(a)(1) because a
`substantial part of the events giving rise to this action occurred in this District. Moreover,
`Defendants are based in this District, maintain Plaintiffs’ and Class Members’ Private
`Information in this District, and has caused harm to Plaintiffs and Class Members in this
`District.
`
`6
`CLASS ACTION COMPLAINT
`
`1
`2
`3
`4
`5
`6
`7
`8
`9
`10
`11
`12
`13
`14
`15
`16
`17
`18
`19
`20
`21
`22
`23
`24
`25
`26
`27
`28
`
`
`
`Clarkson Law Firm, P.C. | 22525 Pacific Coast Highway, Malibu, CA 90265 | P: (213) 788-4050 F: (213) 788-4070 | clarksonlawfirm.com
`
`
`
`
`
`Case 2:24-cv-04482-SPG-MAA Document 1 Filed 05/29/24 Page 9 of 37 Page ID #:9
`
`
`
`PARTIES
`
`Plaintiff Cynthia Ryan
`25. Plaintiff Cynthia Ryan is a citizen of the State of California. At all relevant
`times, Plaintiff has resided in the county of Los Angeles, California.
`26. Since at least 2012, Plaintiff Ryan has been Defendants’ customer and
`Ticketmaster account holder. Plaintiff provided her Private Information to Defendants,
`including her credit card. In receiving and maintaining her Private Information for its
`business purposes, Defendants expressly and impliedly promised, and undertook a duty,
`to act reasonably in its handling of Plaintiff Ryan’s Private Information. Defendants,
`however, did not take proper care of Plaintiff Ryan’s Private Information, leading to its
`exposure to and exfiltration by cybercriminals as a direct result of Defendants’
`inadequate cybersecurity measures.
`27. Plaintiff Ryan is deeply concerned by the Data Breach because she and her
`family frequently use Ticketmaster to purchase concert tickets. Plaintiff Ryan continues
`to worry about her Private Information, as it is readily available for cybercriminals to
`sell, buy, and exchange, on the Dark Web.
`28. Since learning about the Data Breach, Plaintiff anticipates needing to spend
`substantial time to determine the extent and gravity of the Data Breach and to mitigate
`damages. Plaintiff will need to review for fraudulent activity and closely monitor her
`financial information.
`29. Plaintiff Ryan suffers a substantially increased risk of fraud, identity theft,
`and data misuse resulting from her Private Information being leaked on to the Dark Web
`and subjected to unauthorized third parties/criminals.
`30. Plaintiff Ryan has a continuing interest in ensuring that her Private
`Information, which remains in Defendants’ possession, is protected and safeguarded
`from future breaches.
`
`7
`CLASS ACTION COMPLAINT
`
`1
`2
`3
`4
`5
`6
`7
`8
`9
`10
`11
`12
`13
`14
`15
`16
`17
`18
`19
`20
`21
`22
`23
`24
`25
`26
`27
`28
`
`
`
`Clarkson Law Firm, P.C. | 22525 Pacific Coast Highway, Malibu, CA 90265 | P: (213) 788-4050 F: (213) 788-4070 | clarksonlawfirm.com
`
`
`
`
`
`Case 2:24-cv-04482-SPG-MAA Document 1 Filed 05/29/24 Page 10 of 37 Page ID #:10
`
`
`
`Plaintiff Rosalia Garcia
`31. Plaintiff Rosalia Garcia is a citizen of the State of California. At all relevant
`times, Plaintiff Garcia has resided in the county of Los Angeles, California.
`32. Since at least 2019, Plaintiff Garcia has been Defendants’ customer and
`Ticketmaster account holder. Plaintiff provided her Private Information to Defendants.
`In receiving and maintaining her Private Information for its business purposes,
`Defendants expressly and impliedly promised, and undertook a duty, to act reasonably in
`its handling of Plaintiff Garcia’s Private Information. Defendants, however, did not take
`proper care of Plaintiff Garcia’s Private Information, leading to its exposure to and
`exfiltration by cybercriminals as a direct result of Defendants’ inadequate cybersecurity
`measures.
`33. Plaintiff Garcia is deeply concerned by the Data Breach because she
`frequently uses Ticketmaster to purchase tickets. Plaintiff Garcia continues to worry
`about her Private Information, as it is readily available for cybercriminals to sell, buy,
`and exchange, on the Dark Web.
`34. Since learning about the Data Breach, Plaintiff anticipates needing to spend
`substantial time to determine the extent and gravity of the Data Breach and to mitigate
`damages. Plaintiff will need to review for fraudulent activity and closely monitor her
`financial information.
`35. Plaintiff Garcia suffers a substantially increased risk of fraud, identity theft,
`and data misuse resulting from her Private Information being leaked onto the Dark Web
`and subjected to unauthorized third parties/criminals.
`36. Plaintiff Garcia has a continuing interest in ensuring that her Private
`Information, which remains in Defendants’ possession, is protected and safeguarded
`from future breaches.
`
`8
`CLASS ACTION COMPLAINT
`
`1
`2
`3
`4
`5
`6
`7
`8
`9
`10
`11
`12
`13
`14
`15
`16
`17
`18
`19
`20
`21
`22
`23
`24
`25
`26
`27
`28
`
`
`
`Clarkson Law Firm, P.C. | 22525 Pacific Coast Highway, Malibu, CA 90265 | P: (213) 788-4050 F: (213) 788-4070 | clarksonlawfirm.com
`
`
`
`
`
`Case 2:24-cv-04482-SPG-MAA Document 1 Filed 05/29/24 Page 11 of 37 Page ID #:11
`
`
`
`Defendant Ticketmaster, LLC.
`37. Defendant Ticketmaster, LLC. is a wholly owned subsidiary of Defendant
`Live Nation Entertainment, Inc. headquartered in California with its principal executive
`office located at 9348 Civic Center Drive, Beverly Hills, CA 90210.
`38. Ticketmaster and Live Nation Entertainment completed their merger on
`January 25, 2010.5
`39. Ticketmaster “operates as a ticket distribution company. [Ticketmaster]
`buys, transfers, and sells tickets for live music, sporting, arts, theater, and family events.
`Ticketmaster serves clients worldwide.”6
`40. Plaintiffs and Class Members are current and former customers of
`Ticketmaster and account holders on Ticketmaster.com.
`41. Due to the nature of the services Ticketmaster provides, it receives and is
`entrusted with securely storing consumers’ Private Information, which includes, inter
`alia, individuals’ full name, payment information, occasional location data, and other
`sensitive information. Ticketmaster promised to provide confidentiality and adequate
`security for the data it collected from customers through its applicable privacy policy and
`through other disclosures in compliance with statutory privacy requirements.
`Defendant Live Nation Entertainment, Inc.
`42. Defendant Live Nation Entertainment, Inc. is a Delaware corporation
`
`headquartered in California with its principal executive office located at 9348 Civic
`
`Center Drive, Beverly Hills, CA 90210.
`
`
`5 Live Nation and Ticketmaster Entertainment Complete Merger, SECURITIES AND
`EXCHANGE
`COMMISSION
`(Jan.
`25,
`2010),
`https://www.sec.gov/Archives/edgar/data/1335258/000119312510012287/dex991.htm.
`6
`LLC,
`BLOOMBERG,
`Ticketmaster
`https://www.bloomberg.com/profile/company/0009574D:US (last visited May 29,
`2024).
`
`9
`CLASS ACTION COMPLAINT
`
`1
`2
`3
`4
`5
`6
`7
`8
`9
`10
`11
`12
`13
`14
`15
`16
`17
`18
`19
`20
`21
`22
`23
`24
`25
`26
`27
`28
`
`
`
`Clarkson Law Firm, P.C. | 22525 Pacific Coast Highway, Malibu, CA 90265 | P: (213) 788-4050 F: (213) 788-4070 | clarksonlawfirm.com
`
`
`
`
`
`Case 2:24-cv-04482-SPG-MAA Document 1 Filed 05/29/24 Page 12 of 37 Page ID #:12
`
`
`
`43. Live Nation Entertainment is a publicly traded corporation listed on the New
`
`York Stock Exchange with revenues totaling approximately $3.8 billion for the three
`
`months ended on March 31, 2024.7
`
`44. Live Nation is “the largest live entertainment company in the world,
`
`connecting over 765 million fans across all of our concerts and ticketing platforms in 49
`
`countries during 2023.”8
`
`45. Due to the nature of the services Live Nation provides, it receives and is
`entrusted with securely storing consumers’ Private Information, which includes, inter
`alia, individuals’ full name, payment information, occasional location data, and other
`sensitive information. Live Nation promised to provide confidentiality and adequate
`security for the data it collected from customers through its applicable privacy policy and
`through other disclosures in compliance with statutory privacy requirements.
`FACTUAL ALLEGATIONS
`A. The Data Breach, and Defendants Unsecure Data Management.
`46. On May 28, 2024, threat actors posted that 1.4 terabytes of Private
`Information were available for purchase on the hacking website Breach Forums.9 The
`notorious hacking group ShinyHunters offered the trove of Plaintiffs’ and Class
`Members’ Private Information for $500,000.
`
`
`7 Form 10-Q Quarterly Report for Live Nation Entertainment, Inc., BAMSEC,
`https://www.bamsec.com/filing/133525824000071?cik=1335258 (last visited May 29,
`2024).
`8 Form 10-K Annual Report for Live Nation Entertainment, Inc., BAMSEC,
`https://www.bamsec.com/filing/133525824000017?cik=1335258 (last visited May 29,
`2024).
`9 Waqas, supra note 1.
`
`10
`CLASS ACTION COMPLAINT
`
`1
`2
`3
`4
`5
`6
`7
`8
`9
`10
`11
`12
`13
`14
`15
`16
`17
`18
`19
`20
`21
`22
`23
`24
`25
`26
`27
`28
`
`
`
`Clarkson Law Firm, P.C. | 22525 Pacific Coast Highway, Malibu, CA 90265 | P: (213) 788-4050 F: (213) 788-4070 | clarksonlawfirm.com
`
`
`
`
`
`Case 2:24-cv-04482-SPG-MAA Document 1 Filed 05/29/24 Page 13 of 37 Page ID #:13
`
`
`
`47. Defendants are yet to make a statement or inform consumers that their data
`is available on the dark web. Such data includes, according to the hackers’ forum post,
`“560 million customers [sic] full details (name, address, email, phone) – Ticket sales,
`event information, order details – CC [credit card] detail [sic] – customer, last 4 of card,
`expiration date. Customer fraud details – much more.”10
`48. Prior to the Data Breach in May 2024, Plaintiffs and Class Members had
`provided their Private Information to Ticketmaster with the reasonable expectation and
`mutual understanding that Ticketmaster would comply with its obligations to keep such
`information confidential and secure from unauthorized access. In particular, Plaintiffs
`and Class Members provided their names, emails, phone numbers, location data and
`credit card information to Ticketmaster in order to register for an account and purchase
`event tickets on Ticketmaster.com.
`49. PII is a valuable property right.11 “Firms are now able to attain significant
`market valuations by employing business models predicated on the successful use of
`personal data within the existing legal and regulatory frameworks.”12 It is estimated that
`American companies have spent over $19 billion on acquiring personal data of
`consumers in 2018.13 It is so valuable to identity thieves that once PII has been disclosed,
`criminals often trade it on the “cyber black-market,” or the “dark web,” for many years.
`
`
`10 Id.
`11 See Marc van Lieshout, The Value of Personal Data, 457 IFIP ADVANCES IN
`INFORMATION
`AND COMMUNICATION
`TECHNOLOGY
`26-38
`(May
`2015),
`https://www.researchgate.net/publication/283668023_
`The_Value_of_Personal_Data
`(“The value of [personal] information is well understood by marketers who try to collect
`as much data about personal conducts and preferences as possible...”).
`12 Exploring the Economics of Personal Data: A Survey of Methodologies for Measuring
`Monetary Value, OECD No. 220 (Apr. 2, 2013), https://www.oecd-ilibrary.org/science-
`and-technology/exploring-the-economics-of-personal-data_5k486qtxldmq-en.
`13 U.S. Firms to Spend Nearly $19.2 Billion on Third-Party Audience Data and Data-Use
`Solutions in 2018, Up 17.5% from 2017, INTERACTIVE ADVERTISING BUREAU (Dec. 5,
`2018), https://www.iab.com/news/2018-state-of-data-report/.
`
`11
`CLASS ACTION COMPLAINT
`
`1
`2
`3
`4
`5
`6
`7
`8
`9
`10
`11
`12
`13
`14
`15
`16
`17
`18
`19
`20
`21
`22
`23
`24
`25
`26
`27
`28
`
`
`
`Clarkson Law Firm, P.C. | 22525 Pacific Coast Highway, Malibu, CA 90265 | P: (213) 788-4050 F: (213) 788-4070 | clarksonlawfirm.com
`
`
`
`
`
`Case 2:24-cv-04482-SPG-MAA Document 1 Filed 05/29/24 Page 14 of 37 Page ID #:14
`
`
`
`Indeed, the threat actor who compromised Defendants’ systems is seeking a one-time
`payment of half a million dollars in exchange for this Private Information.
`50. Plaintiffs and the Class’s Private Information exposed in the Data Breach has
`been exposed on the Dark Web.
`51. Ticketmaster promised consumers it would keep their data secure and
`private. Data security is purportedly a critical component of Ticketmaster’s business
`model. On a section of its website, Ticketmaster confidently asserts the following
`statements:
`
`“We’re always taking steps to make sure your information is
`protected and deleted securely,” “[we] have security measure in
`place to protect your information,”14 and “[the] security of our
`fans’ information is a priority for us. We take all necessary
`security measures to protect personal information that’s shared
`and stored with us.”15
`
`52. On its website, Ticketmaster maintains an “Our Commitments” section,
`including “Security & Confidentiality” as one of “10 commitments that drive
`[Ticketmaster’s] privacy program, globally”.16
`53. Contrary to Ticketmaster’s various express assurances that it would take
`reasonable measures to safeguard the sensitive information entrusted to it, an
`“unauthorized” person or persons was able to access its network servers.
`54. To date, Ticketmaster has not disclosed complete specifics of the attack, such
`as whether ransomware has been used.
`55. As such, Ticketmaster, and its parent company Live Nation, have failed to
`secure the PII of the individuals that provided their sensitive information. Defendants
`
`
`14 Privacy Policy, TICKETMASTER, https://privacy.ticketmaster.com/privacy-policy (last
`visited May 29, 2024).
`15 Our Commitments, TICKETMASTER,
`commitments (last visited May 29, 2024).
`16 Id.
`
`https://privacy.ticketmaster.com/en/our-
`
`12
`CLASS ACTION COMPLAINT
`
`1
`2
`3
`4
`5
`6
`7
`8
`9
`10
`11
`12
`13
`14
`15
`16
`17
`18
`19
`20
`21
`22
`23
`24
`25
`26
`27
`28
`
`
`
`Clarkson Law Firm, P.C. | 22525 Pacific Coast Highway, Malibu, CA 90265 | P: (213) 788-4050 F: (213) 788-4070 | clarksonlawfirm.com
`
`
`
`
`
`Case 2:24-cv-04482-SPG-MAA Document 1 Filed 05/29/24 Page 15 of 37 Page ID #:15
`
`
`
`failed to take appropriate steps to protect the PII of Plaintiffs and other Class Members
`from being disclosed.
`B. Defendants Failed to Comply with FTC Guidelines
`56. Defendants were prohibited by the Federal Trade Commission Act (the
`“FTC Act”) (15 U.S.C. § 45) from engaging in “unfair or deceptive acts or practices in
`or affecting commerce.” The Federal Trade Commission (the “FTC”) has concluded that
`a company’s failure to maintain reasonable and appropriate data security for consumers’
`sensitive personal information is an “unfair practice” in violation of the FTC Act. See,
`e.g., FTC v. Wyndham Worldwide Corp., 799 F.3d 236 (3d Cir. 2015).
`57. The FTC has promulgated numerous guides for businesses which highlight
`the importance of implementing reasonable data security practices. According to the
`FTC, the need for data security should be factored into all business decision-making.
`In 2016, the FTC updated its publication, Protecting Personal Information: A
`58.
`Guide for Business, which established cyber-security guidelines for businesses. The
`guidelines note that businesses should protect the personal customer information that they
`keep; properly dispose of personal information that is no longer needed; encrypt
`information stored on computer networks; understand their network’s vulnerabilities; and
`implement policies to correct any security problems.17 The guidelines also recommend
`that businesses use an intrusion detection system to expose a breach as soon as it occurs;
`monitor all incoming traffic for activity indicating someone is attempting to hack the
`system; watch for large amounts of data being transmitted from the system; and have a
`response plan ready in the event of a breach.18
`
`17 Protecting Personal Information: A Guide for Business, FEDERAL TRADE COMMISSION
`(Oct.
`2016),
`https://www.ftc.gov/business-guidance/resources/protecting-personal-
`information-guide-business.
`18 Id.
`
`13
`CLASS ACTION COMPLAINT
`
`1
`2
`3
`4
`5
`6
`7
`8
`9
`10
`11
`12
`13
`14
`15
`16
`17
`18
`19
`20
`21
`22
`23
`24
`25
`26
`27
`28
`
`
`
`Clarkson Law Firm, P.C. | 22525 Pacific Coast Highway, Malibu, CA 90265 | P: (213) 788-4050 F: (213) 788-4070 | clarksonlawfirm.com
`
`
`
`
`
`Case 2:24-cv-04482-SPG-MAA Document 1 Filed 05/29/24 Page 16 of 37 Page ID #:16
`
`
`
`59. The FTC further recommends that companies not maintain PII longer than is
`needed for authorization of a transaction; limit access to sensitive data; require complex
`passwords to be used on networks; use industry-tested methods for security; monitor for
`suspicious activity on the network; and verify that third-party service providers have
`implemented reasonable security measures.
`60. The FTC has brought enforcement actions against businesses for failing to
`adequately and reasonably protect customer data, treating the failure to employ
`reasonable and appropriate measures to protect against unauthorized access to
`confidential consumer data as an unfair act or practice prohibited by Section 5 of the
`Federal Trade Commission Act (“FTCA”), 15 U.S.C. § 45. Orders resulting from these
`actions further clarify the measures businesses must take to meet their data security
`obligations.
`61. These FTC enforcement actions include actions agai



