The Federal Trade Commission announced on July 27, 2026 that Elite Events and its operators will pay a civil penalty to resolve allegations that they bypassed online ticket purchasing limits in violation of the Better Online Ticket Sales Act, commonly called the BOTS Act.
According to the FTC, the alleged tactics included large numbers of ticket purchasing accounts, virtual credit card accounts, IP proxy services, and multi-session browsers. The agency said those methods were used to work around limits and controls that ticket issuers had put in place for online purchases.
For business owners, the useful lesson is bigger than concerts and resale markets. Access controls are not just a security-team concern. They can also be contract, compliance, reputation, payment, and vendor-management issues when a team or outside provider treats a technical workaround as a business strategy.
Automation Can Cross a Line Before Anyone Notices
Many businesses now use automation for marketing, purchasing, lead generation, data collection, reporting, support, and operations. Some of that automation is routine and legitimate. The risk starts when a workflow is designed to hide identity, avoid platform limits, create many accounts, rotate payment methods, or make activity look like it comes from different people or places.
That kind of setup can sound technical enough to stay below an owner's radar. It should not. If a vendor, contractor, employee, or growth consultant proposes proxies, bulk accounts, virtual payment methods, scraping tools, or browser-session tricks, the business decision is not only whether the tool works. The decision is whether the tactic is allowed, documented, legal, and consistent with the rules of the platform being used.
The Owner Question Is About Approval
The FTC's case gives owners a practical approval question: who is allowed to authorize automation that interacts with someone else's online service?
A business does not need to be in ticket resale for this to matter. Similar questions can appear in ecommerce purchasing, marketplace listings, review management, recruiting, ad verification, lead generation, competitive research, reservation systems, and software testing. If the workflow depends on bypassing a rule rather than using an approved integration or documented process, the owner should know before it runs.
Questions To Ask Before Running the Tool
- What platform rule, limit, or control does this workflow touch? Ask for the specific terms, policy, or technical control involved.
- Are we using our real business identity? Multiple accounts, borrowed identities, proxy routing, or disguised locations need review before use.
- Who approved the payment method? Virtual cards and many payment accounts can create accounting, fraud, and compliance questions.
- What records will prove the workflow was authorized? Keep approvals, vendor instructions, scope, and legal review notes where leadership can find them.
- Can the same goal be met through an API, partner program, bulk process, or written permission? An official path is often slower, but it is easier to defend.
- What happens if the platform blocks the accounts or reports the activity? Know the operational and reputational fallout before the campaign starts.
A Practical Next Step
Owners do not need to ban useful automation. They do need a short approval gate for higher-risk tactics. Any workflow involving bulk account creation, proxies, rotating identities, bypassing purchase limits, scraping protected areas, or using payment workarounds should be reviewed before launch.
That review does not have to be dramatic. It can be a simple written checkpoint: business purpose, platform involved, data touched, account identities used, payment methods used, vendor responsible, approval owner, and the rule or permission that allows the work. If nobody can answer those questions clearly, the automation belongs back in the queue.
Sources and further reading