Pure Storage confirms data breach after Snowflake account hack
ID: 22855b79-d7c1-5d71-b9a3-e91db0445c47
STIX ID: report--22855b79-d7c1-5d71-b9a3-e91db0445c47
Feed Name: Bleeping Computer
Pure Storage confirmed a breach of a Snowflake analytics workspace that exposed telemetry data and customer identifiers; Snowflake, Mandiant, and CrowdStrike link a wider campaign (tracked as UNC5537) to the use of credentials harvested by multiple infostealer malware families (Vidar, RedLine, Racoon, RisePro, Lumm, Metastealer). The campaign exploits accounts without MFA or network allowlists, has led to hundreds of compromised Snowflake credentials and notifications to ~165 organizations, and has resulted in large-scale data exfiltration and extortion, including multiple high-profile breaches and datasets being sold.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
