The screenshots of the chat logs are really something. This firm claims to be in communication with the actual criminal, and the actual criminal says that using their firm would have helped prevent the breach. I have updated my sense of the firm's trustworthiness accordingly.
Hacker confirms access through infostealer infection [withdrawn]
41–50 of 235 posts
Re: Hacker confirms access through infostealer infection [withdrawn]
#42> The data from these companies was put up for sale on the Russian-speaking cybercrime forum Just russia being russia, as usual.
Your daily evidence that modern Russia is essentially just an organized crime ring with oil reserves and nukes.
Re: Hacker confirms access through infostealer infection [withdrawn]
#43Re: Hacker confirms access through infostealer infection [withdrawn]
#44Re: Hacker confirms access through infostealer infection [withdrawn]
#45Was their intent to dox the employee while discussing this beach? They show the employee’s username, which is easily Googleable.
Re: Hacker confirms access through infostealer infection [withdrawn]
#46Re: Hacker confirms access through infostealer infection [withdrawn]
#47This article is claiming that the Ticketmaster breach from a few days ago was actually a much broader hack affecting 400+ companies, all through a Snowflake employee's stolen credentials. This seems like a pretty big story that's only being reported on hudsonrock.com now. I haven't heard of Hudson Rock before, does anyone know if they are a reputable source?
BBC News report of a substantial hack of Santander bank; linked to Snowflake. https://www.bbc.co.uk/news/articles/c6ppv06e3n8o
To think these random cloud storage companies can access your bank information is utterly shocking.
Re: Hacker confirms access through infostealer infection [withdrawn]
#48It sounds like they found a way to bypass MFA on snowflake (because snowflake didn’t expire session cookies), and stole an employees credential, obtained via a “Lumma-type Infostealer” which I guess is just a key logger in browser extensions and fake versions of software…
something doesn't add up, because I don't see how this extrapolates from stealing privileged Snowflake employee credentials. How does that become a keylogger on a client's computer?
1. Employee installs a key logger
2. Snowflake does not expire session cookies
3. Malware steals their session cookie and password, so can bypass employee MFA/okta
4. ???
5. Somehow this one employee has admin access to 4000 snowflake instances
Re: Hacker confirms access through infostealer infection [withdrawn]
#49The screenshots of the chat logs are really something. This firm claims to be in communication with the actual criminal, and the actual criminal says that using their firm would have helped prevent the breach. I have updated my sense of the firm's trustworthiness accordingly.
“should have bought protection from Hudson Rock could have saved them this one”
“yes i agree it wouldve helped for sure”
Re: Hacker confirms access through infostealer infection [withdrawn]
#50Earlier quoted context omitted.
No, that sounds about right. This is a new, agile, cloud-first company that grew very quickly and has faced significant turnover. You don't get such growth by doing everything right. Looking at linked-in, the unlucky employee could be someone in a sales role, with only 7 months of tenure. Every company has a few sysadmins with a scary amount of reach, but that's not what happened here. Edit: A ServiceNow access reque…
(new) sales person with an uber account that has access to carte blanche customer data. This is not only a disaster, if true, but also violates probably every certification under the sun, if they had any at all. Reminder Snowflake is a couple of sales persons from Oracle and a techie.
You need a way to give your employees access to customer data; for support cases. So you build a "request access" form in your ITSM. Now you can tick off every box related to certification: There is a process. Only authorized persons have access. Every aspect of it can be audited.
Later, perhaps sales people (the 1000's of new joiners) start using it as well for lead generation. It's a lot easier to sell if you know how your product is used by other companies in the same industry.
Much later, someone's account is compromised, makes the same requests and it gets waved through. Why wouldn't it ? It is a valid request made by a current employee of the company. What other criteria would apply ? This is not a bank.