Credential theft

BleepingComputer

πŸ“… 2024-04-01 🏒 Cylance/BlackBerry data warehouse (Snowflake)
Primary Source β†—

Incident Details

Cylance (a cybersecurity company owned by BlackBerry) confirmed in June 2024 that a data breach occurred involving a third-party cloud platform. The threat actor ‘Sp1d3r’ claimed to be selling 34 million customer and employee email records from Cylance on dark web forums. Cylance confirmed this was legacy marketing data from before BlackBerry’s acquisition (2015-2018), not data from active customer security products. Cylance is not a Snowflake customer, contradicting initial reporting that tied the breach directly to the Snowflake UNC5537 campaign. BlackBerry stated no current customer, product, or operational data was compromised. The incident underscores that historical data assets accumulated through acquisitions remain a breach risk years after they are collected.

Technical Details

Initial Attack Vector
CWE-522: Insufficiently Protected Credentials (infostealer-harvested credentials, no MFA on Snowflake account)
Vendor / Product
Cylance/BlackBerry data warehouse (Snowflake)

Timeline

  1. 2024-04-01 Breach occurred
  2. 2024-06-10 Publicly disclosed
  3. 2024-06-10 Customers notified