LocateBaltimore
No Result
View All Result
No Result
View All Result
LocateBaltimore
No Result
View All Result
Home Technology

Hundreds of Snowflake customer passwords found online are linked to info-stealing malware

Pauline Wright by Pauline Wright
June 6, 2024
in Technology
0
325
SHARES
2.5k
VIEWS
Share on FacebookShare on Twitter


Cloud information evaluation firm Snowflake is on the heart of a latest spate of alleged information thefts, as its company clients scramble to perceive if their shops of cloud information have been compromised. 

The Boston-based information large helps some of the most important international companies — together with banks, healthcare suppliers and tech corporations — retailer and analyze their huge quantities of information, akin to customer information, within the cloud.

Last week, Australian authorities sounded the alarm saying they had develop into conscious of “profitable compromises of a number of corporations utilising Snowflake environments,” with out naming the businesses. Hackers had claimed on a identified cybercrime discussion board that that they had stolen lots of of hundreds of thousands of customer data from Santander Bank and Ticketmaster, two of Snowflake’s greatest clients. Santander confirmed a breach of a database “hosted by a third-party supplier,” however wouldn’t identify the supplier in query. On Friday, Live Nation confirmed that its Ticketmaster subsidiary was hacked and that the stolen database was hosted on Snowflake. 

Snowflake acknowledged in a quick assertion that it was conscious of “doubtlessly unauthorized entry” to a “restricted quantity” of customer accounts, with out specifying which of them, however that it has found no proof there was a direct breach of its methods. Rather, Snowflake known as it a “focused marketing campaign directed at customers with single-factor authentication” and that the hackers used “beforehand bought or obtained by way of infostealing malware,” which is designed to scrape a person’s saved passwords from their pc.

Despite the delicate information that Snowflake holds for its clients, Snowflake lets every customer handle the safety of their environments, and doesn’t mechanically enroll or require its clients to use multi-factor authentication, or MFA, in accordance to Snowflake’s customer documentation. Not imposing the use of MFA seems to be how cybercriminals allegedly obtained enormous quantities of information from some of Snowflake’s clients, some of which arrange their environments with out the extra safety measure. 

Snowflake conceded that one of its personal “demo” accounts was compromised as a result of it wasn’t protected past a username and password, however claimed the account “didn’t comprise delicate information.” It’s unclear if this stolen demo account has any function within the latest breaches. 

TechCrunch has this week seen lots of of alleged Snowflake customer credentials that are out there online for cybercriminals to use as half of hacking campaigns, suggesting that the danger of Snowflake customer account compromises could also be far wider than first identified. 

The credentials have been stolen by infostealing malware that contaminated the computer systems of workers who’ve entry to their employer’s Snowflake surroundings.

Some of the credentials seen by TechCrunch seem to belong to workers at corporations identified to be Snowflake clients, together with Ticketmaster and Santander, amongst others. The workers with Snowflake entry embrace database engineers and information analysts, some of whom reference their expertise utilizing Snowflake on their LinkedIn pages.

For its half, Snowflake has instructed clients to instantly change on MFA for his or her accounts. Until then, Snowflake accounts that aren’t imposing the use of MFA to log in are placing their saved information in danger of compromise from easy assaults like password theft and reuse. 

How we checked the info

A supply with information of cybercriminal operations pointed TechCrunch to a web site the place would-be attackers can search by way of lists of credentials which have been stolen from varied sources, akin to infostealing malware on somebody’s pc or collated from earlier information breaches. (TechCrunch shouldn’t be linking to the positioning the place stolen credentials are out there in order not to support dangerous actors.)

In all, TechCrunch has seen greater than 500 credentials containing worker usernames and passwords, together with the net addresses of the login pages for the corresponding Snowflake environments. 

The uncovered credentials seem to pertain to Snowflake environments belonging to Santander, Ticketmaster, a minimum of two pharmaceutical giants, a meals supply service, a public-run freshwater provider, and others. We have additionally seen uncovered usernames and passwords allegedly belonging to a former Snowflake worker. 

TechCrunch shouldn’t be naming the previous worker as a result of there’s no proof they did something incorrect. (It’s in the end each the accountability of Snowflake and its clients to implement and implement safety insurance policies that stop intrusions that outcome from the theft of worker credentials.) 

We didn’t take a look at the stolen usernames and passwords as doing so would break the legislation. As such, it’s unknown if the credentials are presently in energetic use or in the event that they straight led to account compromises or information thefts. Instead, we labored to confirm the authenticity of the uncovered credentials in different methods. This contains checking the person login pages of the Snowflake environments that have been uncovered by the infostealing malware, which have been nonetheless energetic and online on the time of writing.

The credentials we’ve seen embrace the worker’s e mail handle (or username), their password, and the distinctive net handle for logging in to their firm’s Snowflake surroundings. When we checked the net addresses of the Snowflake environments — usually made up of random letters and numbers — we found the listed Snowflake customer login pages are publicly accessible, even when not searchable online.

TechCrunch confirmed that the Snowflake environments correspond to the businesses whose workers’ logins have been compromised. We have been in a position to do that as a result of every login web page we checked had two separate choices to check in.

One approach to login depends on Okta, a single sign-on supplier that permits Snowflake customers to check in with their very own firm’s company credentials utilizing MFA. In our checks, we found that these Snowflake login pages redirected to Live Nation (for Ticketmaster) and Santander sign-in pages. We additionally found a set of credentials belonging to a Snowflake worker, whose Okta login web page nonetheless redirects to an inner Snowflake login web page that now not exists.

Snowflake’s different login possibility permits the person to use solely their Snowflake username and password, relying on whether or not the company customer enforces MFA on the account, as detailed by Snowflake’s personal assist documentation. It’s these credentials that seem to have been stolen by the infostealing malware from the staff’ computer systems.

It’s not clear precisely when the staff’ credentials have been stolen or for the way lengthy they’ve been online. 

There is a few proof to recommend that a number of workers with entry to their firm’s Snowflake environments had their computer systems beforehand compromised by infostealing malware. According to a test on breach notification service Have I Been Pwned, a number of of the company e mail addresses used as usernames for accessing Snowflake environments have been found in a latest information dump containing hundreds of thousands of stolen passwords scraped from varied Telegram channels used for sharing stolen passwords.

Snowflake spokesperson Danica Stanczak declined to reply particular questions from TechCrunch, together with whether or not any of its clients’ information was found within the Snowflake worker’s demo account. In an announcement, Snowflake stated it’s “suspending sure person accounts the place there are sturdy indicators of malicious exercise.”

Snowflake added: “Under Snowflake’s shared accountability mannequin, clients are liable for imposing MFA with their customers.” The spokesperson stated Snowflake was “contemplating all choices for MFA enablement, however we have now not finalized any plans at the moment.”

When reached by e mail, Live Nation spokesperson Kaitlyn Henrich didn’t remark by press time.

Santander didn’t reply to a request for remark.

Missing MFA resulted in enormous breaches

Snowflake’s response up to now leaves quite a bit of questions unanswered, and lays naked a raft of corporations that are not reaping the advantages that MFA safety supplies. 

What is evident is that Snowflake bears a minimum of some accountability for not requiring its customers to change on the safety characteristic, and is now bearing the brunt of that — together with its clients.

The information breach at Ticketmaster allegedly entails upwards of 560 million customer data, in accordance to the cybercriminals promoting the info online. (Live Nation wouldn’t touch upon what number of clients are affected by the breach.) If confirmed, Ticketmaster could be the most important U.S. information breach of the 12 months up to now, and one of the most important in latest historical past.

Snowflake is the newest firm in a string of high-profile safety incidents and sizable information breaches attributable to the shortage of MFA. 

Last 12 months, cybercriminals scraped round 6.9 million customer data from 23andMe accounts that weren’t protected with out MFA, prompting the genetic testing firm — and its opponents — to require customers allow MFA by default to stop a repeat assault.

And earlier this 12 months, the UnitedHealth-owned well being tech large Change Healthcare admitted hackers broke into its methods and stole enormous quantities of delicate well being information from a system not protected with MFA. The healthcare large hasn’t but stated what number of people had their data compromised however stated it’s possible to have an effect on a “substantial proportion of individuals in America.”


Do you already know extra concerning the Snowflake account intrusions? Get in contact. To contact this reporter, get in contact on Signal and WhatsApp at +1 646-755-8849, or by e mail. You may also ship information and paperwork by way of SecureDrop.



Source hyperlink

Tags: cloudcustomerCybersecuritydata breachhundredsinfostealinglinkedmalwareOnlinepasswordsSantanderSnowflaketicketmaster
Previous Post

15 Ways to Eat & Drink Outdoors Around Montgomery County

Next Post

How QWERTY keyboards show the English dominance of tech

Next Post
How QWERTY keyboards show the English dominance of tech

How QWERTY keyboards show the English dominance of tech

No Result
View All Result

Categories

  • Construction (53)
  • Food (977)
  • Local News (1,995)
  • Local Sports (1,999)
  • Technology (4,000)

Recent.

How to Make Powdered Sugar (Without Cornstarch Option)

How to Make Powdered Sugar (Without Cornstarch Option)

August 25, 2026
Cream of Asparagus Soup with White Wine

Cream of Asparagus Soup with White Wine

August 25, 2026
Easy Whole Wheat Penne With Broccoli (18-Minute Base)

Easy Whole Wheat Penne With Broccoli (18-Minute Base)

August 24, 2026

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Check our landing page for details.

Category

  • Construction (53)
  • Food (977)
  • Local News (1,995)
  • Local Sports (1,999)
  • Technology (4,000)

Tags

2024 Draft 2024 Draft News Air apple Baltimore bridge Chicken Clifton Brown day Derrick Henry draft Easy Experiments Game Gameday Gameday News General Google Heres home Homepage Centerpiece Homepage Latest Headlines iPhone Jackson Key Lamar Lamar Jackson Late For Work Maryland NFL offseason OpenAI Ravens Recipe recipes Ryan Mink Savory season shopping tech TikTok users video Watch week
  • About
  • Home

© 2026 JNews - Premium WordPress news & magazine theme by Jegtheme.

No Result
View All Result
  • About
  • Home

© 2026 JNews - Premium WordPress news & magazine theme by Jegtheme.