Live data from Hacker News

Hacker confirms access through infostealer infection [withdrawn]

hudsonrock.com

1–10 of 235 posts

Re: Hacker confirms access through infostealer infection [withdrawn]

#3
This article is claiming that the Ticketmaster breach from a few days ago was actually a much broader hack affecting 400+ companies, all through a Snowflake employee's stolen credentials. This seems like a pretty big story that's only being reported on hudsonrock.com now.

I haven't heard of Hudson Rock before, does anyone know if they are a reputable source?

Re: Hacker confirms access through infostealer infection [withdrawn]

#4

This article is claiming that the Ticketmaster breach from a few days ago was actually a much broader hack affecting 400+ companies, all through a Snowflake employee's stolen credentials. This seems like a pretty big story that's only being reported on hudsonrock.com now. I haven't heard of Hudson Rock before, does anyone know if they are a reputable source?

BBC News report of a substantial hack of Santander bank; linked to Snowflake. https://www.bbc.co.uk/news/articles/c6ppv06e3n8o

Re: Hacker confirms access through infostealer infection [withdrawn]

#5
Why in the world would obtaining a Snowflake employee’s credentials allow you to then obtain Snowflake’s customers’ data? Doesn’t this imply that people working at Snowflake can see all of the data that I put in it?

Admittedly I don’t have much experience with Snowflake, but as a baseline I expect better from a “cloud storage giant”.

Re: Hacker confirms access through infostealer infection [withdrawn]

#7
At least based on the wording of the perpetrator, Snowflake really did have the system designed in a way where a single administrator account gives you carte blanche to everything.

> On may 31st, Snowflake released a statement in which they claim that they are investigating an industry-wide identity-based attacks that have impacted “some” of their customers.

https://community.snowflake.com/s/question/0D5VI00000Emyl00A...

This gives credibility to both Ticketmaster and Santander stories.

Wow! Could be one of the biggest dumps of all time if the threat actors did everything correctly?

Re: Hacker confirms access through infostealer infection [withdrawn]

#8
post #2

> The data from these companies was put up for sale on the Russian-speaking cybercrime forum Just russia being russia, as usual.

Your daily evidence that modern Russia is essentially just an organized crime ring with oil reserves and nukes.

Re: Hacker confirms access through infostealer infection [withdrawn]

#9
The screenshots of the chat logs are really something. This firm claims to be in communication with the actual criminal, and the actual criminal says that using their firm would have helped prevent the breach.

I have updated my sense of the firm's trustworthiness accordingly.

Re: Hacker confirms access through infostealer infection [withdrawn]

#10
post #7

At least based on the wording of the perpetrator, Snowflake really did have the system designed in a way where a single administrator account gives you carte blanche to everything. > On may 31st, Snowflake released a statement in which they claim that they are investigating an industry-wide identity-based attacks that have impacted “some” of their customers. https://community.snowflake.com/s/question/0D5VI00000Emyl00…

If the threat actor has played it right, there is a high possibility that this will be the largest data breach in history.
Post reply on HN