HomeSecuritySnowflake breach exposes customer data

Snowflake breach exposes customer data

Up to 165 Snowflake appear to have had their data exposed as part of an ongoing campaign aimed at information theft and extortion, confirming that the problem is bigger than initially estimated.

snowflake

Mandiant , a Google subsidiary that helps the cloud data storage platform with its incident management efforts, is monitoring a cluster of yet-to-be-classified activities called UNC5537. UNC5537 is described as a financially motivated threat.

See more: Cylance: Data breach via third-party hacking

“UNC5537 is systematically compromising Snowflake customer accounts using stolen credentials, advertising their data for sale on cybercrime forums , and attempting to extort many of the victims,” the threat intelligence firm said on Monday.

"UNC5537 has targeted hundreds of organizations worldwide and often extorts victims for financial gain. It operates under various aliases on Telegram channels and crime forums.".

There are indications that the hacking includes members based in North America and is working with at least one additional member in Turkey.

This is the first time the number of affected customers has been officially disclosed. Before that, Snowflake had said that a “limited number” of its customers had been affected. The company has over 9,820 customers worldwide.

The campaign, as previously described by Snowflake, was initiated by compromised customer credentials purchased from cybercrime forums or obtained through information-stealing malware such as Lumma, MetaStealer, Raccoon, RedLine, RisePro, and Vidar.

See also: 23andMe: Canadian and UK authorities investigate data breach 

In several cases, malware infections have been detected on contractor systems that were used for personal activities, such as gaming and downloading pirated software, which is a known means of distributing malware.

Unauthorized access to customer instances has paved the way for a reconnaissance tool called FROSTBITE (also known as “rapeflake”), which is used to execute SQL queries and collect information about users, current roles, current IPs, session IDs, and organization names.

Mandiant said it was unable to obtain a full sample of FROSTBITE. The company also noted the use of the legitimate utility DBeaver Ultimate to connect and execute SQL queries on Snowflake instances. The final stage of the attack involves executing commands by the adversary to extract data.

Read more: Account breaches surpass Ransomware as top cyberthreat

Snowflake, in an updated advisory, said it is working closely with its customers to strengthen security . It also said it is developing a plan that will require the implementation of advanced security controls, such as multi-factor authentication (MFA) and network policies.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The attacks, according to Mandiant, have become extremely successful due to three key factors: lack of multi-factor authentication (MFA), non-periodic rotation of credentials, and lack of controls to ensure access only from trusted locations.

“The earliest date of an infostealer infection observed that is associated with a credential exploited by the threat actor dates back to November 2020,” Mandiant said. It added that it “has identified hundreds of Snowflake customer credentials exposed via infostealers since 2020.”.

"This campaign highlights the consequences of the large quantities of credentials circulating in the cyber theft market and may reflect a specific focus by threat actors on similar SaaS platforms.".

The findings highlight the growing demand for information thieves and the pervasive threat they pose to organizations, leading to the regular emergence of new thief variants, such as AsukaStealer, Cuckoo, Iluria, k1w1, SamsStealer, and Seidr, which are sold to other criminals.

Snowflake

Read also: Northern Minerals reveals data breach

“In February, Sultan, the name behind the malware , shared an image of the Lumma and Raccoon thieves, depicted together in a battle against antivirus solutions,” Cyfirma said in a recent analysis. “This suggests collaboration between threat actors, as they join forces and share infrastructure to achieve their goals.”

Source: thehackernews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS