Live data from Hacker News

Hacker confirms access through infostealer infection [withdrawn]

hudsonrock.com

41–50 of 235 posts

Re: Hacker confirms access through infostealer infection [withdrawn]

#41
post #9

The screenshots of the chat logs are really something. This firm claims to be in communication with the actual criminal, and the actual criminal says that using their firm would have helped prevent the breach. I have updated my sense of the firm's trustworthiness accordingly.

in that you trust them less?

Re: Hacker confirms access through infostealer infection [withdrawn]

#42
post #8
post #2

> The data from these companies was put up for sale on the Russian-speaking cybercrime forum Just russia being russia, as usual.

Your daily evidence that modern Russia is essentially just an organized crime ring with oil reserves and nukes.

Yes, any country that is not your ally or vassal is an "organized crime ring". It's safer to be with oil and nukes, than without them you know.

Re: Hacker confirms access through infostealer infection [withdrawn]

#44
post #40

Was their intent to dox the employee while discussing this beach? They show the employee’s username, which is easily Googleable.

Yeah that seems super sus to me as well. Super unprofessional.

As is the plug of 'should have bought protection from hudson rock'

Re: Hacker confirms access through infostealer infection [withdrawn]

#47

This article is claiming that the Ticketmaster breach from a few days ago was actually a much broader hack affecting 400+ companies, all through a Snowflake employee's stolen credentials. This seems like a pretty big story that's only being reported on hudsonrock.com now. I haven't heard of Hudson Rock before, does anyone know if they are a reputable source?

BBC News report of a substantial hack of Santander bank; linked to Snowflake. https://www.bbc.co.uk/news/articles/c6ppv06e3n8o

Great, so these companies do not give a flying fuck about their customer data in making sure the data stored at cloud storage companies are end to end encrypted.

To think these random cloud storage companies can access your bank information is utterly shocking.

Re: Hacker confirms access through infostealer infection [withdrawn]

#48

It sounds like they found a way to bypass MFA on snowflake (because snowflake didn’t expire session cookies), and stole an employees credential, obtained via a “Lumma-type Infostealer” which I guess is just a key logger in browser extensions and fake versions of software…

something doesn't add up, because I don't see how this extrapolates from stealing privileged Snowflake employee credentials. How does that become a keylogger on a client's computer?

Yeah it is a bit muddled honestly. I had to read it a couple times and I still don’t completely get what happened:

1. Employee installs a key logger

2. Snowflake does not expire session cookies

3. Malware steals their session cookie and password, so can bypass employee MFA/okta

4. ???

5. Somehow this one employee has admin access to 4000 snowflake instances

Re: Hacker confirms access through infostealer infection [withdrawn]

#49
post #9

The screenshots of the chat logs are really something. This firm claims to be in communication with the actual criminal, and the actual criminal says that using their firm would have helped prevent the breach. I have updated my sense of the firm's trustworthiness accordingly.

That particular exchange is bizarre and cartoonish. I don’t know what to make of it.

“should have bought protection from Hudson Rock could have saved them this one”

“yes i agree it wouldve helped for sure”

Re: Hacker confirms access through infostealer infection [withdrawn]

#50

Earlier quoted context omitted.

No, that sounds about right. This is a new, agile, cloud-first company that grew very quickly and has faced significant turnover. You don't get such growth by doing everything right. Looking at linked-in, the unlucky employee could be someone in a sales role, with only 7 months of tenure. Every company has a few sysadmins with a scary amount of reach, but that's not what happened here. Edit: A ServiceNow access reque…

(new) sales person with an uber account that has access to carte blanche customer data. This is not only a disaster, if true, but also violates probably every certification under the sun, if they had any at all. Reminder Snowflake is a couple of sales persons from Oracle and a techie.

I'm not sure it does, perhaps it violates the spirit but not the letter.

You need a way to give your employees access to customer data; for support cases. So you build a "request access" form in your ITSM. Now you can tick off every box related to certification: There is a process. Only authorized persons have access. Every aspect of it can be audited.

Later, perhaps sales people (the 1000's of new joiners) start using it as well for lead generation. It's a lot easier to sell if you know how your product is used by other companies in the same industry.

Much later, someone's account is compromised, makes the same requests and it gets waved through. Why wouldn't it ? It is a valid request made by a current employee of the company. What other criteria would apply ? This is not a bank.

Post reply on HN