Back to blog

Bad Actor, Good Quarter: A Ticketing Tech Group Filed Both on the Same Morning

TE
The eventcloud Team 10 August 2026 · 6 min read
Bad Actor, Good Quarter: A Ticketing Tech Group Filed Both on the Same Morning

There is a specific flavour of Monday that only happens at listed software companies. On 3 August, accesso Technology Group sent the market two announcements at once. One said trading was fine, guidance was intact and the new payments product had gone live. The other said somebody had been inside its systems.

Both are true. But if you run conferences, trade shows, summits or galas on somebody else's platform, the second is the more useful read. Vendor security notices are usually written in language so vague they could pass for a horoscope. This one was unusually plain, and it is a decent excuse to ask the question most organisers postpone forever: what exactly is sitting in your ticketing vendor's database, and what happens on the day someone else reads it?

What accesso actually disclosed

accesso Technology Group builds ticketing, virtual queuing, guest experience and food and beverage software for attractions, leisure venues and cultural sites. On 3 August it issued a notice confirming it had identified an IT security incident involving temporary unauthorised access to what it called a limited part of the group's systems, as reported by TheTicketingBusiness.

The access had been contained, with no downtime and no major disruption to services. accesso enacted its incident response plan, brought in external specialists and put additional precautionary measures in place. Its investigation so far indicates the systems reached held internal information about accesso's own business operations. Nothing suspicious has appeared since, the board assessed the risk of financial exposure as low, and the company said it was in touch with customers and the relevant authorities. The investigation continues.

The same morning brought the half-year trading update for the six months to 30 June: trading resilient and in line with expectations, helped by cost efficiencies taken earlier in the year. Full-year guidance held at roughly $146m of revenue and around $20m of cash EBITDA, according to Proactive Investors, with the usual second-half weighting for summer and Halloween. Chief executive Lee Cowie, who took the job earlier this year, pointed to appetite for a single connected platform spanning ticketing, retail, guest experience and queuing. Underpinning all of it: accessoPay, the group's payments capability, now live, with the first customers due to start transacting this month. Interim results land on 15 September.

The uncomfortable maths of modern event tech: every product your vendor bolts on is another room in a building where your attendees' data lives, and you are still the one who has to explain the fire.

What this means for event organisers

Start with the legal bit, because it is the part people get wrong. Under UK and EU data protection law, when you run an event and collect attendee details, you are almost certainly the controller and your registration platform is the processor. That distinction sounds like paperwork until something goes sideways, at which point the regulator's letters, the notification clock and the awkward email to 4,000 delegates all land on your desk, not your vendor's. The vendor must tell you, and fast. Whether your contract says "fast" in a way you could enforce is worth checking before you need to know.

Then there is the quieter lesson in accesso's own strategy update. The direction of travel is consolidation: one platform for tickets, check-in, merchandise and payments, fused into a single commercial relationship. Organisers like this, reasonably, because managing six vendors is a job nobody applied for. But a single connected ecosystem is also a single connected target. Which brings us to the questions nobody enjoys asking on a sales call.

Ask your platformWhy it matters
How quickly must you notify us of a security incident?You are the controller. Your notification clock starts when you find out, so their delay becomes your breach.
Who holds the merchant account for ticket revenue?If you use your own payment processor and take payouts directly, card data never sits in a shared vendor environment.
Which fields on our registration form are stored, and for how long?Custom registration forms are where scope creep lives. Every optional question is a future liability.
Is attendee data segregated between customers?Shared tenancy is normal. Knowing how it is partitioned is not paranoia, it is diligence.
Can we export and delete our data on demand?Retention you cannot control is retention you cannot defend.
Who has admin access on your side, and is it logged?Most incidents are access problems, not exotic zero-day cinema.

Notice how many come back to one principle: collect less, hold it in fewer places, know where the money flows. Organisers who run their own payment processor and take payouts straight to their own account quietly shrink the problem, because the most sensitive part of the transaction never becomes somebody else's inventory.

Ten years ago this was a much smaller conversation

Here is the context the announcements do not include. Rewind a decade and your ticketing supplier held names, email addresses and a seat number. The rest of the event ran on spreadsheets, lanyards printed the night before and a cash float in a biscuit tin.

Today the same supplier may hold card tokens, billing addresses, dietary requirements, accessibility needs, job titles, employer names, badge scan histories showing which sessions someone attended and who they met, and increasingly some form of identity check. Dietary and accessibility fields, incidentally, are special category data in the UK and EU. Most organisers collect them without a second thought because they are trying to be hospitable, which is exactly the point: nobody adds a risky field on purpose. They add a helpful one.

Meanwhile the industry has spent 2026 charging towards platforms that do everything. Cvent absorbed ON24. AudienceView took Saffire. Ticketing vendors have added credentialing, badge printing, facial check-in and now payments. Every move is defensible alone. Collectively they mean the average organiser's data footprint has grown rather faster than the average organiser's security budget.

Watch this space

Three things worth tracking. accesso's investigation is ongoing, and the company was careful to say its findings so far point to internal business information rather than customer records. "So far" is doing real work in that sentence, and the interim results on 15 September are the natural moment for an update.

Next, accessoPay going live this month moves the group from holding data about transactions to sitting closer to the transactions themselves. That changes what a future incident could touch, for accesso and for every other ticketing business running the same playbook.

Finally, watch incident disclosure turn into a procurement question rather than a legal one. Most RFPs today ask about uptime and integrations. The organisers who look clever in three years will be the ones who asked about notification windows, data residency and deletion, and got the answers in writing.

None of this is cause to panic about your ticketing stack. accesso appears to have handled it the way you would want a vendor to: found it, contained it, told people, kept trading. That beats most outcomes. It is simply a good week to open your own registration form, look at every field, and ask whether you truly need the answer or whether you added it in 2023 because it seemed useful. Fewer questions, fewer places for the data to sit, clearer ownership of the money. Not a security strategy on its own, but a very good start, and it is how we think a platform should be built.

Share this article Twitter LinkedIn
Stop paying to succeed

Run Your Next Event on Flat Pricing

Unlimited tickets, registrations and events. One price, no matter how big you grow.

Get in touch! Let's have a chat!