‘Absolute joke’: customers’ personal data exposed amid Pandemonium Rocks festival refund stoush

Information commissioner investigating data breach as ticket holders demand refunds because of amended lineup

Kylie Gilroy was already incensed when she and her partner applied for partial refunds for this Saturday’s Pandemonium Rocks music festival on the Gold Coast. The Mackay couple had spent more than $2,000 on concert tickets, air fares and hotel accommodation for a show they no longer wanted to see, after festival organisers confirmed just over two weeks ago that seven of the 13 acts promised, including headliners Deep Purple, the Dead Kennedys, Placebo and Gang of Four, had pulled out.

But when Gilroy hit the send button on her partial refund application, which would have recouped $140 of her outlay of $516 for two tickets, her anger turned to disbelief.

The names, email addresses, mobile numbers and bank account details of more than 100 strangers filled her screen. An hour later, on the evening of 19 April, she could see the personal details of more than 500 people, including her own.

It would take festival organisers more than 90 minutes to realise what had happened – that an admin tab on the Google form they were using had been left open.

“The way that this event has been run is absolute bullshit, and we can’t do anything about it,” said Gilroy. “Nobody can do anything about it.”

Another ticket holder, Jenny, who lives on the Gold Coast, told the Guardian she thought she had become the victim of a scam when some “random guy” emailed to tell her he could see her personal details, including phone number and bank account number, online.

Jenny, who did not want her last name used, said she immediately emptied the bank account identified of all funds.

Late the following morning, Pandemonium posted a message on its Facebook page confirming a data breach took place on Friday between 5.47pm and 7.20pm.

“All people within the timeframe who filled the form will be contacted by Pandemonium directly asap to notify them that their data was made public during that window and to advise their banks to update their information,” the message said. “We are sincerely sorry for the angst this has caused.”

The four ticket holders the Guardian spoke to said they had not been contacted by the festival organisers, and none said they had received any refund.

On Pandemonium’s Facebook page, some users have described being unable to message organisers via the platform. On 22 March the organisers posted that “due to reckless reporting, and the wilful proliferation of misinformation, rumours and conspiracy surrounding the festival, we are turning comments off on our social media (for now)”.

Under the Notifiable Data Breaches scheme covered by the Australian Privacy Act, an organisation that is subject to the act and suspects a data breach may have occurred must notify the people affected and the Office of the Australian Information Commissioner (OAIC) as soon as possible.

As of Tuesday, Pandemonium’s organisers, Apex Entertainment, had not reported the breach to the commissioner.

An OAIC spokesperson told the Guardian the office was seeking further information from the company, including whether it records an annual turnover of more than $3m, which would make reporting data breaches to the commissioner mandatory.

Apex couldn’t be reached for comment.

The Pandemonium Rocks festival encompassed five concerts spread across six cities, with tickets initially ranging from $250 to $650, then dropped to $190 for a standard ticket after the sudden program change.

More than 8,000 people attended the first concert in Melbourne last Saturday, where the modified lineup included Alice Cooper, Blondie, the Psychedelic Furs and Wheatus.

The Newcastle concert, described by the organisers as a “side show”, took place on Tuesday night. The Sydney concert will be held on Thursday at Olympic Park and further events follow on the Gold Coast and in Brisbane.

NSW Fair Trading has confirmed that since 13 February it has dealt with 53 complaints about Pandemonium refunds. Queensland’s Office of Fair Trading told the Guardian it was investigating a number of consumer complaints it had received about the festival. Consumer Affairs Victoria said in a statement it “does not comment on individual businesses”.

The OFT will be in contact with the consumers as the investigation progresses.

A NSW Fair Trading spokesperson said consumers were entitled to refunds when an event organiser “chooses to cancel or makes a major change to an event”. A major change could include the headline act.

“NSW Fair Trading is thoroughly assessing all complaints received so far and has contacted Pandemonium Rocks Festival requesting response to several matters,” the statement said.

Gilroy said the offer of a $70 refund on a $258 ticket, bought on the assumption she and her partner would see Deep Purple, the Dead Kennedys and Placebo perform, was an “absolute joke”.

Multiple ticket-holders said as an alternative to a partial refund Pandemonium had offered them an additional complimentary ticket or a branded hoodie.

Contributor

Kelly Burke

The GuardianTramp

Related Content

Article image
Queensland country music festival becomes Australia’s first to offer Covid vaccines
The Savannah in the Round festival in the Cairns hinterland this weekend will feature a Covid-19 vaccination hub – headlined by Pfizer

Kelly Burke

29, Sep, 2021 @11:00 PM

Article image
‘We’re ready for anything’: Sydney festival 2022 unveils full program
Festivalgoers can choose indoor, outdoor or stay-at-home events, as mass concerts, bold installations and world-premiere theatre set to take over city in January

Kelly Burke

16, Nov, 2021 @7:00 PM

Article image
Craving a summer music festival? Here’s a state-by-state gig guide
You may not be mixing sweat with strangers in a mosh pit – but great live events are (hopefully) coming to a Covid-safe stage near you

Meg Watson

16, Nov, 2020 @4:30 PM

Article image
Perth festival 2022 prepares for opening weekend despite border closures and cancellations
Several events have been called off, while a few artists have special dispensation to enter WA after two-weeks’ quarantine

Kelly Burke

09, Feb, 2022 @4:30 PM

Article image
WA lockdown: Perth festival cancels opening night as Fringe World put on hold
In what was meant to be a time of celebration for the city, the five-day lockdown has left the local arts world in disarray again

Kelly Burke

01, Feb, 2021 @6:52 AM

Article image
Meadow: is the hyper-local micro-festival the way forward for Australian music?
Feeling very much like the opposite of lockdown, Meadow music festival might have been small but offered welcome reminders of pre-Covid life

Andy Hazel

26, Apr, 2021 @2:38 AM

Article image
Perth festival 2022 features immersive events and puts WA talent front and centre
Artistic director Iain Grandage says ocean-themed program is ‘constantly evolving’ amid Covid and border uncertainty

Kelly Burke

15, Nov, 2021 @1:19 AM

Article image
Activists angry over Perth festival Fringe World’s new deal with fossil fuel giant Woodside
Woodside has transitioned its sponsorship to ‘philanthropy’ at the festival’s parent company Artrage, which says it is ‘not in business of making political statements’

Mark Naglazas

23, Jun, 2021 @11:00 PM

Article image
Risks, refunds and cancellations: your guide to buying tickets amid Covid this summer
From Sydney, Perth and Adelaide festivals to major shows, tickets make great last-minute gifts. But they could also be a roll of the dice

Elissa Blake

22, Dec, 2021 @2:14 AM

Article image
Sydney festival to suspend foreign government funding after mass boycott
Israeli embassy funding overshadowed this year’s Sydney festival, leading to an independent review

Kelly Burke

27, Sep, 2022 @4:00 AM