> The data from these companies was put up for sale on the Russian-speaking cybercrime forum Just russia being russia, as usual.
Hacker confirms access through infostealer infection [withdrawn]
11–20 of 235 posts
Re: Hacker confirms access through infostealer infection [withdrawn]
#12Why in the world would obtaining a Snowflake employee’s credentials allow you to then obtain Snowflake’s customers’ data? Doesn’t this imply that people working at Snowflake can see all of the data that I put in it? Admittedly I don’t have much experience with Snowflake, but as a baseline I expect better from a “cloud storage giant”.
From what the Hudson Rock article shows, they were able to use an SE’s creds to access their demo account. This is not a customer account and shouldn’t (but of course could) contain sensitive info. It’s not clear to me how this snowballed into a larger breach.
Perhaps customers had granted this SE access to their accounts and the data within. Or perhaps there’s a deeper hack. But this isn’t clear to me from what I’ve read.
Re: Hacker confirms access through infostealer infection [withdrawn]
#13> Snowflake’s single platform eliminates data silos
I guess so, especially now.
Re: Hacker confirms access through infostealer infection [withdrawn]
#14Why in the world would obtaining a Snowflake employee’s credentials allow you to then obtain Snowflake’s customers’ data? Doesn’t this imply that people working at Snowflake can see all of the data that I put in it? Admittedly I don’t have much experience with Snowflake, but as a baseline I expect better from a “cloud storage giant”.
There’s something missing here. From what the Hudson Rock article shows, they were able to use an SE’s creds to access their demo account. This is not a customer account and shouldn’t (but of course could) contain sensitive info. It’s not clear to me how this snowballed into a larger breach. Perhaps customers had granted this SE access to their accounts and the data within. Or perhaps there’s a deeper hack. But this…
Re: Hacker confirms access through infostealer infection [withdrawn]
#15IOCs: https://community.snowflake.com/s/article/Communication-ID-0...
Re: Hacker confirms access through infostealer infection [withdrawn]
#16Why in the world would obtaining a Snowflake employee’s credentials allow you to then obtain Snowflake’s customers’ data? Doesn’t this imply that people working at Snowflake can see all of the data that I put in it? Admittedly I don’t have much experience with Snowflake, but as a baseline I expect better from a “cloud storage giant”.
There’s something missing here. From what the Hudson Rock article shows, they were able to use an SE’s creds to access their demo account. This is not a customer account and shouldn’t (but of course could) contain sensitive info. It’s not clear to me how this snowballed into a larger breach. Perhaps customers had granted this SE access to their accounts and the data within. Or perhaps there’s a deeper hack. But this…
Re: Hacker confirms access through infostealer infection [withdrawn]
#17At least based on the wording of the perpetrator, Snowflake really did have the system designed in a way where a single administrator account gives you carte blanche to everything. > On may 31st, Snowflake released a statement in which they claim that they are investigating an industry-wide identity-based attacks that have impacted “some” of their customers. https://community.snowflake.com/s/question/0D5VI00000Emyl00…
Re: Hacker confirms access through infostealer infection [withdrawn]
#18At least based on the wording of the perpetrator, Snowflake really did have the system designed in a way where a single administrator account gives you carte blanche to everything. > On may 31st, Snowflake released a statement in which they claim that they are investigating an industry-wide identity-based attacks that have impacted “some” of their customers. https://community.snowflake.com/s/question/0D5VI00000Emyl00…
Interestingly, there's another adjacent story on the frontpage about Pegasus being used against NGOs in Eastern Europe. The principle of least authority is important, but also device security is important!
Re: Hacker confirms access through infostealer infection [withdrawn]
#19>We believe this is the result of ongoing industry-wide, identity-based attacks with the intent to obtain customer data. Research indicates that these types of attacks are performed with our customers’ user credentials that were exposed through unrelated cyber threat activity. To date, we do not believe this activity is caused by any vulnerability, misconfiguration, or malicious activity within the Snowflake product.
[0]https://community.snowflake.com/s/question/0D5VI00000Emyl00A...
Re: Hacker confirms access through infostealer infection [withdrawn]
#20At least based on the wording of the perpetrator, Snowflake really did have the system designed in a way where a single administrator account gives you carte blanche to everything. > On may 31st, Snowflake released a statement in which they claim that they are investigating an industry-wide identity-based attacks that have impacted “some” of their customers. https://community.snowflake.com/s/question/0D5VI00000Emyl00…
If the threat actor has played it right, there is a high possibility that this will be the largest data breach in history.