Cyber Threat Actor: IsHaKdZ
| Actor Type | Location | Known Incidents |
Criminal
|
Turkey
|
1 incident |
|---|
Profile
The threat actor known as IsHaKdZ, also referred to by that alias, has been publicly linked to a cyber incident targeting Ticketfly in May 2018. Open‑source reporting indicates the actor is based in Turkey. During the incident IsHaKdZ contacted Ticketfly employees, reported a vulnerability in the company’s website and requested a payment of one bitcoin for protection. When the ransom was not paid, the actor exploited the vulnerability to gain access to Ticketfly’s systems.
The actor defaced the Ticketfly site with an image of V from V for Vendetta and a message claiming responsibility. IsHaKdZ asserted possession of a complete database containing names, addresses, email addresses and phone numbers of customers and venue employees. The stolen data was reportedly stored in spreadsheet files that were shared with journalists as proof of the breach. IsHaKdZ also threatened to release an additional “backstage” dataset if further demands were not met. Ticketfly responded by taking all of its systems offline for forensic investigation and notified users that some client and customer information was believed to be compromised. With the website unavailable, venues were forced to use printed guest lists and required attendees to present photo IDs or the original credit card used for purchase plus a note from the ticket buyer. Eventbrite, the parent company, engaged third‑party forensic experts to restore services and stated that the security of client and customer data remained its top priority. No malware families, specific tooling or exploit code were described in the available sources, and the actor’s methods appear limited to web‑application vulnerability exploitation and data theft. Public investigations have not attributed the actor to any state sponsor or criminal consortium, and no other campaigns have been publicly attributed to IsHaKdZ beyond the Ticketfly incident. The incident caused significant operational disruption for Ticketfly’s customers and partner venues while highlighting the risks of unpatched web vulnerabilities.
