4 ms·
The dark web and info stealing malware are the source of the hacks. My worry is not only that consumers get numb to breaches, but they consume rampant misinfor
by beardedwizard 2y ago
The dark web and info stealing malware are the source of the hacks.
My worry is not only that consumers get numb to breaches, but they consume rampant misinformation and have no idea how to hold appropriate parties accountable.
How many times have you held AWS accountable for stolen access keys?
Was it AWS fault when rabbit leaked their own keys?
Is it snowflakes fault when you lose your creds to infostealing malware?
How should snowflake enforce mfa on machine service account credentials?
The answers are no, no, and they can not possibly. Not even hyperscalers have this magic.
- edm0nd 2y agoEh, iirc the source of the hack was just regular stealers like Redline, not "the dark web". It was actually Snowflakes fault. The threat actors were able to find a test/demo account they could log into and from there they were able to access prod things they shouldnt have.
- beardedwizard 2y agoThis is exactly the kind of comment I'm talking about. You have not read anything from snowflake, mandiant or crowdstrike on this, and you haven't even read the cnn article that has snowflakes response on this. The snowflake demo account has nothing to do with it.
- edm0nd 2y agoNo, its what happened 100%. Funnily enough, its YOU who hasnt read anything. https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion https://cloud.google.com/blog/topics/threat-intelligence/unc... "In April 2024, Mandiant received threat intelligence on database records that were subsequently determined to have originated from a victim’s Snowflake instance. Mandiant notified the victim, who then engaged Mandiant to investigate suspected data theft involving their Snowflake instance. During this investigation, Mandiant determined that the organization’s Snowflake instance had been compromised by a threat actor using credentials previously stolen via infostealer malware. The threat actor used these stolen credentials to access the customer’s Snowflake instance and ultimately exfiltrate valuable data. At the time of the compromise, the account did not have multi-factor authentication (MFA) enabled." https://www.symmetry-systems.com/blog/what-we-know-so-far-about-the-snowflake-breach/ https://www.symmetry-systems.com/blog/what-we-know-so-far-ab... "Snowflake has confirmed that a threat actor obtained credentials of a single former employee and accessed demo accounts they had access to. Snowflake asserts these accounts contained no “sensitive” data and were isolated from production and corporate systems. However, unlike Snowflake’s core systems, which are protected by Okta and Multi-Factor Authentication (MFA), these dormant demo accounts lacked such safeguards. "