Menu
Browse

Euro Cup Tickets Reseller

Primary URL Location Industry
eurocuptickets[.]com
Country
Retail Icon
Retail
Profile

Euro Cup Tickets Reseller operates as a ticket reseller that focuses on providing access to major international sporting events. The organisation runs online platforms where customers can purchase tickets for competitions such as the European Championship and the Olympic Games. Its core service involves listing inventory, processing payments, and delivering tickets electronically or via physical distribution. The websites rely on standard web technologies, including JavaScript libraries, to enable interactive features and checkout functionality.

According to the disclosed security incident, the organisation maintains at least two affiliated websites that were compromised in the attack. These affiliated sites are part of the same ticket‑selling infrastructure and share underlying code components. The infection was discovered on both platforms, indicating a shared vulnerability across the organisation’s web presence. No explicit figures regarding employee count, annual revenue, or geographic reach are provided in the source material.

The distinguishing characteristic of Euro Cup Tickets Reseller in this context is its reliance on third‑party JavaScript libraries, specifically a modified version of the Slippry library, which attackers exploited to insert a MageCart skimmer. The skimmer was designed to activate on pages containing payment‑related keywords, capture card details during checkout, and transmit the data to an attacker‑controlled domain. This method allowed the malicious code to remain hidden for extended periods—over seven weeks on one site and approximately two weeks on the other—before detection. The incident highlights the organisation’s exposure to client‑side supply‑chain risks despite its primary focus on ticket distribution.

Security researchers identified the compromise on 2019‑12‑03 and attempted to notify the operator through email and live‑chat channels. The operator initially delayed remediation, allowing the skimmer to continue exfiltrating payment information during the active period. Eventually, the malicious code was removed and the affected sites were secured, mitigating further data loss. No information about the organisation’s ownership, parent company, or subsidiary structure is available in the provided sources.

Incidents
Linked incidents available to members
1 incident