LocateBaltimore
No Result
View All Result
No Result
View All Result
LocateBaltimore
No Result
View All Result
Home Technology

Hackers steal “important quantity” of data from hundreds of Snowflake customers

Pauline Wright by Pauline Wright
June 11, 2024
in Technology
0
326
SHARES
2.5k
VIEWS
Share on FacebookShare on Twitter


Getty Images

As many as 165 customers of cloud storage supplier Snowflake have been compromised by a bunch that obtained login credentials via information-stealing malware, researchers mentioned Monday.

On Friday, Lending Tree subsidiary QuoteWizard confirmed it was among the many customers notified by Snowflake that it was affected within the incident. Lending Tree spokesperson Megan Greuling mentioned the corporate is within the course of of figuring out whether or not data saved on Snowflake has been stolen.

“That investigation is ongoing,” she wrote in an electronic mail. “As of this time, it doesn’t seem that client monetary account data was impacted, nor data of the mum or dad entity, Lending Tree.”

Researchers from Mandiant, a Google-owned safety agency Snowflake retained to research the mass compromise, mentioned Monday that the businesses have up to now recognized 165 customers whose data could have been stolen within the spree. Live Nation confirmed 10 days in the past that data its TicketMaster group saved on Snowflake had been stolen following a posting providing the sale of the total names, addresses, cellphone numbers, and partial bank card numbers for 560 million Ticketmaster customers.

Santander, Spain’s largest financial institution, mentioned lately that data belonging to some of its customers has additionally been stolen. The similar group promoting the Ticketmaster data provided the sale of Santander data. Researchers from safety agency Hudson Rock mentioned that stolen data was additionally saved on Snowflake. Santander has neither confirmed nor denied the declare.

Mandiant’s Monday publish mentioned that every one the compromises it has tracked up to now had been the consequence of login credentials for Snowflake accounts being stolen by infostealer malware and saved in huge logs, typically for years at a time. None of the affected accounts made use of multifactor authentication, which requires customers to offer a one-time password or extra means of authentication moreover a password.

Advertisement

The group finishing up the assaults is financially motivated, with members principally positioned in North America. Mandiant is monitoring it as UNC5537. Company researchers wrote:

Based on our investigations thus far, UNC5537 obtained entry to a number of organizations’ Snowflake buyer situations by way of stolen buyer credentials. These credentials had been primarily obtained from a number of infostealer malware campaigns that contaminated non-Snowflake owned methods. This allowed the risk actor to achieve entry to the affected buyer accounts and led to the export of a major quantity of buyer data from the respective Snowflake buyer situations. The risk actor has subsequently begun to extort many of the victims immediately and is actively trying to promote the stolen buyer data on acknowledged cybercriminal boards.

Mandiant recognized that almost all of the credentials utilized by UNC5537 had been obtainable from historic infostealer infections, some of which dated way back to 2020.

The risk marketing campaign performed by UNC5537 has resulted in quite a few profitable compromises on account of three major elements:

  1. The impacted accounts weren’t configured with multi-factor authentication enabled, which means profitable authentication solely required a legitimate username and password.
  2. Credentials recognized in infostealer malware output had been nonetheless legitimate, in some circumstances years after they had been stolen, and had not been rotated or up to date.
  3. The impacted Snowflake buyer situations didn’t have community enable lists in place to solely enable entry from trusted places.
Enlarge / Attack Path UNC5537 has utilized in assaults in opposition to as many as 165 Snowflake customers.

Mandiant

Initial entry to affected Snowflake accounts typically occurred with the use of the corporate’s native SnowSight or SnowSQL, that are a web-based consumer interface and a command-line interface respectively. The risk actors additionally used a customized utility that exhibits up as “rapeflake” in logs and that Mandiant tracks as FrostBite.



Source hyperlink

Tags: customersdataHackershundredssignificantSnowflakestealvolume
Previous Post

The data practitioner for the AI era

Next Post

AI Is Apple’s Best Shot at Getting You to Upgrade Your iPhone

Next Post
AI Is Apple’s Best Shot at Getting You to Upgrade Your iPhone

AI Is Apple’s Best Shot at Getting You to Upgrade Your iPhone

No Result
View All Result

Categories

  • Construction (53)
  • Food (977)
  • Local News (1,995)
  • Local Sports (1,999)
  • Technology (4,000)

Recent.

How to Make Powdered Sugar (Without Cornstarch Option)

How to Make Powdered Sugar (Without Cornstarch Option)

August 25, 2026
Cream of Asparagus Soup with White Wine

Cream of Asparagus Soup with White Wine

August 25, 2026
Easy Whole Wheat Penne With Broccoli (18-Minute Base)

Easy Whole Wheat Penne With Broccoli (18-Minute Base)

August 24, 2026

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Check our landing page for details.

Category

  • Construction (53)
  • Food (977)
  • Local News (1,995)
  • Local Sports (1,999)
  • Technology (4,000)

Tags

2024 Draft 2024 Draft News Air apple Baltimore bridge Chicken Clifton Brown day Derrick Henry draft Easy Experiments Game Gameday Gameday News General Google Heres home Homepage Centerpiece Homepage Latest Headlines iPhone Jackson Key Lamar Lamar Jackson Late For Work Maryland NFL offseason OpenAI Ravens Recipe recipes Ryan Mink Savory season shopping tech TikTok users video Watch week
  • About
  • Home

© 2026 JNews - Premium WordPress news & magazine theme by Jegtheme.

No Result
View All Result
  • About
  • Home

© 2026 JNews - Premium WordPress news & magazine theme by Jegtheme.