SoatDev IT Consulting
SoatDev IT Consulting
  • About us
  • Expertise
  • Services
  • How it works
  • Contact Us
  • News
  • June 3, 2024
  • Rss Fetcher
Illustration of a phone with yellow caution tape running over it.
Illustration by Amelia Holowaty Krales / The Verge

A Ticketmaster data breach that allegedly includes details for 560 million accounts and another one affecting Santander have been linked to their accounts at Snowflake, a cloud storage provider. However, Snowflake says there’s no evidence its platform is at fault.

A joint statement to that effect made last night with CrowdStrike and Mandiant, two third-party security companies investigating the incident, lends additional credibility to the claim. Also, an earlier third-party report saying bad actors generated session tokens and may have compromised “hundreds” of Snowflake accounts has now been removed. Hudson Rock, the security firm behind that report, posted a statement of its own today on LinkedIn: “In accordance to a letter we received from Snowflake’s legal counsel, we have decided to take down all content related to our report.”

A post from Snowflake says, “To date, we do not believe this activity is caused by any vulnerability, misconfiguration, or malicious activity within the Snowflake product. Throughout the course of our ongoing investigation, we have promptly informed the limited number of customers who we believe may have been impacted.”

The joint statement says the attacks appear to be a “targeted campaign” focused on accounts without multifactor authentication. Snowflake has also released instructions for customers to review their accounts for unusual activity and ways to set up account and network policies to prevent similar attacks.

Snowflake, CrowdStrike, and Mandiant:

We have not identified evidence suggesting this activity was caused by a vulnerability, misconfiguration, or breach of Snowflake’s platform;

We have not identified evidence suggesting this activity was caused by compromised credentials of current or former Snowflake personnel;

This appears to be a targeted campaign directed at users with single-factor authentication;

As part of this campaign, threat actors have leveraged credentials previously purchased or obtained through infostealing malware; and

We did find evidence that a threat actor obtained personal credentials to and accessed demo accounts belonging to a former Snowflake employee. It did not contain sensitive data. Demo accounts are not connected to Snowflake’s production or corporate systems. The access was possible because the demo account was not behind Okta or Multi-Factor Authentication (MFA), unlike Snowflake’s corporate and production systems.

Ticketmaster’s parent company, Live Nation, which waited 11 days to confirm the data breach in a note to investors late Friday evening, has not provided any additional details about what information has been compromised or responded to inquiries.

Previous Post
Next Post

Recent Posts

  • Octonions sometimes associate
  • Looking for keys under the lamppost
  • Why Intempus thinks robots should have a human physiological state
  • 48 hours left: What you won’t want to miss at the 20th TechCrunch Disrupt in October
  • Last 24 hours: TechCrunch Disrupt 2025 Early Bird Deals will fly away after today

Categories

  • Industry News
  • Programming
  • RSS Fetched Articles
  • Uncategorized

Archives

  • May 2025
  • April 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023

Tap into the power of Microservices, MVC Architecture, Cloud, Containers, UML, and Scrum methodologies to bolster your project planning, execution, and application development processes.

Solutions

  • IT Consultation
  • Agile Transformation
  • Software Development
  • DevOps & CI/CD

Regions Covered

  • Montreal
  • New York
  • Paris
  • Mauritius
  • Abidjan
  • Dakar

Subscribe to Newsletter

Join our monthly newsletter subscribers to get the latest news and insights.

© Copyright 2023. All Rights Reserved by Soatdev IT Consulting Inc.