Tixel data breach: your email and mobile number may have been accessed
If you are a customer of Tixel, here’s what is being claimed, and what it would mean for you.
Tixel emailed customers on 28 August 2026 to say their email address and mobile number may have been accessed after an incident at its analytics provider, Metabase. Passwords, payment details, tickets and purchase history were not affected. The real risk is scam texts and emails that look as if they come from Tixel.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
On the night of Friday 28 August 2026, Tixel, a Melbourne-based marketplace for second-hand event tickets, emailed customers to say their email address and mobile number may have been accessed in a security incident. Tixel said passwords, credit card details, payment information and purchase history were not affected, and that accounts — including any tickets or listings — were unaffected.
Watch Tixel
Get alerted the next time Tixel files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Tixel’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals — $499/mo or $4,990/yr.
Tixel said this started with Metabase, a company it uses for analytics, which was briefly reached by an unauthorised party. Metabase has said that on 3 August 2026 an attacker used a previously unknown weakness in its cloud service to get in, and that it then blocked that path and issued a fix. Tixel has not said how many of its customers were involved, or whether every customer was affected.
What “no cards, no passwords” does not tell you
The official account of this incident leads with relief: your card was not taken, your password was not taken, the tickets in your account are still yours. That is true. It is also the part that makes this sound like nothing happened to you.
What an unauthorised party may now hold is more ordinary than a card number, and more useful to a scammer. It is an email address and a mobile number that belong to someone who buys or sells tickets. That is enough to send you a text about a gig you actually have on the books, or an email about a listing you really did put up. The message will not feel like random junk, because it is aimed at a service you use and delivered to contact details that are genuinely yours.
Tixel itself told customers to watch for spam and fake messages pretending to be from Tixel, and said it would never ask for a password or payment details by email or text. That warning is the practical story. The payment details were not the prize. A click, or a code you type into the wrong place, is.
One honest limit: Tixel said details may have been accessed, not that a list of customers has been published. There is no public roll-call, and no figure for how many Tixel customers were involved. Not getting the email does not prove you were spared. Getting it does not mean your details are sitting on the open internet. Treat the pair as if it could be in someone else’s hands. There is no reliable lookup that can confirm otherwise.
What to actually expect
- Emails or texts that look like they come from Tixel — about tickets, a refund, a listing, or a locked account — asking you to click a link or reply with a code. Tixel has said it will never ask for a password or payment details by email or text.
- More ordinary spam and scam texts to the mobile number you gave Tixel, including messages that never mention Tixel at all. The underlying incident began in early August, weeks before customers were emailed, so those messages may already have started.
- No change to tickets or listings already in your account, and no charges appearing because someone used a card stored with Tixel. The company has said that information was not part of this incident.
- No letter, public list, or search that can tell you whether your own email and mobile were among those accessed. Tixel has not published a number, and that kind of confirmation is rarely available.
What you can and cannot fix
If your email address and mobile number were accessed, that cannot be undone. Those two details cannot be recalled from whoever reached them, and they cannot be removed from the incident. Changing your Tixel password does not take an email address or a phone number back.
- Treat unexpected Tixel messages as fake. Do not click links in emails or texts about tickets. If you need to check an order, open the Tixel app or type the website address yourself.
- Watch that same email and phone on other accounts. Banks, email providers and social apps often use that pair to reset a password. An unexpected reset text or “was this you?” prompt is the near-term way this kind of incident gets used beyond tickets. Do not approve a reset you did not start, and switch on extra login checks where the account offers them.
- You do not need to cancel cards because of this incident as Tixel described it. Payment information and purchase history were not the records it said were reached.
- Cut back what is already published about you elsewhere. A bare leaked record — here, an email and a mobile number — becomes more dangerous when it is joined to people-search listings that add relatives, extra phone numbers, employers and previous addresses. Unlike the Tixel data, those listings can often actually be taken down. That is one of the few parts of this you still control.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
Report details & sourcing
Related breaches
Privy August 2026 incident: emails were taken, crypto wallets were not
In August 2026 Privy confirmed that an attacker copied customer and end-user email addresses, plus a…
Manchester Airports Group data breach: 8.7 million customer records accessed
Manchester Airports Group has confirmed that an unauthorised party accessed customer data from airpo…
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…