Live data from Hacker News

Hacker confirms access through infostealer infection [withdrawn]

hudsonrock.com

31–40 of 235 posts

Re: Hacker confirms access through infostealer infection [withdrawn]

#31
post #5

Why in the world would obtaining a Snowflake employee’s credentials allow you to then obtain Snowflake’s customers’ data? Doesn’t this imply that people working at Snowflake can see all of the data that I put in it? Admittedly I don’t have much experience with Snowflake, but as a baseline I expect better from a “cloud storage giant”.

No, that sounds about right. This is a new, agile, cloud-first company that grew very quickly and has faced significant turnover. You don't get such growth by doing everything right. Looking at linked-in, the unlucky employee could be someone in a sales role, with only 7 months of tenure. Every company has a few sysadmins with a scary amount of reach, but that's not what happened here. Edit: A ServiceNow access reque…

(new) sales person with an uber account that has access to carte blanche customer data. This is not only a disaster, if true, but also violates probably every certification under the sun, if they had any at all. Reminder Snowflake is a couple of sales persons from Oracle and a techie.

Re: Hacker confirms access through infostealer infection [withdrawn]

#32
Protecting customer data from compromised insiders can be pretty hard. They often need the access to do their jobs. Still, in this case it's was far too easy - just one session cookie and a password shouldn't itself by sufficient to compromise all your customers.

Re: Hacker confirms access through infostealer infection [withdrawn]

#33
post #5

Why in the world would obtaining a Snowflake employee’s credentials allow you to then obtain Snowflake’s customers’ data? Doesn’t this imply that people working at Snowflake can see all of the data that I put in it? Admittedly I don’t have much experience with Snowflake, but as a baseline I expect better from a “cloud storage giant”.

No, that sounds about right. This is a new, agile, cloud-first company that grew very quickly and has faced significant turnover. You don't get such growth by doing everything right. Looking at linked-in, the unlucky employee could be someone in a sales role, with only 7 months of tenure. Every company has a few sysadmins with a scary amount of reach, but that's not what happened here. Edit: A ServiceNow access reque…

>> This is a new, agile, cloud-first company that grew very quickly and has faced significant turnover.

This is not really true of Snowflake, which is not some 2-person YOLO startup, and it's also pretty irrelevant as the weakest link is often a single employee regardless of the size or industry of the company. In my experience the support and security is way better than average - example: as a client of both Snowflake and Sisense, Snowflake reached out to me about the Sisense breach before Sisense did.

Re: Hacker confirms access through infostealer infection [withdrawn]

#35
> To put it bluntly, a single credential resulted in the exfiltration of potentially hundreds of companies that stored their data using Snowflake, with the threat actor himself suggesting 400 companies are impacted

You only have to "fail" once, as they say.-

Re: Hacker confirms access through infostealer infection [withdrawn]

#36

It sounds like they found a way to bypass MFA on snowflake (because snowflake didn’t expire session cookies), and stole an employees credential, obtained via a “Lumma-type Infostealer” which I guess is just a key logger in browser extensions and fake versions of software…

something doesn't add up, because I don't see how this extrapolates from stealing privileged Snowflake employee credentials. How does that become a keylogger on a client's computer?

Re: Hacker confirms access through infostealer infection [withdrawn]

#37
post #2

> The data from these companies was put up for sale on the Russian-speaking cybercrime forum Just russia being russia, as usual.

The screenshot shows the post in English. The website domain is Indian. The seller contact xmpp.cn in China. But no, we'll keep blaming Russia for everything.

Re: Hacker confirms access through infostealer infection [withdrawn]

#38
post #7

At least based on the wording of the perpetrator, Snowflake really did have the system designed in a way where a single administrator account gives you carte blanche to everything. > On may 31st, Snowflake released a statement in which they claim that they are investigating an industry-wide identity-based attacks that have impacted “some” of their customers. https://community.snowflake.com/s/question/0D5VI00000Emyl00…

In my experience with Snowflake support about a year ago, an administrator of the customer's account had to explicitly grant access to Snowflake in order for the Snowflake team to see or do anything -- and if I recall correctly the access had an expiry.

That’s if they were following procedure. But on these internal systems, there are often hacks around the procedure that folks with the right mindset can easily find.

Re: Hacker confirms access through infostealer infection [withdrawn]

#39
post #8
post #2

> The data from these companies was put up for sale on the Russian-speaking cybercrime forum Just russia being russia, as usual.

Your daily evidence that modern Russia is essentially just an organized crime ring with oil reserves and nukes.

That's just "government"
Post reply on HN