logo

Snowflake account hacks linked to Santander, Ticketmaster breaches

ID: e414e70c-7440-5dd3-800e-9fa07820e0c5

STIX ID: report--e414e70c-7440-5dd3-800e-9fa07820e0c5

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2024-05-31

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

A threat actor claimed to have accessed and exfiltrated data from Snowflake customer accounts after stealing employee credentials via an infostealer; Hudson Rock published claims that hundreds of customer instances were affected and the actor attempted extortion. Snowflake says the activity resulted from compromised customer accounts (not a product vulnerability), has notified affected customers, and published IOCs (including a custom exfiltration tool named 'RapeFlake' and DBeaver connection indicators) while urging MFA and account hardening.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.