Home/Incidents/Tixel

Tixel

29 Aug 2026 · National · Media & Entertainment
Supply Chain Attack HIGH ✓ Verified

What happened

Melbourne-based ticket resale platform Tixel notified users of a cybersecurity incident resulting from a zero-day SQL injection vulnerability (CVE-2026-72898) in its third-party analytics vendor, Metabase. The vulnerability permitted unauthorized access to a Metabase application database, exposing customer email addresses and mobile phone numbers. Tixel confirmed that core internal infrastructure, accounts, passwords, payment processing details, credit card numbers, and ticket transaction histories remained uncompromised. Tixel rotated connection API keys, revoked unauthorized connections, patched the software instance, and issued customer warnings regarding potential phishing and scam campaigns.

Incident details

Organisation
Tixel
Date
29 Aug 2026
Attack type
Supply Chain Attack
Severity
HIGH
Sector
Media & Entertainment
State
National
Records affected
Unknown
Threat actor
Unknown

Source

7news.com.au ↗
← Back to all incidents