this post was submitted on 01 Jun 2024
6 points (87.5% liked)

Cybersecurity

5685 readers
72 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !cybersecurity@lemmy.capebreton.social !securitynews@infosec.pub !netsec@links.hackliberty.org !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 1 year ago
MODERATORS
top 2 comments
sorted by: hot top controversial new old
[โ€“] autotldr@lemmings.world 2 points 5 months ago

This is the best summary I could come up with:


Infosec analysts at Hudson Rock believe Snowflake was compromised by miscreants who used that intrusion to steal data on hundreds of millions of people from Ticketmaster, Santander, and potentially other customers of the cloud storage provider.

This week one or more crooks going by the handle ShinyHunters was spotted putting what's understood to be 1.3TB of data stolen from Ticketmaster up for sale on an underworld forum.

Ticketmaster's parent Live Nation confirmed today in a filing to the US securities watchdog it had "identified unauthorized activity within a third-party cloud database environment containing company data."

"On May 27, 2024, a criminal threat actor offered what it alleged to be company user data for sale via the dark web," the corporation added.

Today, Hudson Rock claimed all that info from Ticketmaster and Santander, and potentially hundreds of other organizations, was stolen from one vendor in particular: Snowflake.

These credentials were supposedly used to sign into the employee's ServiceNow account, apparently side-stepping Snowflake's Okta-based access management system.


The original article contains 838 words, the summary contains 165 words. Saved 80%. I'm a bot and I'm open source!

[โ€“] Alphane_Moon@lemmy.ml 2 points 5 months ago* (last edited 5 months ago)

Interesting that Okta seems to be involved in the alleged breaches at Snowflake as previous reported in this community.

Some more context on this: Post 1, Post 2.

Kevin Beaumont, a Mastadon cybersecurity posters, reports that a tool called rapeflake was used to harvest account credentials.