Data Security, Breach, Cloud Security

SaaS integration breach leads to widespread data theft attacks

(Adobe Stock)

As reported by Bleeping Computer, over a dozen companies have experienced data theft following a breach at a SaaS integration provider, which resulted in the compromise of authentication tokens. While various cloud storage and SaaS vendors were targeted, the majority of these attacks focused on the cloud-based data warehouse platform Snowflake.

Snowflake confirmed unusual activity impacting a small number of its customers, stating the attacks did not exploit vulnerabilities in its own systems. The threat actor allegedly used stolen authentication tokens, believed to originate from a breach at data anomaly detection company Anodot, to steal data. Attempts were made to target Salesforce, but these were thwarted by AI detection systems.

The ShinyHunters extortion gang has claimed responsibility for the attacks, demanding ransom payments to prevent the release of stolen data from dozens of companies.

Source: Bleeping Computer

An In-Depth Guide to Cloud Security

Get essential knowledge and practical strategies to fortify your cloud security.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds