logo

Hacker in Snowflake Extortions May Be a U.S. Soldier

ID: e4fee1ef-48fd-5a0f-88de-1d7094932e0e

STIX ID: report--e4fee1ef-48fd-5a0f-88de-1d7094932e0e

Feed Name: Krebs on Security

Threat Score
80/100

Date Published: 2024-11-27

Date Updated: 2026-04-19

Author: BrianKrebs

...
...

This KrebsOnSecurity investigation documents a large criminal campaign that harvested Snowflake account credentials (often accounts protected only by username/password) to steal and extort sensitive datasets from dozens of organizations — notably AT&T (≈110M records). The piece profiles the prolific threat actor "Kiberphant0m" (and linked aliases such as Reverseshell, Buttholio, Vars_Secc), outlines their sales/leaks of stolen data, SIM-swapping and DDoS/IoT botnet activity, and notes arrests of two suspects while the primary actor remains at large and continues public extortion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.