Hacker in Snowflake Extortions May Be a U.S. Soldier
ID: e4fee1ef-48fd-5a0f-88de-1d7094932e0e
STIX ID: report--e4fee1ef-48fd-5a0f-88de-1d7094932e0e
Feed Name: Krebs on Security
This KrebsOnSecurity investigation documents a large criminal campaign that harvested Snowflake account credentials (often accounts protected only by username/password) to steal and extort sensitive datasets from dozens of organizations — notably AT&T (≈110M records). The piece profiles the prolific threat actor "Kiberphant0m" (and linked aliases such as Reverseshell, Buttholio, Vars_Secc), outlines their sales/leaks of stolen data, SIM-swapping and DDoS/IoT botnet activity, and notes arrests of two suspects while the primary actor remains at large and continues public extortion.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
