[ad_1]
According to security experts, cybercriminals have managed to pilfer a “significant volume of data” from numerous clients using Snowflake’s cloud storage solutions for managing their extensive data repositories.
Mandiant, a prestigious incident response firm assisting Snowflake to delve into the recent data breaches, disclosed in a Monday blog update that they have informed approximately 165 Snowflake users regarding the potential theft of their data.
Ever since these hacking incidents surfaced in April, this is the maiden instance the exact scale of impact on Snowflake clients has been revealed. Although Snowflake’s commentary has been sparse, suggesting that only a “limited number” of clients were impacted, the company serves over 9,800 enterprises, including technology leaders, healthcare entities, and retail behemoths that utilize Snowflake for data processing and analytics.
To date, only Ticketmaster and LendingTree have acknowledged thefts of data stored within Snowflake’s platforms. Other Snowflake clients have indicated that investigations into potential data breaches are ongoing.
Mandiant alerts that the offensive operations by cybercriminals are in progress, implying that the quantity of Snowflake corporate users reporting data breaches might climb.
Attributing these security lapses to the unidentified cybercriminal collective UNC5537 in their report, Mandiant suggests the group, driven by profit motives, includes individuals from North America and Turkey. They are known for extorting victims, demanding payments for returning stolen data, or to stop the dissemination of their customer information.
Mandiant has confirmed that since at least April 14, they identified unauthorized activities in a client’s Snowflake platform, notifying Snowflake of the intrusions on May 22.
Most login credentials used by UNC5537 during the attacks were obtained from previous malware attacks that had captured user information, some accounts dating back to 2020. Mandiant’s discovery corroborates Snowflake’s statements, which denied any direct compromise of its infrastructure but highlighted the absence of multi-factor authentication (MFA) implementation on affected user accounts as a contributing factor.
TechCrunch recently uncovered a plethora of pilfered Snowflake user credentials online, a consequence of corporate workstation malware infections. This exposure underscores a sustained danger to clients who have not updated passwords or activated MFA.
Moreover, Mandiant observed numerous Snowflake user credentials publicly available via malicious software.
While Snowflake itself does not mandate nor enforce default MFA for its customers, it has mooted implementing compulsory usage. Unfortunately, Snowflake, as of their last communication, has yet to put forth any definitive schedule for this.
When prompted, Snowflake’s Danica Stanczak didn’t clarify why the firm has not reset clients’ passwords or enforced MFA. Snowflake’s response to Mandiant’s findings on Monday has not been clearly articulated either.
Are you privy to further details regarding the Snowflake account breaches? Feel free to reach out. For contacting this correspondent, utilize Signal and WhatsApp at +1 646-755-8849, or email directly. For the submission of files and documents, SecureDrop is a viable option.
[ad_2]
FAQs
What is Snowflake?
Snowbox is a company that provides cloud data platform services for various purposes including data analytics and data storage.
Who is Mandiant?
Mandiant is an incident response and cybersecurity firm that assists companies in investigating and mitigating cybersecurity threats.
What happened with Snowflake customers?
Cybercriminals have stolen substantial amounts of data from a number of Snowflake’s customers by exploiting stolen credentials.
How many Snowflake customers were affected?
About 165 customers of Snowflake were notified regarding potential data theft as a result of the account hacks. The actual number of affected customers could increase.
What is multi-factor authentication (MFA)?
MFA is a security system that requires more than one method of authentication from independent categories of credentials to verify the user’s identity for a login or other transaction.
Has Snowflake enforced the use of MFA?
As per the latest communications, Snowflake has not enforced the use of MFA but is reportedly developing a plan to do so.
How did the cybercriminals gain access to customer data?
The criminals used previously stolen credentials, available due to historical infostealer malware, to access Snowflake customers’ instances and exfiltrate data.










































