惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

I
Intezer
V
Vulnerabilities – Threatpost
Google Online Security Blog
Google Online Security Blog
T
The Exploit Database - CXSecurity.com
C
CXSECURITY Database RSS Feed - CXSecurity.com
AWS News Blog
AWS News Blog
G
GRAHAM CLULEY
P
Privacy & Cybersecurity Law Blog
www.infosecurity-magazine.com
www.infosecurity-magazine.com
C
Cybersecurity and Infrastructure Security Agency CISA
N
News | PayPal Newsroom
T
Tenable Blog
Spread Privacy
Spread Privacy
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
S
Secure Thoughts
P
Privacy International News Feed
IT之家
IT之家
Project Zero
Project Zero
T
The Blog of Author Tim Ferriss
Engineering at Meta
Engineering at Meta
大猫的无限游戏
大猫的无限游戏
博客园_首页
GbyAI
GbyAI
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
量子位
雷峰网
雷峰网
Apple Machine Learning Research
Apple Machine Learning Research
Hacker News: Ask HN
Hacker News: Ask HN
Google DeepMind News
Google DeepMind News
MongoDB | Blog
MongoDB | Blog
N
Netflix TechBlog - Medium
Martin Fowler
Martin Fowler
NISL@THU
NISL@THU
I
InfoQ
D
DataBreaches.Net
有赞技术团队
有赞技术团队
K
Kaspersky official blog
Security Latest
Security Latest
The Register - Security
The Register - Security
Hugging Face - Blog
Hugging Face - Blog
S
Security @ Cisco Blogs
P
Proofpoint News Feed
M
MIT News - Artificial intelligence
H
Hackread – Cybersecurity News, Data Breaches, AI and More
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
AI
AI
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
P
Proofpoint News Feed
Security Archives - TechRepublic
Security Archives - TechRepublic
N
News and Events Feed by Topic

Breaches – ThreatDown by Malwarebytes

Snowflake “breach” looks like 165 individual incidents Ransomware drives healthcare provider into administration K-12 district hit with $500k Medusa ransomware attack Comcast’s Xfinity breached by Citrix Bleed; 36 million customer’s data accessed MongoDB warns customers about data breach after cyberattack State of Maine data breach impacts 1.3 million people Okta breach happened after employee logged into personal Google account - ThreatDown by Malwarebytes Medical research data Advarra stolen after SIM swap 1Password reports security incident after breach at Okta
Ticketmaster, Santander Bank breaches linked to Snowflake hack, threat actor claims
Bill Cozens · 2024-06-01 · via Breaches – ThreatDown by Malwarebytes
Snowflake logo

An individual allegedly behind recent attacks on Ticketmaster and Santander Bank has claimed that they gained initial access to their victims by using stolen Snowflake credentials.

The possible connection was first revealed by cybersecurity company Hudson Rock, which today published a blog post detailing a conversation with an alleged perpetrator of the two breaches. According to the post, the threat actor used stolen credentials to sign into a Snowflake employee’s ServiceNow account, thus bypassing Okta. 

The stolen credentials are believed to have originated from an Infostealer downloaded to the same Snowflake employee’s account in October 2023. After gaining initial access, Hudson Rock said, the threat actor was able to access refresh tokens from Okta, allowing them to maintain persistent access and steal data from some companies using Snowflake software.

Snowflake, an American data cloud company, is used by thousands of companies to store, manage, and analyze large volumes of data. On May 31st, the company released a statement on its community forums stating they had “recently observed and are investigating an increase in cyber threat activity targeting” some of their customers’ accounts, without specifically mentioning Ticketmaster or Santander Bank.

The threat actor allegedly tried to extort a 20 million dollar ransom from Snowflake as well, writing to a Hudson Rock researcher:

anyway my goal is for them [Snowflake] to buy their data back rather than let it end up in the wrong hands and a few already have independently but snowflake could just pay me 20m and save everyone time.

At of the time of writing, neither the threat actor’s nor Hudson Rock’s claims have been validated by third-party sources.

According to the Snowflake statement, companies using Snowflake software are recommended to:

Detecting months-long threat campaigns, such as those behind the alleged Snowflake hack, takes a team of security professionals scouring your systems 24×7 for IOCs and suspicious activity observed on endpoints.

In late January 2024, the ThreatDown Managed Detection and Response (MDR) team found and stopped a three-month long malware campaign against a Managed Service Provider (MSP) based in Europe. Read the details of how ThreatDown MDR neutralized the threat.

Learn more about ThreatDown MDR here.

UPDATE 6/2/2024: Hudson Rock has since taken down their blog post.