Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Please enable JavaScript in your browser to complete this form.
    Loading
    What's Hot

    Get 1 Year of The Zero Byte for $30: Lawsuit Highlights Fake News

    October 21, 2024

    Get One Year of The Zero Byte for $5: How a Trump Win Could Unleash AI

    October 21, 2024

    Get One Year of The Zero Byte for $5: Sam Altman’s Eye-Scanning Orb Delivered

    October 17, 2024
    Facebook X (Twitter) Instagram
    The Zero ByteThe Zero Byte
    • AI
    • Tech
      1. Computing
      2. Cybersecurity
      3. Politics
      4. Smart Home
      5. Software
      6. Startups
      7. Streaming Services
      8. Virtual Reality
      9. View All

      OpenAI Unveils New AI Safety Research, Critics Call for More Action

      July 17, 2024

      Samsung Galaxy Book 4 Edge is among the first Copilot+ PCs to arrive

      June 20, 2024

      M4 MacBook Pros Expected to Launch in Late 2024

      June 19, 2024

      AI Cameras on UK Trains Use Amazon Tech to Monitor Passenger Emotions

      June 17, 2024

      Can You Trust ChatGPT-4o With Your Private Data?

      July 31, 2024

      ACLU Defends Your Right to Create Deepfakes

      July 24, 2024

      Apple, Nvidia, Anthropic Used YouTube Videos to Train AI

      July 16, 2024

      AI Spam Outranks Original News in Google Search Results

      July 2, 2024

      New Jersey’s $500M Plan to Lead in AI Innovation

      July 25, 2024

      ACLU Defends Your Right to Create Deepfakes

      July 24, 2024

      French AI Startups Thrived Until the Election Changed Everything

      June 28, 2024

      Auto Industry Calls Biden’s New Automatic Braking Rule “Impractical

      June 24, 2024

      Why Heat Pumps Are Gaining Popularity

      May 23, 2024

      Green and Blue-Green Roofs: The Ultimate Eco-Friendly Solution

      April 22, 2024

      Couple’s Journey to Eliminate Natural Gas from Their Home

      March 30, 2024

      Zoom Challenges Google and Microsoft with AI-Powered Documents

      August 6, 2024

      Download Paywalled Articles Easily with Quora’s Poe Chatbot Platform

      June 28, 2024

      Apple WWDC 2024 Live Blog: Major AI, iOS, and Software Updates Expected

      June 10, 2024

      Lightroom’s AI Tool Quickly Removes Unwanted Objects

      May 21, 2024

      Anthropic Unveils Method to Understand AI’s Inner Workings

      May 21, 2024

      OpenAI Dissolves Long-Term AI Risk Team Amid Growing Concerns

      May 17, 2024

      VSCO Launches Marketplace Connecting Photographers and Brands

      May 7, 2024

      Quora CEO Discusses AI, Poe Chatbot, and OpenAI’s Non-Competitive Role

      May 6, 2024

      Get One Year of The Zero Byte for Just $5

      September 26, 2024

      Spotify Expands Enterprise and Developer Tools with Backstage Platform

      April 30, 2024

      Rio: The AI News Anchor App Secures Funding from Curio

      April 26, 2024

      Substack Enhances Notes Feature with Twitter-Inspired Functionalities

      April 16, 2024

      Saga’s HoloBike: A Bizarre Virtual Reality Cycling Experience

      May 7, 2024

      Exploring the World Beyond Apple’s Vision Pro Headset

      April 20, 2024

      Disney Imagineer Builds Real-Life Lightsaber: Bringing Star Wars to Life

      April 8, 2024

      Apple’s Vision Pro Aims to Solve VR’s Biggest Problems: Comfort and Immersion

      April 8, 2024

      Get One Year of The Zero Byte for Just $5

      September 26, 2024

      Get One Year of The Zero Byte for Just $5

      September 25, 2024

      Get One Year of The Zero Byte for Just $30

      September 18, 2024

      AI Scientist Invents and Runs Its Own Experiments

      August 21, 2024
    • Gaming
      1. Gaming Hardware
      2. Game Reviews
      3. View All

      Game Devs at GDC Demand Change Amidst Internet Outrage

      March 26, 2024

      Retro Oddities: A Must-Own Gaming History Lesson in The Zero Byte Collection

      March 14, 2024

      Snag a PS5 Bundle with Marvel’s Spider-Man 2 for Just $399.99 Today

      March 11, 2024

      MSI Claw: A Formidable Challenger to the Steam Deck

      March 11, 2024

      Sonic Heroes Rumored to Make a Comeback: What We Know

      March 26, 2024

      Game Devs at GDC Demand Change Amidst Internet Outrage

      March 26, 2024

      Rise of the Ronin’s Innovative Feature: A New Industry Standard

      March 24, 2024

      Rise of the Ronin: A Masterful Blend of Gaming’s Finest Elements

      March 13, 2024

      Video Game Actors Strike Over AI Concerns

      July 25, 2024

      Carv Secures $10M Series A to Empower Gamers to Monetize Their Data

      April 25, 2024

      Raichu Mega Evolution Forms Imagined by Creative Pokemon Fan

      March 26, 2024

      Sonic Heroes Rumored to Make a Comeback: What We Know

      March 26, 2024
    • Gadgets
      1. New Gadgets
      2. Phones and Tech
      3. Wearables
      4. Gadget Reviews
      5. View All

      Acer Chromebook Plus: The Perfect Student Laptop Solution

      April 18, 2024

      OnePlus Unveils Its Own Take on Google’s Magic Eraser Feature

      April 3, 2024

      Do Smartphones Help or Harm Kids? Exploring the Pros and Cons

      March 29, 2024

      Google to Introduce AI-Powered Features on Pixel 8 Devices

      March 28, 2024

      Humane Ai Pin: A Flawed Glimpse into the Future of Wearable Tech

      April 11, 2024

      Withings ScanWatch 2 and Light: Effortless Elegance for the Tech-Weary

      March 11, 2024

      Acer Chromebook Plus: The Perfect Student Laptop Solution

      April 18, 2024

      AMD 3D V-Cache Processor to Avoid: The Zero Byte’s Recommendation

      March 26, 2024

      Microsoft Unveils Unexpected Surface Devices in Latest Launch

      March 22, 2024

      OnePlus 12 Screen: Is It Curved or Flat? Here’s What We Know

      March 16, 2024

      Top 9 TV Streaming Devices for 4K and HD: Our Best Picks

      June 19, 2024

      M4 MacBook Pros Expected to Launch in Late 2024

      June 19, 2024

      McLaren Artura Spider Hybrid: High Performance and Fun

      June 16, 2024

      Apple AI May Not Work on Millions of iPhones—But There’s Hope

      June 17, 2024
    • Science
      1. Health
      2. Space
      3. Psychology and Neuroscience
      4. Robots
      5. Space
      6. View All

      New Alzheimer’s Treatments Useless Without Early Diagnosis

      June 24, 2024

      Post-Pandemic Recovery: Challenges and Uncertainties Ahead

      June 24, 2024

      How to Exercise Safely During a Heat Wave

      June 22, 2024

      Tips to Stay Healthy and Avoid Illness This Summer

      June 15, 2024

      NASA Investigates Starliner Faults, Indefinite Delay in Space

      June 23, 2024

      What Happened Before the Big Bang?

      June 23, 2024

      SpaceX Starship Test Brings Mars Mission Closer

      June 6, 2024

      Searching for Ultralight Dark Matter Explained

      June 2, 2024

      Get One Year of The Zero Byte for $5: Most US Teens Use AI, Parents Unaware

      September 18, 2024

      New Alzheimer’s Treatments Useless Without Early Diagnosis

      June 24, 2024

      Arctic Zombie Fire Season Begins: What You Need to Know

      June 1, 2024

      Can AI Prove String Theory’s Accuracy in Describing Our World?

      May 26, 2024

      AI Scientist Invents and Runs Its Own Experiments

      August 21, 2024

      Boeing’s Starliner Set to Launch NASA Astronauts After Delays

      May 6, 2024

      SpaceX’s Starship: The Future Plans and Upcoming Developments

      March 15, 2024

      Uncanny Valley: Exploring the Realm of Eerie AI Dolls

      March 13, 2024

      NASA Investigates Starliner Faults, Indefinite Delay in Space

      June 23, 2024

      What Happened Before the Big Bang?

      June 23, 2024

      SpaceX Starship Test Brings Mars Mission Closer

      June 6, 2024

      Searching for Ultralight Dark Matter Explained

      June 2, 2024

      Get One Year of The Zero Byte for $5: Most US Teens Use AI, Parents Unaware

      September 18, 2024

      AI Scientist Invents and Runs Its Own Experiments

      August 21, 2024

      New Alzheimer’s Treatments Useless Without Early Diagnosis

      June 24, 2024

      Post-Pandemic Recovery: Challenges and Uncertainties Ahead

      June 24, 2024
    • Movies
      • Movie Reviews
    • Auto
    • Reviews
      1. Gadget Reviews
      2. Game Reviews
      3. Movie Reviews
      4. View All

      Acer Chromebook Plus: The Perfect Student Laptop Solution

      April 18, 2024

      AMD 3D V-Cache Processor to Avoid: The Zero Byte’s Recommendation

      March 26, 2024

      Microsoft Unveils Unexpected Surface Devices in Latest Launch

      March 22, 2024

      OnePlus 12 Screen: Is It Curved or Flat? Here’s What We Know

      March 16, 2024

      Sonic Heroes Rumored to Make a Comeback: What We Know

      March 26, 2024

      Game Devs at GDC Demand Change Amidst Internet Outrage

      March 26, 2024

      Rise of the Ronin’s Innovative Feature: A New Industry Standard

      March 24, 2024

      Rise of the Ronin: A Masterful Blend of Gaming’s Finest Elements

      March 13, 2024

      Oscars 2024: Unveiling the Triumphs and Surprises in Cinema

      March 11, 2024

      Conann: A Glamorous Fever Dream Exploring Beauty in Barbarism

      March 12, 2024

      Acer Chromebook Plus: The Perfect Student Laptop Solution

      April 18, 2024

      Sonic Heroes Rumored to Make a Comeback: What We Know

      March 26, 2024

      Game Devs at GDC Demand Change Amidst Internet Outrage

      March 26, 2024

      Rise of the Ronin’s Innovative Feature: A New Industry Standard

      March 24, 2024
    The Zero ByteThe Zero Byte
    Home»Science»Environment»How Hackers Allegedly Stole Ticketmaster Data from Snowflake
    How Hackers Allegedly Stole Ticketmaster Data from Snowflake
    Environment

    How Hackers Allegedly Stole Ticketmaster Data from Snowflake

    By TZBJune 17, 20244 Mins Read
    Share
    Facebook Twitter Copy Link

    Hackers Exploit EPAM Worker’s Credentials to Access Snowflake Accounts

    Direct Access Through Plaintext Credentials

    Hackers claimed they accessed Snowflake accounts of EPAM customers using plaintext usernames and passwords found on an EPAM worker’s computer. When Snowflake credentials weren’t stored on the worker’s system, they used old credentials stolen in previous breaches by infostealer malware, including those harvested from the same EPAM worker in Ukraine.

    Infostealer Malware and Credential Reuse

    Credentials harvested by infostealers are often sold or posted online. If victims don’t change their login details after a breach, those credentials can remain active for years. This is especially problematic if the same credentials are used across multiple accounts. Hackers can identify users through their email addresses and try the same credentials in various places.

    The hackers in this case used credentials stolen by an infostealer in 2020 to access Snowflake accounts.

    Verification and Evidence

    The Zero Byte couldn’t independently confirm the hackers’ claims of accessing the EPAM worker’s machine or using EPAM to breach Ticketmaster’s data and other Snowflake accounts. However, the hacker provided a file appearing to be a list of EPAM worker credentials from the company’s Active Directory database.

    Mandiant, in a blog post, revealed that hackers used old data siphoned by infostealers to access Snowflake accounts. About 80 percent of the victims identified in the Snowflake campaign were compromised using previously stolen credentials.

    Ransom Negotiations and Data Repositories

    An independent security researcher, Reddington, who has been negotiating ransom transactions between the ShinyHunter hackers and victims, pointed to an online repository of data harvested by an infostealer. This included data from the EPAM worker’s computer in Ukraine, revealing the worker’s complete name, an internal EPAM URL pointing to Ticketmaster’s Snowflake account, and plaintext credentials.

    “This means that [an EPAM worker] who had access to that Snowflake [account] had password-stealing malware on their computer, and their password was stolen and sold on the dark web,”

    says Reddington.

    EPAM’s Response

    An EPAM spokesperson, when contacted by The Zero Byte, stated, “We do not comment on situations to which we are not a part.” The company suggested it did not believe it played any role in the campaign. When provided with details about how hackers accessed the system of an EPAM worker in Ukraine, the spokesperson replied, “Hackers frequently spread false information to advance their agendas. We maintain a policy of not engaging with misinformation and consistently uphold robust security measures to protect our operations and customers. We are continuing our exhaustive investigation and, at this time, see no evidence to suggest that we have been affected or involved in this matter.”

    Potential Security Concerns

    It’s possible the ShinyHunter hackers did not directly hack the EPAM worker but used old credentials from repositories. Reddington found data online used by nine different infostealers to harvest data from EPAM workers’ machines, raising concerns about the security of data belonging to other EPAM customers.

    EPAM serves various critical industries, including banks, healthcare, and tech companies like Microsoft, Google, Adobe, and Amazon Web Services. It’s unclear if these companies have Snowflake accounts accessible by EPAM workers.

    Third-Party Risks and Infostealers

    The Snowflake campaign highlights the growing security risks from third-party companies and infostealers. Mandiant noted that multiple contractors were breached to gain access to Snowflake accounts. Contractors, often known as business process outsourcing (BPO) companies, are a potential gold mine for hackers because compromising a contractor’s machine can give direct access to multiple customer accounts.

    “Contractors that customers engage to assist with their use of Snowflake may utilize personal and/or non-monitored laptops that exacerbate this initial entry vector,”

    wrote Mandiant. These devices, often used to access multiple organizations’ systems, present a significant risk if compromised by infostealer malware.

    Snowflake’s Response

    Mandiant identified hundreds of customer Snowflake credentials exposed via infostealers since 2020. The lack of multifactor authentication (MFA) made the breaches possible. Snowflake’s CISO, Brad Jones, acknowledged last week that the lack of MFA enabled the breaches. Jones stated that Snowflake is working on giving customers the ability to mandate MFA for their accounts and plans to make MFA the default in the future.

    Access Credentials EPAM Hackers Worker
    Share. Facebook Twitter Copy Link
    Previous ArticleLunar Rebellion Thrills in ‘The Moon Is a Harsh Mistress
    Next Article AI’s Impact on Big Tech Jobs: What You Need to Know

    Related Posts

    Environment

    Top Pickleball Paddles of 2024: Tested and Reviewed

    June 24, 2024
    Environment

    Top 28 Nintendo Switch Games for All Players in 2024

    June 24, 2024
    Environment

    Recluse Spider Season: Debunking the Myth

    June 23, 2024
    View 2 Comments

    2 Comments

    1. opalb on June 17, 2024 8:55 am

      Serious: If true, this could have severe repercussions for data security in cloud services.

      Reply
    2. opald on June 17, 2024 8:55 am

      Question: How did they even pull that off without getting caught immediately?

      Reply
    Leave A Reply Cancel Reply

    Top Posts

    Truecaller Unveils Web Client for Android: Seamless Caller ID and Spam Protection

    April 10, 2024

    M4 MacBook Pro Already in Development, According to Expert

    March 15, 2024

    Withings ScanWatch 2 and Light: Effortless Elegance for the Tech-Weary

    March 11, 2024
    Stay In Touch
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from The Zero Byte about tech.

    Please enable JavaScript in your browser to complete this form.
    Loading
    Most Popular

    Truecaller Unveils Web Client for Android: Seamless Caller ID and Spam Protection

    April 10, 2024

    M4 MacBook Pro Already in Development, According to Expert

    March 15, 2024

    Withings ScanWatch 2 and Light: Effortless Elegance for the Tech-Weary

    March 11, 2024
    Our Picks

    Get 1 Year of The Zero Byte for $30: Lawsuit Highlights Fake News

    October 21, 2024

    Get One Year of The Zero Byte for $5: How a Trump Win Could Unleash AI

    October 21, 2024

    Get One Year of The Zero Byte for $5: Sam Altman’s Eye-Scanning Orb Delivered

    October 17, 2024

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Please enable JavaScript in your browser to complete this form.
    Loading
    The Zero Byte
    Facebook X (Twitter) Instagram
    • Privacy Policy
    © 2025 The Zero Byte.

    Type above and press Enter to search. Press Esc to cancel.