Credential theft
BleepingComputer
Primary Source βIncident Details
Cylance (a cybersecurity company owned by BlackBerry) confirmed in June 2024 that a data breach occurred involving a third-party cloud platform. The threat actor ‘Sp1d3r’ claimed to be selling 34 million customer and employee email records from Cylance on dark web forums. Cylance confirmed this was legacy marketing data from before BlackBerry’s acquisition (2015-2018), not data from active customer security products. Cylance is not a Snowflake customer, contradicting initial reporting that tied the breach directly to the Snowflake UNC5537 campaign. BlackBerry stated no current customer, product, or operational data was compromised. The incident underscores that historical data assets accumulated through acquisitions remain a breach risk years after they are collected.
Technical Details
- Initial Attack Vector
- CWE-522: Insufficiently Protected Credentials (infostealer-harvested credentials, no MFA on Snowflake account)
- Vendor / Product
- Cylance/BlackBerry data warehouse (Snowflake)
Timeline
- 2024-04-01 Breach occurred
- 2024-06-10 Publicly disclosed
- 2024-06-10 Customers notified