Central Tickets Exposed 687,732 UK Records with Unsalted SHA-1 Password Hashes
HEROIC analysts found that Central Tickets, a United Kingdom ticketing platform operating at centraltickets.co.uk, suffered a database breach that exposed 687,732 records, leaked on July 1, 2024. The compromised data includes email addresses, IP addresses, phone numbers, first names, last names, and password hashes stored using unsalted SHA-1. The combination of full contact details and crackable password hashes makes this one of the more operationally dangerous breach profiles in the entertainment sector.
Why This Is Dangerous
Unsalted SHA-1 password hashes can be reversed at scale using precomputed rainbow tables, which already exist for billions of common passwords. Unlike salted hashes that require individual cracking per record, unsalted SHA-1 allows attackers to crack millions of hashes simultaneously by comparing them against a single precomputed table. This means a significant portion of the 687,732 password hashes in this breach may already be cracked within hours of the data being obtained, giving attackers immediate access to plaintext credentials.
What Was Exposed
- Email addresses
- IP addresses
- Phone numbers
- First names
- Last names
- Password hashes (unsalted SHA-1)
Why This Matters
This breach delivers a complete personal profile for each victim: full name, email, phone number, IP address, and a crackable password. Attackers who crack the SHA-1 hashes gain credentials that can be immediately tested across email providers, banking portals, and other ticketing platforms through credential stuffing. Phone numbers and email addresses together enable SIM-swap attacks and targeted phishing. The combination supports account takeover, identity theft, and financial fraud at significant scale across 687,732 affected individuals in the United Kingdom.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to the server-side data store of a web application. Typical attack vectors include SQL injection vulnerabilities, stolen administrative credentials, misconfigured database access controls, and unpatched application software. Once inside, attackers export user tables containing all stored customer records. The data is subsequently sold or published on hacking forums, often emerging publicly weeks or months after the original exfiltration as the data is monetized through underground markets.
Check If You Are Affected
HEROIC provides a free identity scanner that checks your email address against a database of over 400 billion compromised records, including the Central Tickets breach. Visit heroic.com to scan your email address at no cost. If your data appeared in this breach, you will be notified immediately so you can change your password and secure your accounts before attackers act on the cracked credentials.
Breach Breakdown
687,732 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds