< ciso
brief />
Tag Banner

All news with #snowflake tag

31 articles

Telegram Account Linked to ASOS Notification Incident

🔍 Group-IB found the Telegram account tied to the October 6 ASOS notification was previously active in gaming-item trading communities and used multiple aliases. Investigators say the channel was created the same day and have not found evidence that ASOS customer data was dumped or that Snowflake was compromised. ASOS confirmed possible access to basic contact details, restricted notification-platform access, and is working with advisers and authorities while customers are urged to remain vigilant.
read more →

ASOS push-notification claims Snowflake compromise

📣 Customers of online fashion retailer ASOS received a push notification on October 6 claiming a Snowflake compromise and urging engagement or data leakage. The message, signed ‘xuanyewengateway’, included a Telegram link; ASOS has not confirmed any breach. Experts cautioned users not to follow the link, advised password changes, and urged ASOS to review Snowflake logs and follow incident response protocols. Analysts noted the claim could indicate access to connected systems but stressed further verification is needed.
read more →

Amazon Redshift adds Iceberg materialized views

🚀 Amazon Redshift now supports creating and refreshing Apache Iceberg materialized views that store precomputed joins and aggregations as Iceberg tables in Amazon S3 and register them in the AWS Glue Data Catalog. Materialized views are created with SQL using CREATE MATERIALIZED VIEW ... USING ICEBERG and are queryable by Iceberg-compatible engines such as Amazon Athena, Apache Spark on Amazon EMR, AWS Glue, and third-party engines like Trino or Snowflake. Redshift provides manual incremental refreshes to recompute only changed data, and the resulting Iceberg tables are discoverable and governed through the Glue Data Catalog.
read more →

Former soldier jailed for hacking and extortion

🔒 A former U.S. Army soldier was sentenced to 70 months in prison and ordered to pay $294,978 in restitution after admitting to hacking and extorting at least 10 U.S. technology and telecommunications firms between April 2023 and December 2024. The 21-year-old, known online as kiberphant0m, stole login credentials using an SSH brute tool he helped develop and coordinated with accomplices via Telegram. Stolen data was threatened for public release on cybercrime forums and sold to facilitate SIM-swapping and other frauds, with attempted extortion demands totaling around $1 million. Two associates were tied to larger Snowflake breaches affecting hundreds of organizations and millions of individuals.
read more →

Soldier Sentenced for Major Telecom Data Extortion

🔒 A U.S. Army soldier pleaded guilty to hacking multiple telecom firms and stealing mobile call and text metadata for over 100 million AT&T customers, and was sentenced to 70 months in federal prison with nearly $300,000 restitution. Operating as “Kiberphant0m” from a base in South Korea, he and alleged co-conspirators accessed Snowflake-stored data lacking MFA, extorted providers including Verizon, and later re-extorted victims with purported national security materials. Authorities linked co-conspirators to prior large-scale cybercrime, and investigators highlighted the unique insider threat posed by an active-duty soldier with secret clearance. While Wagenius cooperated, prosecutors noted prison attempts to probe system vulnerabilities and to prompt AI for exploit code; despite the scale of stolen data, his extortion proceeds were minimal.
read more →

Wiz AI Agent Finds Critical Script Injection in Snowflake

🔎 Security researchers at Wiz, part of Google Cloud, discovered a critical script injection vulnerability in Snowflake’s public GitHub repository that GitHub Advanced Security missed. The issue, found by Wiz Research’s autonomous Red Agent on June 23, allowed unauthenticated command execution in a GitHub Actions runner via a crafted issue title. Snowflake patched the workflow and rotated the Jira token after being notified via HackerOne, reporting no evidence of unauthorized access.
read more →

Snowflake GitHub Actions workflow injection exposed Jira token

🔒 Researchers at Wiz disclosed a GitHub Actions workflow injection in Snowflake's snowflakedb/snowflake-connector-net repo that allowed attacker-controlled issue fields to be expanded into a shell run: block, exposing JIRA_BASE_URL, JIRA_USER_EMAIL, and JIRA_API_TOKEN. The vulnerability stemmed from unsafe expression expansion in .github/workflows/jira_issue.yml and incorrect event property checks, which let a crafted public issue reach the job. Snowflake patched the workflow the same day Wiz reported it and rotated the exposed Jira token; no evidence of unauthorized access or affected releases was found.
read more →

Snowflake attacker pleads guilty in mass data hacks

🔒 A Canadian hacker has pleaded guilty to participating in a group that compromised logins and breached a US cloud data warehouse, impacting 165 organizations and resulting in theft of customer records and multimillion-dollar extortion. Identified as Connor Riley Moucka, he worked with two co-conspirators and is linked to intrusions affecting companies such as AT&T, Ticketmaster and Neiman Marcus. The coordinated investigation involved the FBI and international law enforcement partners and led to guilty pleas and arrests tied to the Snowflake-focused campaign.
read more →

Canadian Hacker Pleads Guilty in Snowflake Extortion Case

🛡️ Connor Riley Moucka, a 26-year-old Canadian, pleaded guilty to computer fraud and conspiracy for hacking and extorting more than 165 Snowflake customers and stealing AT&T call and text metadata for over 100 million users. Authorities say the conspirators used stolen credentials where multi-factor authentication was not enforced, exfiltrated terabytes of sensitive data, and extorted victims for ransom. Moucka admitted to threatening officials and security researchers and faces significant prison time at his October sentencing.
read more →

Snowflake breach actor pleads guilty in US court

🔒 Connor Riley Moucka pleaded guilty in Seattle federal court to charges including computer fraud, wire fraud and aggravated identity theft for his role in the 2024 Snowflake customer account intrusions that affected at least 165 organizations and exposed data tied to over 100 million people. Prosecutors say attackers used old credentials harvested by infostealer malware and exploited accounts with MFA disabled, resulting in more than $9.5 million in direct victim losses and at least $495,000 personally taken by Moucka.
read more →

AWS adds autonomous agents and cross-data analytics

🤖 Amazon Quick receives major updates including autonomous agents, multi-dataset analytics, and a redesigned activity feed. Quick connects to common business apps and learns workflows to automate recurring tasks and reduce manual notifications. The multi-dataset analytics lets users query across sources like Snowflake and relational databases using natural language while inheriting semantics from catalogs such as AWS Glue and Databricks Unity Catalog. The updated activity feed provides a conversational, personalized workspace for approvals, messaging, and sharing Quick applications externally.
read more →

Amazon Quick expands integrations with 16 new connectors

🔗 Amazon Quick now connects to 16 additional tools including Adobe, Figma, WhatsApp, Snowflake, and Smartsheet, enabling teams to act on insights without switching context. The new connectors span productivity, design, analytics, financial intelligence, commerce, and communication, so teams can build cross-tool workflows inside Quick. Integrations are available in all AWS Regions where Amazon Quick is offered.
read more →

AWS Secrets Manager adds Datadog and Snowflake support

🔐 AWS Secrets Manager now supports managed external secrets for Datadog vended keys and Snowflake Programmatic Access Tokens, enabling automatic rotation of third-party credentials directly within Secrets Manager. The update covers Datadog API keys, Application keys, and admin credential pairs for service accounts. For Snowflake, Secrets Manager can rotate Programmatic Access Tokens using Snowflake's native authentication and offers a configurable grace period to minimize disruption. These additions join existing integrations such as BigID, Confluent Cloud, MongoDB Atlas, and Salesforce and are available in all Regions where managed external secrets is supported.
read more →

Zara Data Breach Exposes 197,000 Customers' Records

🔒 A ShinyHunters campaign has compromised data for over 197,000 Zara customers, according to HaveIBeenPwned. Stolen items include unique email addresses, product SKUs, order IDs and support ticket data after stolen authentication tokens from analytics provider Anodot were used to access BigQuery and Snowflake instances; the group leaked a claimed 140GB trove. Inditex says no names, passwords or payment details were affected and operations remained unaffected. Other reported victims include Vimeo, Rockstar Games and McGraw Hill.
read more →

Amazon Athena Adds Managed Connectors for 12 Sources

🔗 Amazon Athena now provides managed connectors for 12 external data sources, including DynamoDB, PostgreSQL, MySQL, and Snowflake, enabling queries against data outside Amazon S3 without deploying connector infrastructure. Athena creates and manages AWS Glue Data Catalog federated connectors on your behalf and registers each source as a federated catalog. You can query those sources alongside S3 data and optionally apply fine‑grained access controls through AWS Lake Formation. Federated queries are available in all standard AWS Regions except AWS GovCloud (US) and China Regions.
read more →

AWS Glue Adds OAuth 2.0 Support for Snowflake Connectivity

🔒 AWS Glue now supports OAuth 2.0 for native Snowflake connectivity, allowing customers to read from and write to Snowflake without sharing persistent user credentials. This token-based authorization uses temporary access tokens to eliminate credential management, enabling granular permissions and improved auditability. The built-in AWS Glue Snowflake connector with OAuth is available in all AWS commercial regions, simplifying secure data integration.
read more →

Rockstar Games analytics data leaked after Anodot breach

🔓 A data set allegedly belonging to Rockstar Games was published by the ShinyHunters extortion group after they say authentication tokens were stolen from Anodot and used to access connected Snowflake accounts. The leak reportedly contains more than 78.6 million records of internal analytics — including in‑game revenue, purchase metrics, player behavior, and game economy data for GTA Online and Red Dead Online — plus Zendesk support analytics. Rockstar said only a limited amount of non‑material company information was accessed and that the incident does not affect players.
read more →

Snowflake Customers Targeted After SaaS Integrator Breach

🔐 Over a dozen companies experienced data theft after attackers used stolen authentication tokens from a breached SaaS integrator to access cloud accounts. The majority of observed incidents targeted Snowflake, which reported "unusual activity" and said a small number of customer accounts were impacted. Snowflake emphasized that its systems were not compromised and that it locked down potentially affected accounts and notified customers. BleepingComputer sources point to an alleged breach at Anodot, and the extortion gang ShinyHunters claims responsibility.
read more →

Spanner Columnar Engine Preview: Serving Iceberg Lakehouses

🚀 The preview of the Spanner columnar engine enables low-latency serving of Apache Iceberg lakehouse data with Spanner’s horizontal scale and strong consistency. It adds a columnar storage layer and vectorized execution to accelerate analytical scans — Google cites up to 200× faster scans — while isolating heavy analytical queries from transactional workloads. The feature supports on-demand columnar conversion, automatic query routing, and reverse ETL integrations with BigQuery, Databricks, Snowflake and Oracle to make curated analytical data available for real-time applications.
read more →

AWS Clean Rooms Adds Parameters to PySpark Templates

🧩 AWS Clean Rooms now supports parameters in PySpark analysis templates, allowing template authors to define input values that collaborators supply at job submission time without editing the template code. When a collaborator is approved to run an analysis, they submit parameter values directly to the PySpark job, enabling reusable templates and faster iteration. This feature lets partners vary time windows, geographic regions, and other inputs dynamically to adapt analyses. It supports collaboration across companies on AWS or Snowflake and helps accelerate time-to-insights for use cases like advertising attribution.
read more →