{"id":101360,"date":"2024-05-31T22:03:00","date_gmt":"2024-05-31T22:03:00","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2024\/05\/31\/massive-ticketmaster-santander-data-breaches-linked-to-snowflake-cloud-storage\/"},"modified":"2024-05-31T22:03:00","modified_gmt":"2024-05-31T22:03:00","slug":"massive-ticketmaster-santander-data-breaches-linked-to-snowflake-cloud-storage","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2024\/05\/31\/massive-ticketmaster-santander-data-breaches-linked-to-snowflake-cloud-storage\/","title":{"rendered":"Massive Ticketmaster, Santander data breaches linked to Snowflake cloud storage"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">An alleged data breach potentially affecting as many as <a href=\"https:\/\/hackread.com\/hackers-ticketmaster-data-breach-560m-users-sale\/\" target=\"_blank\" rel=\"noopener\">560 million Ticketmaster accounts<\/a> and a confirmed one for Santander Bank may have stemmed from attacks on the cloud storage accounts with a company called Snowflake. As spotted <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/snowflake-account-hacks-linked-to-santander-ticketmaster-breaches\/\" target=\"_blank\" rel=\"noopener\">by <em>Bleeping Computer<\/em><\/a>, an investigation from <a href=\"https:\/\/www.hudsonrock.com\/blog\/snowflake-massive-breach-access-through-infostealer-infection\" target=\"_blank\" rel=\"noopener\">cybersecurity firm Hudson Rock<\/a> reports that a bad actor gained access to Ticketmaster and Santander by using the stolen credentials of a single Snowflake employee.<\/p>\n<\/div>\n<div>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">According to Hudson Rock, the hacker bypassed the authentication service Okta using these credentials and then generated session tokens to obtain a trove of information from Snowflake. In addition to Ticketmaster and Santander Bank, Hudson Rock suggests the hacker may have gained access to hundreds of other Snowflake customers. A few of the major brands that use the cloud storage service include AT&amp;T, HP, Instacart, DoorDash, NBCUniversal, and Mastercard.<\/p>\n<\/div>\n<div>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">Snowflake has seemingly disputed Hudson Rock\u2019s findings in its most recent response, <a href=\"https:\/\/community.snowflake.com\/s\/question\/0D5VI00000Emyl00AB\/detecting-and-preventing-unauthorized-user-access\" target=\"_blank\" rel=\"noopener\">saying that<\/a> while investigating \u201cpotentially unauthorized access to certain customer accounts,\u201d it \u201cobserved increased threat activity beginning mid-April 2024 from a subset of IP addresses and suspicious clients we believe are related to unauthorized access.\u201d <\/p>\n<\/div>\n<div>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">More details on those findings <a href=\"https:\/\/community.snowflake.com\/s\/article\/Communication-ID-0108977-Additional-Information\" target=\"_blank\" rel=\"noopener\">are available here,<\/a> but the company says that while a bad actor accessed a \u201cdemo account\u201d belonging to a former employee, it didn\u2019t contain sensitive information. It claims that \u201cTo date, we do not believe this activity is caused by any vulnerability, misconfiguration, or malicious activity within the Snowflake product.\u201d<\/p>\n<\/div>\n<div>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">Ticketmaster still has yet to confirm any breach, but <a href=\"https:\/\/x.com\/vxunderground\/status\/1796063116574314642\" target=\"_blank\">malware tracker vx-underground<\/a> says it can assert \u201cwith a high degree of confidence\u201d that the leaked data is legitimate. It notes that some of the leaked information dates back to the mid-2000s and includes full names, emails, addresses, phone numbers, hashed credit card numbers, and more.<\/p>\n<\/div>\n<div>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">Earlier this month, Santander <a href=\"https:\/\/www.santander.com\/en\/stories\/statement\" target=\"_blank\" rel=\"noopener\">published a statement<\/a> to confirm that \u201ccertain information\u201d of customers in Chile, Spain, and Uruguay had been accessed. <em>The Verge<\/em> reached out to Ticketmaster and Santander with requests for comment but didn\u2019t immediately hear back.<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/www.theverge.com\/2024\/5\/31\/24168984\/ticketmaster-santander-data-breach-snowflake-cloud-storage\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>An alleged data breach potentially affecting as many as 560 million Ticketmaster accounts and a confirmed one for Santander Bank may have stemmed from attacks on the cloud storage accounts with a company called Snowflake. As spotted by Bleeping Computer, an investigation from cybersecurity firm Hudson Rock reports that a bad actor gained access to [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":101361,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-101360","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/101360","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=101360"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/101360\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/101361"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=101360"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=101360"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=101360"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}