{"id":80462,"date":"2024-06-10T16:54:36","date_gmt":"2024-06-10T16:54:36","guid":{"rendered":"https:\/\/neclink.com\/index.php\/2024\/06\/10\/mandiant-says-hackers-stole-a-significant-volume-of-data-from-snowflake-customers\/"},"modified":"2024-06-10T16:54:36","modified_gmt":"2024-06-10T16:54:36","slug":"mandiant-says-hackers-stole-a-significant-volume-of-data-from-snowflake-customers","status":"publish","type":"post","link":"https:\/\/neclink.com\/index.php\/2024\/06\/10\/mandiant-says-hackers-stole-a-significant-volume-of-data-from-snowflake-customers\/","title":{"rendered":"Mandiant says hackers stole a &#8216;significant volume of data&#8217; from Snowflake customers"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">Security researchers say they believe financially motivated cybercriminals have stolen a \u201csignificant volume of data\u201d from hundreds of customers hosting their vast banks of data with cloud storage giant Snowflake.<\/p>\n<p class=\"wp-block-paragraph\">Incident response firm Mandiant, which is working with Snowflake to investigate the recent spate of data thefts, said <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/unc5537-snowflake-data-theft-extortion\" target=\"_blank\" rel=\"noreferrer noopener\">in a blog post Monday<\/a> that the two firms have notified around 165 customers that their data may have been stolen.<\/p>\n<p class=\"wp-block-paragraph\">It\u2019s the first time that the number of affected Snowflake customers has been disclosed since the account hacks began in April. Snowflake has said little to date about the attacks, only that a \u201climited number\u201d of its customers are affected. The cloud data giant has more than 9,800 corporate customers, like healthcare organizations, retail giants and some of the world\u2019s largest tech companies, which use Snowflake for data analytics.<\/p>\n<p class=\"wp-block-paragraph\">So far, <a href=\"https:\/\/techcrunch.com\/2024\/05\/31\/live-nation-confirms-ticketmaster-was-hacked-says-personal-information-stolen-in-data-breach\/\" target=\"_blank\" rel=\"noreferrer noopener\">only Ticketmaster<\/a> and <a href=\"https:\/\/techcrunch.com\/2024\/06\/07\/snowflake-ticketmaster-lendingtree-customer-data-breach\/\" target=\"_blank\" rel=\"noreferrer noopener\">LendingTree have confirmed<\/a> data thefts where their stolen data was hosted on Snowflake. Several other Snowflake customers say they are currently investigating possible data thefts from their Snowflake environments.<\/p>\n<p class=\"wp-block-paragraph\">Mandiant said the threat campaign is \u201congoing,\u201d suggesting the number of Snowflake corporate customers reporting data thefts may rise.<\/p>\n<p class=\"wp-block-paragraph\">In <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/unc5537-snowflake-data-theft-extortion\" target=\"_blank\" rel=\"noreferrer noopener\">its blog post<\/a>, Mandiant attributed the account hacks to UNC5537, an as-yet-unclassified cybercriminal gang that the security firm says is motivated by making money. The gang, which Mandiant says includes members in North America and at least one member in Turkey, attempts to extort its victims into paying to get their files back or to prevent the public release of their customers\u2019 data.<\/p>\n<p class=\"wp-block-paragraph\">Mandiant confirmed the attacks \u2014 which rely on the use of \u201cstolen credentials to access the customer\u2019s Snowflake instance and ultimately exfiltrate valuable data\u201d \u2014 date back to at least April 14, when its researchers first identified evidence of improper access to an unnamed Snowflake customer\u2019s environment. Mandiant said it notified Snowflake to its customer account intrusions on May 22.<\/p>\n<p class=\"wp-block-paragraph\">The security firm said the majority of stolen credentials used by UNC5537 were \u201cavailable from historical infostealer infections,\u201d with some dating as far back as 2020. Mandiant\u2019s findings <a href=\"https:\/\/community.snowflake.com\/s\/question\/0D5VI00000Emyl00AB\/detecting-and-preventing-unauthorized-user-access\" target=\"_blank\" rel=\"noreferrer noopener\">confirm Snowflake\u2019s limited disclosure<\/a>, which said there wasn\u2019t a direct breach of Snowflake\u2019s own systems but blamed its customer accounts for not using multi-factor authentication (MFA).\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Last week, TechCrunch found circulating online <a href=\"https:\/\/techcrunch.com\/2024\/06\/05\/snowflake-customer-passwords-found-online-infostealing-malware\/\" target=\"_blank\" rel=\"noreferrer noopener\">hundreds of Snowflake customer credentials stolen by malware<\/a> that infected the computers of staffers who have access to their employer\u2019s Snowflake environment. The number of credentials available online linked to Snowflake environments suggests an ongoing risk to customers who have not yet changed their passwords or enabled MFA.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Mandiant said it has also seen \u201chundreds of customer Snowflake credentials exposed via infostealers.\u201d<\/p>\n<p class=\"wp-block-paragraph\">For its part, Snowflake does not require its customers to use by default or enforce the security feature\u2019s use. In a brief update on Friday, Snowflake has said it\u2019s \u201cdeveloping a plan\u201d to enforce the use of MFA on its customers\u2019 accounts, but has not yet provided a timeline.<\/p>\n<p class=\"wp-block-paragraph\">Snowflake spokesperson Danica Stanczak declined to say why the company hasn\u2019t reset customer passwords or enforced MFA. Snowflake did not immediately comment on Mandiant\u2019s blog post Monday.<\/p>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n<p class=\"wp-block-paragraph\"><em>Do you know more about the Snowflake account intrusions? Get in touch. To contact this reporter, get in touch on Signal and WhatsApp at +1 646-755-8849, or <a href=\"https:\/\/techcrunch.com\/2024\/06\/10\/mandiant-hackers-snowflake-stole-significant-volume-data-customers\/mailto:zack.whittaker@techcrunch.com\" target=\"_blank\" rel=\"noreferrer noopener\">by email.<\/a> You can also send files and documents via <a href=\"https:\/\/techcrunch.com\/tips\" target=\"_blank\" rel=\"noreferrer noopener\">SecureDrop<\/a>.<\/em><\/p>\n<figure class=\"wp-block-embed is-type-wp-embed is-provider-techcrunch wp-block-embed-techcrunch\"\/>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2024\/06\/10\/mandiant-hackers-snowflake-stole-significant-volume-data-customers\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security researchers say they believe financially motivated cybercriminals have stolen a \u201csignificant volume of data\u201d from hundreds of customers hosting their vast banks of data<\/p>\n","protected":false},"author":1,"featured_media":80463,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[178],"tags":[],"class_list":["post-80462","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tech"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/posts\/80462","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/comments?post=80462"}],"version-history":[{"count":0,"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/posts\/80462\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/media\/80463"}],"wp:attachment":[{"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/media?parent=80462"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/categories?post=80462"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/tags?post=80462"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}