According to the latest news, the cloud-based data storage and analytics giant Snowflake has supposedly suffered a breach according to researchers that interacted with a certain Threat Actor known as ‘whitewarlock’ on the deep web hacking forum ‘exploit[.]in’. The claims are currently not corroborated by the Snowflake team.
Cyberint found the original compromised machine potentially exploited by ‘whitewarlock’. Over 500 demo environment instances were found included in the malware log. The compromised machine is linked to a current active employee of Snowflake, a sales engineer.
It is assumed that the Threat Actor could gain access to prospect and sales-related environments and newly onboarded production accounts. However, such access isn’t expected to grant the type of data that the Threat Actor claims to hold. Furthermore, Snowflake stated, alongside cybersecurity companies that it employed to investigate the incident, did not find evidence showing the attack was “caused by compromised credentials of current or former Snowflake personnel.”
BACKGROUND
Snowflake is a cloud-based data storage and analytics company that services over 9,400 customers. Researchers investigating an independent security breach of ‘Santander Group’ have reportedly found evidence suggesting that the aforementioned breach was instigated by a compromised Snowflake account. The Threat Actor ‘whitewarlock’ suggested that as many as 400 clients were involved in the breach and attempted to extort Snowflake to pay 20 million dollars to purchase the exfiltrated data back but has received no reply.
Who is Whitewarlock?
The Threat Actor Whitewarlock posted on the deep web hacker forum ‘exploit[.]in’ breached data related to ‘Santander group’ on May 23rd . The forum account was created on the same day as the post, no other activity was found related to the account. As of May 31st, no other data is being sold by the Threat Actor, at least on the forum. Cyberint also searched for the moniker and its twists across other sources in an attempt to link to any other deep web or darknet forums, however, no such corroborating data was found.