/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers say a threat actor claims to have hacked Ticketmaster and Santander using stolen credentials of a Snowflake employee; Snowflake disputes the claims

A threat actor claiming recent Santander and Ticketmaster breaches says they stole data after hacking into an employee's account at cloud storage company Snowflake.

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

The initial allegation placed Ticketmaster and Santander in a possible shared-access incident centered on Snowflake credentials, while Snowflake contested that account of the intrusion. Days later, researchers reported an alleged listing of more than 500 Snowflake customer credentials, widening the focus from two named victims to customer-access hygiene.

The related coverage also distinguished customer-account compromise from a platform breach: Snowflake, CrowdStrike, and Mandiant said they had found no evidence that Snowflake's platform itself was breached. That distinction is central to how customers, insurers, and cloud buyers assign responsibility.

First-order effects

  • Ticketmaster, Santander, and Snowflake must validate affected accounts, access paths, and data exposure while treating the reported intrusion route as disputed rather than established.
  • Snowflake faces an immediate trust and communications challenge: customers need clarity on whether the issue was credential misuse in individual environments or a service-level security failure.

Second-order effects

  • Other Snowflake customers may accelerate credential rotation, multi-factor authentication checks, and reviews of privileged access, especially after the alleged credential listing surfaced.
  • Security providers and incident-response partners gain a larger role in establishing forensic attribution, because the operational response differs materially between stolen credentials and a platform compromise.

Third-order effects

  • If repeated customer-environment incidents are tied to identity controls rather than cloud-platform flaws, cloud-security accountability will increasingly hinge on how providers and customers divide responsibility for credentials and monitoring.
  • The episode points toward identity security becoming a primary concentration risk in shared cloud ecosystems: one access-control weakness can create correlated exposure across otherwise separate companies.

The trend: Cloud-breach scrutiny is shifting from whether a provider's core platform was penetrated to whether identity and access failures can create multi-customer exposure around it.

Discussion

  • @evisdrenova Evis Drenova on x
    Wow. Hacker used one employee's login creds to dump refresh tokens and then used those to generate as many session tokens as they wanted. Then bypassed Okta using a new session token + the employee's password. https://www.hudsonrock.com/...
  • @troyhunt Troy Hunt on x
    This is a great write up on the possible origin of both the Ticketmaster and Santander data breaches, both attributed back to a compromise at @SnowflakeDB: https://www.hudsonrock.com/...
  • @gossithedog Kevin Beaumont on x
    Enterprise orgs, check your proxy logs (if you still have a proxy and haven't yeeted yourself off a zero trust bridge yet) for *.snowflake.com to see if any of your users signed for up for the free trial and set your data free.
  • @rockhudsonrock @rockhudsonrock on x
    🚨🚨 NEW INVESTIGATION 🚨🚨 Snowflake, Cloud Storage Giant, Suffers Massive Breach: Hacker Confirms to Hudson Rock Access Through Infostealer Infection https://www.hudsonrock.com/... [image]
  • @arkadiyt Arkadiy Tetelman on x
    Steal a Snowflake employee's cookies, access their helpdesk, & generate session tokens into customer environments. Completely preventable yet still all too common Thankfully we have a network policy requiring VPN for Snowflake access, so any session tokens for us were useless
  • @hunterwalk @hunterwalk on threads
    i swear i was buying those front row Backstreet Boys tickets with meet & greet for a friend every single tour since 1993 For.  A. Friend.
  • @joetidy Joe Tidy on x
    Ticketmaster confirms data hack which could affect 560m globally. Confirmed then. It's a biggie. https://www.bbc.com/...
  • @joetidy Joe Tidy on x
    Finding out about a giant data breach affecting hundreds of millions of people through a chilled out notice to investors is pretty grim. “We do not believe it is reasonably likely to have, a material impact on our financial condition or results of operations.”
  • @josephfcox Joseph Cox on x
    New from 404 Media: Ticketmaster/Live Nation confirm the hack in an SEC filing. I also obtained a second, larger sample of data on Thursday. I verified it relates to genuine accounts on the Ticketmaster website, included personal info, payments, etc https://www.404media.co/...
  • @josephfcox Joseph Cox on x
    Here's how I verified the second, larger sample of Ticketmaster data I got https://www.404media.co/... [image]
  • r/technews r on reddit
    Live Nation confirms Ticketmaster was hacked, says personal information stolen in data breach
  • @mattjay Matt Johansen on x
    This is a wild ride. Snowflake breached and scraped of over 400 companies data. Ticketmaster and Santander leaks this week seem to be tied to this. @vxunderground and @GossiTheDog putting out great content on it. [video]
  • @h4ckmanac @h4ckmanac on x
    🚨#DataBreach Update: 🚨 🇪🇸#Spain: The allegedly stolen data from Santander has also been put up for sale on the well-known hacking forum BreachForums, directly by the administrator ShinyHunters. ShinyHunters is the same threat actor who is selling the details of 560 million [image…