Live data from Hacker News

Hacker confirms access through infostealer infection [withdrawn]

hudsonrock.com

51–60 of 235 posts

Re: Hacker confirms access through infostealer infection [withdrawn]

#51
post #37
post #2

> The data from these companies was put up for sale on the Russian-speaking cybercrime forum Just russia being russia, as usual.

The screenshot shows the post in English. The website domain is Indian. The seller contact xmpp.cn in China. But no, we'll keep blaming Russia for everything.

I agree. Every single security thing that happens is put on Russia.

Typical propaganda.

If we were pre-Ukraine, it’d be China getting all the blame (like it used to be).

I’m not pro-Russia, I’m just anti-bullshit.

Re: Hacker confirms access through infostealer infection [withdrawn]

#52

Earlier quoted context omitted.

No, that sounds about right. This is a new, agile, cloud-first company that grew very quickly and has faced significant turnover. You don't get such growth by doing everything right. Looking at linked-in, the unlucky employee could be someone in a sales role, with only 7 months of tenure. Every company has a few sysadmins with a scary amount of reach, but that's not what happened here. Edit: A ServiceNow access reque…

>> This is a new, agile, cloud-first company that grew very quickly and has faced significant turnover. This is not really true of Snowflake, which is not some 2-person YOLO startup, and it's also pretty irrelevant as the weakest link is often a single employee regardless of the size or industry of the company. In my experience the support and security is way better than average - example: as a client of both Snowfla…

Its support and security posture could very well be better than average. Looking a other breaches (Qlik Attunity, Microsoft AAD, ...) indicates that being better then average is not enough if you're a sufficiently attractive target.

Re: Hacker confirms access through infostealer infection [withdrawn]

#53
post #5

Why in the world would obtaining a Snowflake employee’s credentials allow you to then obtain Snowflake’s customers’ data? Doesn’t this imply that people working at Snowflake can see all of the data that I put in it? Admittedly I don’t have much experience with Snowflake, but as a baseline I expect better from a “cloud storage giant”.

[deleted]

Re: Hacker confirms access through infostealer infection [withdrawn]

#55

Earlier quoted context omitted.

(new) sales person with an uber account that has access to carte blanche customer data. This is not only a disaster, if true, but also violates probably every certification under the sun, if they had any at all. Reminder Snowflake is a couple of sales persons from Oracle and a techie.

I'm not sure it does, perhaps it violates the spirit but not the letter. You need a way to give your employees access to customer data; for support cases. So you build a "request access" form in your ITSM. Now you can tick off every box related to certification: There is a process. Only authorized persons have access. Every aspect of it can be audited. Later, perhaps sales people (the 1000's of new joiners) start usi…

> What other criteria would apply?

Many companies have processes that require 2 or more humans in the loop for sensitive prod data.

Re: Hacker confirms access through infostealer infection [withdrawn]

#57
post #37

Earlier quoted context omitted.

The screenshot shows the post in English. The website domain is Indian. The seller contact xmpp.cn in China. But no, we'll keep blaming Russia for everything.

I agree. Every single security thing that happens is put on Russia. Typical propaganda. If we were pre-Ukraine, it’d be China getting all the blame (like it used to be). I’m not pro-Russia, I’m just anti-bullshit.

>I agree. Every single security thing that happens is put on Russia.

This is transparently false. Both Russia and China have copped blame for various recent attacks. And the fact of the matter is that Russian hackers are extremely active at the moment, and were even before 2022.

See for example: https://www.wired.com/story/notpetya-cyberattack-ukraine-rus...

>If we were pre-Ukraine, it’d be China getting all the blame (like it used to be).

Russia was behind the Solarwinds hack, which is the most widely covered one in the past decade. Ironically the Chinese were also independently exploiting Solarwinds to break into government agencies, but that didn't get much attention.

Re: Hacker confirms access through infostealer infection [withdrawn]

#58
post #9

The screenshots of the chat logs are really something. This firm claims to be in communication with the actual criminal, and the actual criminal says that using their firm would have helped prevent the breach. I have updated my sense of the firm's trustworthiness accordingly.

This is just pure speculation, but it kind of looks like the hacker was being ignored by Snowflake, so they somehow got in touch with Hudson Rock and offered them this promotional opportunity (to break the news, more than the throwaway line in the article) with the goal of retaliating against Snowflake for failing to pay the ransom. And Hudson Rock agreed to play along and hype up the story, presenting it as a bigger breach than it really was. One wonders whether Hudson Rock was the first they went to, or just the first to take them up on the offer.

Re: Hacker confirms access through infostealer infection [withdrawn]

#59
post #9

The screenshots of the chat logs are really something. This firm claims to be in communication with the actual criminal, and the actual criminal says that using their firm would have helped prevent the breach. I have updated my sense of the firm's trustworthiness accordingly.

That particular exchange is bizarre and cartoonish. I don’t know what to make of it. “should have bought protection from Hudson Rock could have saved them this one” “yes i agree it wouldve helped for sure”

seems like a shameless marketing plug to me

Re: Hacker confirms access through infostealer infection [withdrawn]

#60
post #9

The screenshots of the chat logs are really something. This firm claims to be in communication with the actual criminal, and the actual criminal says that using their firm would have helped prevent the breach. I have updated my sense of the firm's trustworthiness accordingly.

in that you trust them less?

Absolutely the case for me. I don't give Snowflake much here, but Hudson Rock sells this exact type of "protection" and so far including BBC, no other independent verification?

This from the GP's link does it: “should have bought protection from Hudson Rock could have saved them this one”

Post reply on HN