Full Report
Group-IB discovers a sophisticated multi-layered scam scheme targeting fans with fake ticket sales on two fronts: social network platforms and fraudulent websites impersonating official distributors.
Analysis Summary
# Incident Report: Sophisticated Multi-Layered Ticket Scam Campaign
## Executive Summary
Group-IB discovered a highly coordinated, multi-layered scam campaign targeting high-profile concert attendees (specifically fans of Celine Dion) through fraudulent ticket sales. The attackers utilized a two-pronged approach: social media advertising to build trust and sophisticated phishing websites that impersonated official distributors like Ticketmaster and AXS. The operation resulted in the theft of personal information and financial credentials through a refined checkout process hosted on compromised or fraudulent e-commerce platforms.
## Incident Details
- **Discovery Date:** July 2024 (based on report publication)
- **Incident Date:** Ongoing (detected actively throughout 2024)
- **Affected Organization:** Various ticket distributors (Impersonated: Ticketmaster, AXS, La Défense Arena)
- **Sector:** Entertainment / E-commerce
- **Geography:** Global, with a focus on France and English-speaking fans.
## Timeline of Events
### Initial Access
- **Date/Time:** Variable (Campaign active during peak concert sales)
- **Vector:** Social Engineering / Malvertising
- **Details:** Attackers launched targeted advertisements on social networks (Facebook, X, Instagram) promoting "exclusive" or "last-minute" tickets. These ads led users to sophisticated landing pages.
### Lateral Movement
- **Details:** N/A. This was an external scam campaign; the attackers did not move laterally through a corporate network but instead moved victims across different fraudulent subdomains to simulate a legitimate purchasing flow.
### Data Exfiltration/Impact
- **Details:** Victims entered PII (names, addresses, phone numbers) and highly sensitive financial data (credit card numbers, CVVs) into fraudulent checkout forms.
### Detection & Response
- **How it was discovered:** Group-IB’s Digital Risk Protection systems identified a cluster of fraudulent domains using similar infrastructure and Shopify configurations.
- **Response actions taken:** Domain monitoring, reporting of fraudulent Shopify IDs, and public dissemination of Indicators of Compromise (IoCs) to alert financial institutions and fans.
## Attack Methodology
- **Initial Access:** Social media advertisements and SEO poisoning.
- **Persistence:** Use of legitimate e-commerce frameworks (Shopify) to maintain functional storefronts.
- **Defense Evasion:** Use of multiple subdomains and "State OAuth" tokens to make the URL redirects appear like legitimate authentication flows.
- **Credential Access:** Phishing via fraudulent checkout forms (Direct theft of CC details).
- **Discovery:** Scammers monitored official concert dates and sell-out statuses to time their ads for maximum impact.
- **Collection:** Harvesting of user data via web forms.
- **Impact:** Financial theft and unauthorized use of consumer credit cards.
## Impact Assessment
- **Financial:** Significant individual losses; total aggregate cost estimated in the tens of thousands of dollars based on the volume of active domains.
- **Data Breach:** High-volume theft of PII and PCI-DSS regulated data.
- **Operational:** N/A (External scam).
- **Reputational:** Damage to the impersonated brands (Ticketmaster, Celine Dion official site) due to customer dissatisfaction and loss of trust.
## Indicators of Compromise
**Phishing Domains (Defanged):**
- hxxps://celinedion-paris[.]com/
- hxxps://celine-dion-arena[.]com/
- hxxps://ticketmaster-celinedion[.]fr/
- hxxps://billeteriecelinedion[.]com/en/
- hxxps://celinedion-parisladefense-arena[.]com/
- hxxps://celinedion-france[.]com/
**Shopify Customer IDs:**
- a53f5577-962a-4b5c-96cd-03e498fb55d5
- 96d99313-0cf3-46ba-948f-066e2979c652
- 4983cefd-9810-444e-9eb0-64b4933878eb
- 7e7dbd4b-c5a9-4d4e-af60-64fd673ea525
## Response Actions
- **Containment:** Flagging of identified Shopify accounts for termination.
- **Eradication:** Requesting takedowns for the identified phishing domains.
- **Recovery:** Advising victims to contact their banks for card replacement and fraud dispute.
## Lessons Learned
- **Refined Tactics:** Scammers are moving away from "cheap" looking sites to high-fidelity clones using professional e-commerce tools like Shopify to increase their success rate.
- **Social Trust:** The use of social media ads creates a false sense of legitimacy, bypasses traditional email spam filters, and targets users when their guard is down.
- **Infrastructure Reuse:** The presence of shared OAuth states and Shopify IDs across different domains suggests a centralized "scam-as-a-service" or a single highly organized group.
## Recommendations
- **For Consumers:** Always verify the URL before entering payment info. Use official links provided on the artist's verified social media profiles (blue checkmark).
- **For Organizations:** Implement proactive Digital Risk Protection (DRP) to monitor for domain typosquatting and brand impersonation.
- **For Platforms:** Enhanced vetting for advertisers promoting high-demand event tickets on social media platforms.