Close Menu
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

What's On

Invincible VS Is A 3v3 Fighting Game Based On The Popular Series

9 June 2025

Samsung Galaxy Z Fold 7, Z Flip 7 Unpacked Event Tipped to Be Held Mid-July

9 June 2025

Planet of Lana II: Children of the Leaf Is An Emotional Puzzle Platformer Out In 2026

9 June 2025
Facebook X (Twitter) Instagram
Just In
  • Invincible VS Is A 3v3 Fighting Game Based On The Popular Series
  • Samsung Galaxy Z Fold 7, Z Flip 7 Unpacked Event Tipped to Be Held Mid-July
  • Planet of Lana II: Children of the Leaf Is An Emotional Puzzle Platformer Out In 2026
  • Vivo Y300c With 6,500mAh Battery, 50-Megapixel Dual Rear Cameras Launched: Price, Specifications
  • Vivo Y300c – Price in India, Specifications (9th June 2025)
  • The Next Call Of Duty Is Black Ops 7, And It Features A Co-Op Campaign Set In 2035
  • Super Meat Boy 3D Places The Eponymous Meat Pile In A 3D Platformer
  • iOS 26 to Feature “Liquid Glass” UI Elements in Anticipation of 2027 iPhone Models: Report
Facebook X (Twitter) Instagram Pinterest Vimeo
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release
Subscribe
Best in TechnologyBest in Technology
Home » The Snowflake Attack May Be Turning Into One of the Largest Data Breaches Ever
News

The Snowflake Attack May Be Turning Into One of the Largest Data Breaches Ever

News RoomBy News Room6 June 20244 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email

Since Snowflake acknowledged accounts had been targeted, it has provided some more information about the incident. Brad Jones, Snowflake’s CISO, said in a blog post that threat actors used login details to accounts that had been “purchased or obtained through infostealing malware,” which is designed to pull usernames and passwords from devices that have been compromised. The incident appears to be a “targeted campaign directed at users with single-factor authentication,” Jones added.

Jones’ post said Snowflake, alongside cybersecurity companies CrowdStrike and Mandiant, which it employed to investigate the incident, did not find evidence showing the attack was “caused by compromised credentials of current or former Snowflake personnel.” However, it has found one former employee’s demo accounts were accessed, claiming they did not contain sensitive data.

When asked about potential breaches of specific companies’ data, a Snowflake person pointed to Jones’s statement: “We have not identified evidence suggesting this activity was caused by a vulnerability, misconfiguration, or breach of Snowflake’s platform.” The company did not provide an on-record comment clarifying what was meant by a “breach.” (Security company Hudson Rock said it removed a research post including various unverified claims about the Snowflake incident after receiving a legal letter from Snowflake).

The US Cybersecurity and Infrastructure Security Agency has issued an alert about the Snowflake incident, while Australia’s Cyber Security Center said it is “aware of successful compromises of several companies utilizing Snowflake environments.”

Unclear Origins

Little is known about the Sp1d3r account advertising data on BreachForums, and it is not clear whether ShinyHunters obtained the data it was selling from another source or directly from victims’ Snowflake accounts—information about a Ticketmaster and Santander breach was originally posted on another cybercrime forum by a new user called “SpidermanData.”

The Sp1d3r account posted on BreachForums that the 2 terabytes of alleged LendingTree and QuoteWizard data was for sale for $2 million; while 3TB of data allegedly from Advance Auto Parts would cost someone $1.5 million. “The price set by the threat actor appears extremely high for a typical listing posted to BreachForums,” says Chris Morgan, a senior cyber threat intelligence analyst at security firm ReliaQuest.

Morgan says the legitimacy of Sp1d3r is not clear; however, he points out there is a nod to teenage hacking group Scattered Spider. “Interestingly, the threat actor’s profile picture is taken from an article referencing the threat group Scattered Spider, although it is unclear whether this is to make an intentional association with the threat group.”

While the exact source of the alleged data breaches is unclear, the incident highlights how interconnected companies can be when relying upon products and services from third-party providers. “I think a lot of this is just a recognition of how interdependent these services now are and how hard it is to control the security posture of third parties,” security researcher Tory Hunt told WIRED when the incidents first emerged.

As part of its response to the attacks, Snowflake has told all customers to make sure they enforce multi-factor authentication on all accounts and only allow traffic from authorized users or locations. Companies that have been impacted should also reset their Snowflake login credentials. Enabling multi-factor authentication vastly reduces the chances that online accounts will be compromised. As mentioned, TechCrunch reported this week that it has seen “hundreds of alleged Snowflake customer credentials” taken by infostealing malware from computers of people who have accessed Snowflake accounts.

In recent years, coinciding with more people working from home since the Covid-19 pandemic, there has been a rise in the use of infostealer malware. “Infostealers have become more popular because they’re in high demand and pretty easy to create,” says Ian Gray, the vice president of intelligence at security company Flashpoint. Hackers have been seen to be copying or modifying existing infostealers and selling them on for as little as $10 for all the login details, cookies, files, and more from one infected device.

“This malware can be delivered in different ways and targets sensitive info like browser data (cookies and credentials), credit cards, and cryptowallets,” Gray says. “Hackers might comb through the logs for enterprise credentials to break into accounts without permission.”

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCMF Phone 1 Launch Confirmed; Rear Panel Design Teased Ahead of Debut
Next Article Google Messages is getting a feature that could save your life

Related Articles

News

How to Advocate for Trans Rights in Your Community

8 June 2025
News

How to Buy a Bike Helmet

8 June 2025
News

The Best Read-It-Later Apps for Curating Your Longreads

8 June 2025
News

A New Law of Nature Attempts to Explain the Complexity of the Universe

8 June 2025
News

Review: Dell 14 Plus

8 June 2025
News

Bill Atkinson, Macintosh Pioneer and Inventor of Hypercard, Dies at 74

8 June 2025
Demo
Top Articles

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202495 Views

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 202493 Views

5 laptops to buy instead of the M4 MacBook Pro

17 November 202466 Views

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Latest News
Gaming

The Next Call Of Duty Is Black Ops 7, And It Features A Co-Op Campaign Set In 2035

News Room9 June 2025
Gaming

Super Meat Boy 3D Places The Eponymous Meat Pile In A 3D Platformer

News Room9 June 2025
Phones

iOS 26 to Feature “Liquid Glass” UI Elements in Anticipation of 2027 iPhone Models: Report

News Room9 June 2025
Most Popular

The Spectacular Burnout of a Solar Panel Salesman

13 January 2025123 Views

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202495 Views

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 202493 Views
Our Picks

Vivo Y300c With 6,500mAh Battery, 50-Megapixel Dual Rear Cameras Launched: Price, Specifications

9 June 2025

Vivo Y300c – Price in India, Specifications (9th June 2025)

9 June 2025

The Next Call Of Duty Is Black Ops 7, And It Features A Co-Op Campaign Set In 2035

9 June 2025

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us
© 2025 Best in Technology. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.