{"id":230579,"date":"2024-06-10T19:06:23","date_gmt":"2024-06-10T19:06:23","guid":{"rendered":"https:\/\/michigandigitalnews.com\/index.php\/2024\/06\/10\/snowflake-enforces-mfa-as-data-breach-probe-continues\/"},"modified":"2025-06-25T17:17:26","modified_gmt":"2025-06-25T17:17:26","slug":"snowflake-enforces-mfa-as-data-breach-probe-continues","status":"publish","type":"post","link":"https:\/\/michigandigitalnews.com\/index.php\/2024\/06\/10\/snowflake-enforces-mfa-as-data-breach-probe-continues\/","title":{"rendered":"Snowflake enforces MFA as data breach probe continues"},"content":{"rendered":"<p> [ad_1]<br \/>\n<br \/><img decoding=\"async\" src=\"https:\/\/readwrite.com\/wp-content\/uploads\/2024\/06\/Snowflake-enforces-MFA-as-data-breach-probe-continues-900x600.png\" \/><\/p>\n<div>\n<p>Cloud data analytics platform <a href=\"https:\/\/readwrite.com\/data-industry-experts-discuss-ai-advancements\/\">Snowflake<\/a> announced that it will enforce multi-factor authentication following what might be one of the <a href=\"https:\/\/www.wired.com\/story\/snowflake-breach-advanced-auto-parts-lendingtree\/\" target=\"_blank\" rel=\"noopener\">largest data breaches<\/a> on record.<\/p>\n<p>This decision was prompted by a breach noticed last month by Hudson Rock analysts, involving a <a href=\"https:\/\/readwrite.com\/26-billion-online-records-exposed-in-mother-of-all-data-breaches\/\">massive data theft<\/a> from Ticketmaster, Spanish bank Santander, and potentially hundreds of millions of files from Advance Auto Parts\u2014all of whom are Snowflake clients.<\/p>\n<p>Snowflake, a platform that hosts massive datasets for corporations, revealed that hackers had been using stolen credentials to try to infiltrate its customer accounts.<\/p>\n<p>Despite Snowflake launching legal actions against Hudson Rock, forcing them to <a href=\"https:\/\/www.theregister.com\/2024\/06\/04\/snowflake_report_pulled\/\" target=\"_blank\" rel=\"noopener\">withdraw<\/a> their report, the company acknowledged that it was investigating \u201ca targeted threat campaign against some Snowflake customer accounts.\u201d At the same time, <a href=\"https:\/\/techcrunch.com\/2024\/06\/07\/snowflake-ticketmaster-lendingtree-customer-data-breach\/\" target=\"_blank\" rel=\"noopener\">TechCrunch<\/a> reported the discovery of a trove of Snowflake customer passwords online, available to hackers. Snowflake had at first signaled that only a \u201climited\u201d number of customer accounts were compromised.<\/p>\n<p>However, the news outlet reported that LendingTree\u2019s subsidiary, QuoteWizard, also suffered a data breach at Snowflake. \u201cWe can confirm that we use Snowflake for our business operations, and that we were notified by them that our subsidiary, QuoteWizard, may have had data impacted by this incident,\u201d a spokesperson stated.<\/p>\n<h2>Data breach reported on BreachForums<\/h2>\n<p>Much of the drama involving Snowflake has unfolded on BreachForums, a well-known cybercrime marketplace. This site was shut down by the FBI in mid-May, only to be replaced by a new version. This iteration is allegedly managed by the hacker group ShinyHunters, who claim they are trading 560 million records from Ticketmaster and 30 million from Santander.<\/p>\n<p>Both organizations have acknowledged these data breaches. <a href=\"https:\/\/www.sec.gov\/Archives\/edgar\/data\/1335258\/000133525824000081\/lyv-20240520.htm\" target=\"_blank\" rel=\"noopener\">Ticketmaster<\/a> has specifically attributed its breach to Snowflake, whereas <a href=\"https:\/\/www.santander.com\/en\/stories\/statement\" target=\"_blank\" rel=\"noopener\">Santander<\/a> has reported unauthorized access to a database managed by a third-party provider, without confirming the extent of the breach.<\/p>\n<p>Recently, a BreachForums group with the username Sp1d3r has spotted two additional companies affected by the Snowflake incident. According to Sp1d3r, they have 3TB worth of data for 380 million customers from Advance Auto Parts and information in regards to 190 million customers from financial services firm LendingTree and its subsidiary QuoteWizard. <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/advance-auto-parts-stolen-data-for-sale-after-snowflake-attack\/\" target=\"_blank\" rel=\"noopener\">BleepingComputer<\/a> has verified the customer data related to Advance Auto Parts.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">\ud83d\udea8UPDATE: Sp1d3r claims to have stolen 3TB of data from @ AdvanceAutoParts via Snowflake breach. Allegedly includes 380M customer profiles, 140M order records, and more. Data is up for sale for $1.5M.<a href=\"https:\/\/t.co\/asHVxtHFyZ\">https:\/\/t.co\/asHVxtHFyZ<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/DataBreach?src=hash&amp;ref_src=twsrc%5Etfw\">#DataBreach<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/CyberSecurity?src=hash&amp;ref_src=twsrc%5Etfw\">#CyberSecurity<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/Snowflake?src=hash&amp;ref_src=twsrc%5Etfw\">#Snowflake<\/a> <a href=\"https:\/\/t.co\/DeSqRPnBTP\">pic.twitter.com\/DeSqRPnBTP<\/a><\/p>\n<p>\u2014 SOCRadar\u00ae (@socradar) <a href=\"https:\/\/twitter.com\/socradar\/status\/1798657170726375775?ref_src=twsrc%5Etfw\">June 6, 2024<\/a><\/p>\n<\/blockquote>\n<p>The LendingTree spokesperson said, \u201cWe take these matters seriously, and immediately after hearing from [Snowflake] launched an internal investigation.\u201d They added, \u201cAs of this time, it does not appear that consumer financial account information was impacted, nor information of the parent entity, LendingTree.\u201d<\/p>\n<h2>Snowflake reveals details about threat actors<\/h2>\n<p>After acknowledging that accounts had been targeted, Snowflake provided further information about the incident. Brad Jones, the chief information security officer at Snowflake, explained in a <a href=\"https:\/\/community.snowflake.com\/s\/question\/0D5VI00000Emyl00AB\/detecting-and-preventing-unauthorized-user-access\" target=\"_blank\" rel=\"noopener\">post<\/a> that threat actors used login details that had been \u201cpurchased or obtained through infostealing malware,\u201d which is designed to pull usernames and passwords from devices that have been compromised. He described the incident as a \u201ctargeted campaign directed at users with single-factor authentication.\u201d<\/p>\n<p>In the same post, Jones mentioned that Snowflake, with the help of cybersecurity firms CrowdStrike and Mandiant, found no evidence that the attack was \u201ccaused by compromised credentials of current or former Snowflake personnel.\u201d However, he noted that a former employee\u2019s demo accounts were accessed but maintained that they \u201cdid not contain sensitive data.\u201d<\/p>\n<p>In a separate <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/unc5537-snowflake-data-theft-extortion\" target=\"_blank\" rel=\"noopener\">blog post<\/a> by Mandiant, the company reiterated: \u201cMandiant\u2019s investigation has not found any evidence to suggest that unauthorized access to Snowflake customer accounts stemmed from a breach of Snowflake\u2019s enterprise environment.\u201d However, it added that every incident it had responded to associated with the campaign \u201cwas traced back to compromised customer credentials.\u201d ReadWrite reached out to Snowflake, however, the company directed us to Jones\u2019 post for more information.<\/p>\n<p>In addition, the US Cybersecurity and Infrastructure Security Agency has issued an <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2024\/06\/03\/snowflake-recommends-customers-take-steps-prevent-unauthorized-access\" target=\"_blank\" rel=\"noopener\">alert<\/a> concerning the Snowflake incident. Similarly, Australia\u2019s Cyber Security Center has <a href=\"https:\/\/www.cyber.gov.au\/about-us\/view-all-content\/alerts-and-advisories\/increased-cyber-threat-activity-targeting-snowflake-customers\" target=\"_blank\" rel=\"noopener\">admitted<\/a> being \u201caware of successful compromises of several companies utilizing Snowflake environments.\u201d<\/p>\n<p>ReadWrite has reached out to Snowflake and Live Nation for comment.<\/p>\n<p><em>Featured image: Ideogram<\/em><\/p>\n<\/p><\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><br \/>\n<br \/>[ad_2]<br \/>\n<br \/><a href=\"https:\/\/readwrite.com\/snowflake-enforces-mfa-data-breach-probe\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[ad_1] Cloud data analytics platform Snowflake announced that it will enforce multi-factor authentication following what might be one of the largest data breaches on record.<\/p>\n","protected":false},"author":1,"featured_media":230580,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"categories":[152],"tags":[],"_links":{"self":[{"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/posts\/230579"}],"collection":[{"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/comments?post=230579"}],"version-history":[{"count":0,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/posts\/230579\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/media\/230580"}],"wp:attachment":[{"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/media?parent=230579"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/categories?post=230579"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/tags?post=230579"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}