Pure Storage, a leading provider of cloud storage systems and services, has confirmed that its Snowflake workspace was compromised and attackers gained access to telemetry information.

Additionally, the exposed information included customer names, usernames, and email addresses, but no credentials or other data stored on customer systems were affected.
“ After a thorough investigation, Pure Storage has confirmed and addressed a security incident involving a third party who had temporarily gained unauthorized access to a Snowflake data analytics workspace ,” the company said
See also: Snowflake breach exposes customer data
The telemetry information exposed was used by Pure Storage to provide customer support services. “This information includes company names, LDAP usernames, email addresses, and the version number of the Purity.”
Pure Storage has taken steps to prevent further unauthorized access to the Snowflake workspace. Its investigation has not, at this time, identified any evidence of malicious activity in other parts of its customers' infrastructure.
The company said it is contacting customers about the incident and they have not detected any unusual activity on their systems either. More than 11,000 customers use Pure Storage's data storage platform, including large companies and organizations such as Meta, Ford, JP Morgan, NASA, NTT, AutoNation, Equinix and Comcast.
Snowflake attacks: At least 165 organizations were likely affected
In a joint report with Mandiant and CrowdStrike, Snowflake revealed that attackers are using stolen customer credentials to target accounts that are not protected by multi-factor authentication.
See also: Cylance: Data breach via third-party hacking
Mandiant linked the Snowflake attacks to a financially motivated threat actor, tracked as UNC5537. The attacker accessed Snowflake customer accounts using credentials stolen via info-stealer in 2020.
Snowflake and Mandiant have already notified approximately 165 organizations that may have been affected by these ongoing attacks.
Recent breaches at Santander, Ticketmaster and QuoteWizard/LendingTree have also been linked to the Snowflake attacks.

Protecting companies from attacks
To mitigate the risk of cyberattacks (e.g. Snowflake attacks), companies should take proactive measures to strengthen their cybersecurity defenses . Some steps they can take include:
- Employee training: Employees are often the first line of defense against cyber threats. As such, it is vital for companies to provide regular training and awareness programs on cybersecurity best practices . This can include topics such as recognizing phishing emails, creating strong passwords, and reporting suspicious activity.
- Regular software updates: Companies should ensure that all their software and systems are up to date with the latest security patches. Outdated software can leave vulnerabilities for attackers to exploit.
- Strong access controls: Restricting access to sensitive data and systems is essential to preventing insider threats. Companies should implement strict access controls, including multi-factor authentication, to ensure that only authorized individuals have access.
See also: New phishing attack distributes More_eggs malware
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
In conclusion, cybersecurity has become a critical aspect of running a successful business in today’s digital landscape. Companies need to be aware of the various types of cyber threats and take proactive steps to protect themselves. By prioritizing cybersecurity, businesses can mitigate the risks of cyberattacks and protect their operations, finances, and reputation.
Source: www.bleepingcomputer.com
