Skip to content
Back to Blog
medium severity August 29, 2026 · 4 min read Unverified claim — what this is

Tixel data breach: your email and mobile number may have been accessed

If you are a customer of Tixel, here’s what is being claimed, and what it would mean for you.

Tixel emailed customers on 28 August 2026 to say their email address and mobile number may have been accessed after an incident at its analytics provider, Metabase. Passwords, payment details, tickets and purchase history were not affected. The real risk is scam texts and emails that look as if they come from Tixel.

— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Tixel data breach: your email and mobile number may have been accessed

On the night of Friday 28 August 2026, Tixel, a Melbourne-based marketplace for second-hand event tickets, emailed customers to say their email address and mobile number may have been accessed in a security incident. Tixel said passwords, credit card details, payment information and purchase history were not affected, and that accounts — including any tickets or listings — were unaffected.

Watch Tixel

Get alerted the next time Tixel files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.

We’ll email you only about Tixel’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.

Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals — $499/mo or $4,990/yr.

Tixel said this started with Metabase, a company it uses for analytics, which was briefly reached by an unauthorised party. Metabase has said that on 3 August 2026 an attacker used a previously unknown weakness in its cloud service to get in, and that it then blocked that path and issued a fix. Tixel has not said how many of its customers were involved, or whether every customer was affected.

What “no cards, no passwords” does not tell you

The official account of this incident leads with relief: your card was not taken, your password was not taken, the tickets in your account are still yours. That is true. It is also the part that makes this sound like nothing happened to you.

What an unauthorised party may now hold is more ordinary than a card number, and more useful to a scammer. It is an email address and a mobile number that belong to someone who buys or sells tickets. That is enough to send you a text about a gig you actually have on the books, or an email about a listing you really did put up. The message will not feel like random junk, because it is aimed at a service you use and delivered to contact details that are genuinely yours.

Tixel itself told customers to watch for spam and fake messages pretending to be from Tixel, and said it would never ask for a password or payment details by email or text. That warning is the practical story. The payment details were not the prize. A click, or a code you type into the wrong place, is.

One honest limit: Tixel said details may have been accessed, not that a list of customers has been published. There is no public roll-call, and no figure for how many Tixel customers were involved. Not getting the email does not prove you were spared. Getting it does not mean your details are sitting on the open internet. Treat the pair as if it could be in someone else’s hands. There is no reliable lookup that can confirm otherwise.

What to actually expect

  • Emails or texts that look like they come from Tixel — about tickets, a refund, a listing, or a locked account — asking you to click a link or reply with a code. Tixel has said it will never ask for a password or payment details by email or text.
  • More ordinary spam and scam texts to the mobile number you gave Tixel, including messages that never mention Tixel at all. The underlying incident began in early August, weeks before customers were emailed, so those messages may already have started.
  • No change to tickets or listings already in your account, and no charges appearing because someone used a card stored with Tixel. The company has said that information was not part of this incident.
  • No letter, public list, or search that can tell you whether your own email and mobile were among those accessed. Tixel has not published a number, and that kind of confirmation is rarely available.

What you can and cannot fix

If your email address and mobile number were accessed, that cannot be undone. Those two details cannot be recalled from whoever reached them, and they cannot be removed from the incident. Changing your Tixel password does not take an email address or a phone number back.

  • Treat unexpected Tixel messages as fake. Do not click links in emails or texts about tickets. If you need to check an order, open the Tixel app or type the website address yourself.
  • Watch that same email and phone on other accounts. Banks, email providers and social apps often use that pair to reset a password. An unexpected reset text or “was this you?” prompt is the near-term way this kind of incident gets used beyond tickets. Do not approve a reset you did not start, and switch on extra login checks where the account offers them.
  • You do not need to cancel cards because of this incident as Tixel described it. Payment information and purchase history were not the records it said were reached.
  • Cut back what is already published about you elsewhere. A bare leaked record — here, an email and a mobile number — becomes more dangerous when it is joined to people-search listings that add relatives, extra phone numbers, employers and previous addresses. Unlike the Tixel data, those listings can often actually be taken down. That is one of the few parts of this you still control.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
Tixel is one listing. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity Medium contact details only, none of them permanent
Disclosed August 29, 2026
Last reviewed August 29, 2026
Affected Unconfirmed
Data exposed Email addressesMobile numbers
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email