Live data from Hacker News

Hacker confirms access through infostealer infection [withdrawn]

hudsonrock.com

11–20 of 235 posts

Re: Hacker confirms access through infostealer infection [withdrawn]

#11
post #2

> The data from these companies was put up for sale on the Russian-speaking cybercrime forum Just russia being russia, as usual.

People in ex-USSR also speak/write Russian, so while I have no doubt Russians frequent the forum, lots of others from their sphere of influence also visit that forum. Don't assume everyone on HN is a 5-eyes resident.

Re: Hacker confirms access through infostealer infection [withdrawn]

#12
post #5

Why in the world would obtaining a Snowflake employee’s credentials allow you to then obtain Snowflake’s customers’ data? Doesn’t this imply that people working at Snowflake can see all of the data that I put in it? Admittedly I don’t have much experience with Snowflake, but as a baseline I expect better from a “cloud storage giant”.

There’s something missing here.

From what the Hudson Rock article shows, they were able to use an SE’s creds to access their demo account. This is not a customer account and shouldn’t (but of course could) contain sensitive info. It’s not clear to me how this snowballed into a larger breach.

Perhaps customers had granted this SE access to their accounts and the data within. Or perhaps there’s a deeper hack. But this isn’t clear to me from what I’ve read.

Re: Hacker confirms access through infostealer infection [withdrawn]

#14
post #12
post #5

Why in the world would obtaining a Snowflake employee’s credentials allow you to then obtain Snowflake’s customers’ data? Doesn’t this imply that people working at Snowflake can see all of the data that I put in it? Admittedly I don’t have much experience with Snowflake, but as a baseline I expect better from a “cloud storage giant”.

There’s something missing here. From what the Hudson Rock article shows, they were able to use an SE’s creds to access their demo account. This is not a customer account and shouldn’t (but of course could) contain sensitive info. It’s not clear to me how this snowballed into a larger breach. Perhaps customers had granted this SE access to their accounts and the data within. Or perhaps there’s a deeper hack. But this…

There may have been administrative access that was not properly secured.

Re: Hacker confirms access through infostealer infection [withdrawn]

#16
post #12
post #5

Why in the world would obtaining a Snowflake employee’s credentials allow you to then obtain Snowflake’s customers’ data? Doesn’t this imply that people working at Snowflake can see all of the data that I put in it? Admittedly I don’t have much experience with Snowflake, but as a baseline I expect better from a “cloud storage giant”.

There’s something missing here. From what the Hudson Rock article shows, they were able to use an SE’s creds to access their demo account. This is not a customer account and shouldn’t (but of course could) contain sensitive info. It’s not clear to me how this snowballed into a larger breach. Perhaps customers had granted this SE access to their accounts and the data within. Or perhaps there’s a deeper hack. But this…

I was just going to post the same thing. The files that they show in the screenshots are things like PROGRESSIVE_BID_CHANGE_202405271129.csv. Looks suspiciously like the Snowflake Sales Engineer's data for their job role closing a deal with Progressive, not Progressive's own data. And there's no reason to think that a SE would have broad access to customer data. There may be some overlap, but I doubt it contains sensitive customer data owned by Progressive.

Re: Hacker confirms access through infostealer infection [withdrawn]

#17
post #7

At least based on the wording of the perpetrator, Snowflake really did have the system designed in a way where a single administrator account gives you carte blanche to everything. > On may 31st, Snowflake released a statement in which they claim that they are investigating an industry-wide identity-based attacks that have impacted “some” of their customers. https://community.snowflake.com/s/question/0D5VI00000Emyl00…

In my experience with Snowflake support about a year ago, an administrator of the customer's account had to explicitly grant access to Snowflake in order for the Snowflake team to see or do anything -- and if I recall correctly the access had an expiry.

Re: Hacker confirms access through infostealer infection [withdrawn]

#18
post #7

At least based on the wording of the perpetrator, Snowflake really did have the system designed in a way where a single administrator account gives you carte blanche to everything. > On may 31st, Snowflake released a statement in which they claim that they are investigating an industry-wide identity-based attacks that have impacted “some” of their customers. https://community.snowflake.com/s/question/0D5VI00000Emyl00…

...All with just one successful malware-as-a-service attack against the right employee. (Lumma was the malware-as-a-service used.)

Interestingly, there's another adjacent story on the frontpage about Pegasus being used against NGOs in Eastern Europe. The principle of least authority is important, but also device security is important!

https://news.ycombinator.com/item?id=40535912

Re: Hacker confirms access through infostealer infection [withdrawn]

#19
From the official Snowflake response[0]:

>We believe this is the result of ongoing industry-wide, identity-based attacks with the intent to obtain customer data. Research indicates that these types of attacks are performed with our customers’ user credentials that were exposed through unrelated cyber threat activity. To date, we do not believe this activity is caused by any vulnerability, misconfiguration, or malicious activity within the Snowflake product.

[0]https://community.snowflake.com/s/question/0D5VI00000Emyl00A...

Re: Hacker confirms access through infostealer infection [withdrawn]

#20
post #7

At least based on the wording of the perpetrator, Snowflake really did have the system designed in a way where a single administrator account gives you carte blanche to everything. > On may 31st, Snowflake released a statement in which they claim that they are investigating an industry-wide identity-based attacks that have impacted “some” of their customers. https://community.snowflake.com/s/question/0D5VI00000Emyl00…

If the threat actor has played it right, there is a high possibility that this will be the largest data breach in history.

[deleted]
Post reply on HN