Hacking group ShinyHunters claims to have breached contractor EPAM Systems to steal data from Ticketmaster and ~165 other Snowflake users; EPAM denies the claim
A ShinyHunters hacker tells WIRED that they gained access to Ticketmaster's Snowflake cloud account—and others—by first breaching a third-party contractor.
Context & Ripple Effects
This report adds a third-party contractor pathway to earlier allegations around Ticketmaster: ShinyHunters had already claimed a large Ticketmaster data theft, while researchers had tied Ticketmaster and Santander claims to allegedly stolen Snowflake credentials, a premise Snowflake disputed.
The new allegation remains unverified and EPAM denies it, but it matters because it shifts attention from a single cloud-account access theory to the security controls around service providers that can reach many customers' systems.
First-order effects
- EPAM, Ticketmaster, and Snowflake face immediate pressure to investigate whether contractor access was involved; EPAM's denial means the alleged intrusion route is unresolved rather than established.
- Organizations named or implied in ShinyHunters' claims must assess contractor privileges and account access alongside the previously alleged credential exposure.
Second-order effects
- Other Snowflake customers and their contractors may tighten access reviews, especially where a provider's administrative reach spans multiple client environments.
- The allegations compound scrutiny of the earlier claimed Snowflake credential compromise, making clear attribution and the separation of customer, vendor, and platform responsibilities more consequential.
Third-order effects
- If contractor-mediated access proves to be a recurring route, cloud security programs will increasingly treat vendors' identities and permissions as part of the customer attack surface, not a separate procurement concern.
- The episode points toward more emphasis on auditable access chains across cloud platforms, customers, and contractors—but the specific EPAM claim must be verified before it can establish a broader failure pattern.
The trend: Cloud-security risk is moving from the perimeter of individual customer accounts toward the shared identities and privileged access paths connecting platforms, contractors, and many clients.