Credential theft

BleepingComputer

πŸ“… 2024-05-01 🏒 Pure Storage Snowflake workspace (telemetry/support)
Primary Source β†—

Incident Details

Pure Storage, a leading enterprise cloud storage provider, confirmed on June 11, 2024 that attackers breached its Snowflake workspace as part of the broader UNC5537/Sp1d3r campaign targeting Snowflake customers lacking MFA. The compromised workspace contained telemetry data used for proactive customer support, including customer company names, LDAP usernames, email addresses, and Purity software release versions. No passwords, array credentials, or customer-stored data were compromised. Pure Storage stated there was no evidence of unauthorized access to customer storage systems. The breach was part of the same UNC5537 (ShinyHunters-affiliated) campaign that affected AT&T, Ticketmaster, Santander, and ~160 other organizations.

Technical Details

Initial Attack Vector
CWE-522: Insufficiently Protected Credentials (infostealer-harvested credentials, no MFA on Snowflake)
Vendor / Product
Pure Storage Snowflake workspace (telemetry/support)

Timeline

  1. 2024-05-01 Breach occurred
  2. 2024-06-11 Publicly disclosed
  3. 2024-06-11 Customers notified