惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Project Zero
Project Zero
B
Blog RSS Feed
爱范儿
爱范儿
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
阮一峰的网络日志
阮一峰的网络日志
美团技术团队
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
D
Docker
B
Blog
大猫的无限游戏
大猫的无限游戏
V
Vulnerabilities – Threatpost
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
S
Schneier on Security
Spread Privacy
Spread Privacy
NISL@THU
NISL@THU
博客园 - 【当耐特】
IT之家
IT之家
云风的 BLOG
云风的 BLOG
L
Lohrmann on Cybersecurity
V
V2EX
Latest news
Latest news
S
Secure Thoughts
C
Check Point Blog
N
Netflix TechBlog - Medium
N
News | PayPal Newsroom
C
Cybersecurity and Infrastructure Security Agency CISA
The Register - Security
The Register - Security
The Cloudflare Blog
博客园_首页
博客园 - 三生石上(FineUI控件)
L
LINUX DO - 最新话题
W
WeLiveSecurity
G
GRAHAM CLULEY
量子位
T
The Exploit Database - CXSecurity.com
Security Latest
Security Latest
C
Cisco Blogs
Security Archives - TechRepublic
Security Archives - TechRepublic
GbyAI
GbyAI
A
Arctic Wolf
Attack and Defense Labs
Attack and Defense Labs
博客园 - 叶小钗
SecWiki News
SecWiki News
Vercel News
Vercel News
Engineering at Meta
Engineering at Meta
S
Security @ Cisco Blogs
小众软件
小众软件
N
News and Events Feed by Topic
WordPress大学
WordPress大学

Breaches – ThreatDown by Malwarebytes

Snowflake “breach” looks like 165 individual incidents Ransomware drives healthcare provider into administration K-12 district hit with $500k Medusa ransomware attack Comcast’s Xfinity breached by Citrix Bleed; 36 million customer’s data accessed MongoDB warns customers about data breach after cyberattack State of Maine data breach impacts 1.3 million people Okta breach happened after employee logged into personal Google account - ThreatDown by Malwarebytes Medical research data Advarra stolen after SIM swap 1Password reports security incident after breach at Okta
Ticketmaster, Santander Bank breaches linked to Snowflake hack, threat actor claims
Bill Cozens · 2024-06-01 · via Breaches – ThreatDown by Malwarebytes
Snowflake logo

An individual allegedly behind recent attacks on Ticketmaster and Santander Bank has claimed that they gained initial access to their victims by using stolen Snowflake credentials.

The possible connection was first revealed by cybersecurity company Hudson Rock, which today published a blog post detailing a conversation with an alleged perpetrator of the two breaches. According to the post, the threat actor used stolen credentials to sign into a Snowflake employee’s ServiceNow account, thus bypassing Okta. 

The stolen credentials are believed to have originated from an Infostealer downloaded to the same Snowflake employee’s account in October 2023. After gaining initial access, Hudson Rock said, the threat actor was able to access refresh tokens from Okta, allowing them to maintain persistent access and steal data from some companies using Snowflake software.

Snowflake, an American data cloud company, is used by thousands of companies to store, manage, and analyze large volumes of data. On May 31st, the company released a statement on its community forums stating they had “recently observed and are investigating an increase in cyber threat activity targeting” some of their customers’ accounts, without specifically mentioning Ticketmaster or Santander Bank.

The threat actor allegedly tried to extort a 20 million dollar ransom from Snowflake as well, writing to a Hudson Rock researcher:

anyway my goal is for them [Snowflake] to buy their data back rather than let it end up in the wrong hands and a few already have independently but snowflake could just pay me 20m and save everyone time.

At of the time of writing, neither the threat actor’s nor Hudson Rock’s claims have been validated by third-party sources.

According to the Snowflake statement, companies using Snowflake software are recommended to:

Detecting months-long threat campaigns, such as those behind the alleged Snowflake hack, takes a team of security professionals scouring your systems 24×7 for IOCs and suspicious activity observed on endpoints.

In late January 2024, the ThreatDown Managed Detection and Response (MDR) team found and stopped a three-month long malware campaign against a Managed Service Provider (MSP) based in Europe. Read the details of how ThreatDown MDR neutralized the threat.

Learn more about ThreatDown MDR here.

UPDATE 6/2/2024: Hudson Rock has since taken down their blog post.