/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Hacking group ShinyHunters claims to have breached contractor EPAM Systems to steal data from Ticketmaster and ~165 other Snowflake users; EPAM denies the claim

A ShinyHunters hacker tells WIRED that they gained access to Ticketmaster's Snowflake cloud account—and others—by first breaching a third-party contractor.

Wired Kim Zetter

Context & Ripple Effects

This report adds a third-party contractor pathway to earlier allegations around Ticketmaster: ShinyHunters had already claimed a large Ticketmaster data theft, while researchers had tied Ticketmaster and Santander claims to allegedly stolen Snowflake credentials, a premise Snowflake disputed.

The new allegation remains unverified and EPAM denies it, but it matters because it shifts attention from a single cloud-account access theory to the security controls around service providers that can reach many customers' systems.

First-order effects

  • EPAM, Ticketmaster, and Snowflake face immediate pressure to investigate whether contractor access was involved; EPAM's denial means the alleged intrusion route is unresolved rather than established.
  • Organizations named or implied in ShinyHunters' claims must assess contractor privileges and account access alongside the previously alleged credential exposure.

Second-order effects

  • Other Snowflake customers and their contractors may tighten access reviews, especially where a provider's administrative reach spans multiple client environments.
  • The allegations compound scrutiny of the earlier claimed Snowflake credential compromise, making clear attribution and the separation of customer, vendor, and platform responsibilities more consequential.

Third-order effects

  • If contractor-mediated access proves to be a recurring route, cloud security programs will increasingly treat vendors' identities and permissions as part of the customer attack surface, not a separate procurement concern.
  • The episode points toward more emphasis on auditable access chains across cloud platforms, customers, and contractors—but the specific EPAM claim must be verified before it can establish a broader failure pattern.

The trend: Cloud-security risk is moving from the perimeter of individual customer accounts toward the shared identities and privileged access paths connecting platforms, contractors, and many clients.

Discussion

  • @kimzetter Kim Zetter on x
    Hackers who stole Ticketmaster data from Snowflake account appears to have accessed data through a contractor named EPAM Systems. EPAM has workers in Belarus, Ukraine and, before war, Russia. Hacker told me they breached an EPAM worker in Ukraine. https://www.wired.com/...
  • @kimzetter Kim Zetter on x
    EPAM says it found no evidence the hackers used one of their systems, but data leaked online indicates an EPAM worker in Ukraine was infected with an infostealer, which grabbed credentials for worker's Ticketmaster Snowflake account. EPAM manages Snowflake accounts for customers