Back to blog

Six of One, 277 of the Other: The FTC Just Put a Price on Ignoring Ticket Limits

TE
The eventcloud Team 11 August 2026 · 5 min read
Six of One, 277 of the Other: The FTC Just Put a Price on Ignoring Ticket Limits

Somewhere in your ticketing dashboard there is a little box that says "maximum 4 per order". You typed the number in months ago, felt organised about it, and never thought about it again. This week the Federal Trade Commission published a document that works out roughly what that box is worth when nobody is enforcing it, and the answer is $300,000 plus a permanent ban.

The case involves ticket brokers rather than conference organisers, which is exactly why it is worth twenty minutes of your attention. The tactics are the same, the software controls are the same, and the failure mode is the same. The only difference is that the concert industry has a federal statute pointed at the problem and the B2B events industry has a spreadsheet and a hopeful expression.

What the FTC actually filed

According to the FTC's press release, Georgia broker Elite Events and Tickets LLC, which also traded as Smart Scalpers, along with owners Kevin W. McKerley and Aaron L. Fera, will pay $300,000 in civil penalties to settle allegations that they bypassed posted ticket purchase limits at more than 2,400 separate events between September 2024 and March 2025. The settlement was reported in early August by TicketNews.

The headline penalty is $10.7 million. Most of it is suspended because the defendants told the court they cannot pay, which is a sentence that sits oddly next to "purchased millions of dollars' worth of tickets". If the financial disclosures turn out to be fiction, the full amount becomes due immediately.

The worked example in the complaint is the part that should make any organiser wince. Elite Events used 75 separate accounts to buy 277 tickets to a single Metallica concert at Virginia Tech. The posted limit was six. They paid between $50 and $270 per ticket and resold them for $100 to $400. That is not a loophole. That is a limit being run over 46 times in a row while the system dutifully recorded 75 happy customers.

The Commission voted 2-0 to authorise the filing, which landed in the US District Court for the Southern District of Georgia. The defendants are now permanently barred from circumventing purchase controls, running multiple buying accounts, or paying with a card in anyone else's name. Christopher Mufarrige, who runs the FTC's Bureau of Consumer Protection, framed it as protecting the right to buy a ticket at the price the issuer set, which is a tidier way of saying that a queue only works if everyone is standing in it.

The tactics, and what each one defeated

The complaint reads like a product roadmap for a company that never should have existed. Hundreds of agents, many working outside the US, ran the operation. Here is the shape of it.

Tactic usedControl it was designed to beat
Hundreds of accounts with fictitious names, addresses and phone numbersOne-account-per-buyer identity checks
Accounts opened in the names of the firm's own employeesVerified-identity account rules
Virtual card services generating thousands of unique card numbersUnique payment card matching
IP proxy services disguising the origin of each purchaseIP address and geolocation monitoring
Multi-session browsers running parallel independent sessionsSession and cookie based purchase tracking

Every single one of those is an attack on an identity signal rather than on the ticket itself. Nobody hacked anything. They just produced a convincing enough crowd of imaginary people, which is a much easier engineering problem than it sounds and a much harder detection problem than most platforms admit.

A purchase limit is not a rule. It is a claim. The only thing that turns it into a rule is the software sitting behind it, and most organisers have never once checked whether theirs is awake.

What this means for event organisers: ticket tiers, promo codes and purchase limits

Business events do not have a resale problem in the Metallica sense. Nobody is flipping a $1,400 summit pass on StubHub. What business events do have is an allocation problem, and it is the same mechanism wearing a lanyard.

Think about where your registration flow quietly trusts the buyer. Early bird tiers with a fixed count. Member-only rates gated behind a promo code. Exhibitor allocations of complimentary passes. Speaker guest tickets. Sponsor comp codes shared over email, forwarded to a colleague, forwarded again, and eventually pasted into a Slack channel with 400 members. Each of those is a posted limit enforced entirely by good manners.

The gap between "we set a limit" and "the limit held" is where the money leaks. A member rate redeemed 60 times by 12 members is not fraud, it is a control that was never actually a control. An early bird tier that sold out in one order because the cap was per-order rather than per-buyer is a discount you did not intend to give. Neither of these will ever reach the FTC. Both will reach your margin.

Practical version, and none of this requires new software if your platform already does the job properly. Cap promo codes by total redemptions and by uses per email address, because the two are different questions. Set ticket tier limits per buyer rather than per transaction. Expire codes on a date, not on vibes. Pull the redemption report before the event rather than after, so an anomaly is a conversation instead of an autopsy. And check whether your platform can even tell you that the same email bought under three different orders, because a surprising number cannot. Our own take on how promo codes and ticket tiers should behave starts from the assumption that a limit you cannot audit is decoration.

Watch this space: a law that has been used three times in a decade

Here is the context the news coverage skipped. The Better Online Ticket Sales Act was passed in 2016. It sat almost entirely unused until January 2021, when the FTC brought its first ever BOTS Act cases against three New York brokers, landing a $31 million judgment that was suspended down to $3.7 million on inability to pay. Then, broadly, silence.

So in ten years the statute has produced two enforcement waves, both settled for cents on the dollar. That is not a criticism of the FTC so much as an observation about resourcing: bot-driven ticket buying is enormously profitable and enormously distributed, and chasing it one broker at a time is a losing arithmetic problem.

Which is why the interesting trend line is not enforcement, it is architecture. The industry response to the last five years has been identity at the front door: verified accounts, device fingerprinting, registration-first ticketing at LA28, ID checks creeping into major platforms. Every one of those exists because posted limits do not enforce themselves. Expect that logic to keep travelling downhill into B2B registration, where the same features get called delegate management and nobody objects.

The organiser's takeaway is not "worry about scalpers". It is simpler than that. Go and look at every cap, code and tier in your current event, and for each one, answer whether you could prove it held. If the answer takes more than a minute to find, the limit is a suggestion, and suggestions are free for everybody except you.

Share this article Twitter LinkedIn
Stop paying to succeed

Run Your Next Event on Flat Pricing

Unlimited tickets, registrations and events. One price, no matter how big you grow.

Get in touch! Let's have a chat!