
Snowflake ($SNOW), a cloud storage giant, has suffered a significant data breach. The breach was confirmed by Hudson Rock, who reported that the hacker gained access through an infostealer infection. A Snowflake employee named Audrey Delou, a Sales Engineer in EMEA, had her account compromised, which provided substantial access to sensitive data. GitLab's Snowflake account is also believed to have been compromised for a long time. Over 400 companies' data has been affected, and the hacker is demanding $20 million to return the data. Some companies have already paid the ransom. Snowflake has stated that there is no evidence suggesting the breach was due to a vulnerability or misconfiguration in their product, and they do not believe they are the source of the leaked customer credentials. The hacker reportedly used someone’s ServiceNow credentials to gain access.
400+ companies data has been compromised. The hacker wants Snowflake to pay them $20ms to get the data back but they're unresponsive. Some of the companies have already paid the hacker. The hacker found a way to login using someone's servicenow credentials. 😫 https://t.co/GrnOj7jJVF
$SNOW Updated on hack: We have no evidence suggesting this activity was caused by any vulnerability, misconfiguration, or breach of Snowflake’s product. Snowflake does not believe that it was the source of any of the leaked customer credentials. https://t.co/eSXnJDtpSa
Yes, the article claims that a single Snowflake employee named Audrey Delou (a Snowflake Sales Engineer in EMEA) had her account compromised. Really damning stuff given the level of access. If this plays out, and the hackers did execute on all this, it's probably one of the… https://t.co/fJOMd3HGiv https://t.co/ZI5fZFSevM


