Snowflake shares slip after AT&T says hackers accessed knowledge

0
15
Snowflake shares slip after AT&T says hackers accessed knowledge

Sridhar Ramaswamy, CEO of Snowflake and previously co-founder and CEO of startup Neeva, speaks on the Collision convention in Toronto on June 21, 2022.

Eóin Noonan | Sportsfile | Collision | Getty Photos

Snowflake has spent the previous seven weeks coping with the fallout of a significant cyberattack that compromised delicate buyer knowledge at a number of of its purchasers. The software program firm’s issues simply acquired an entire lot worse.

Telecommunications big AT&T stated in a regulatory submitting on Friday that hackers tapped right into a cloud platform housing buyer knowledge, getting access to data of subscribers’ calls and textual content messages throughout a six-month interval in 2022. The info contains cellphone numbers, combination name period and a few cell website particulars, AT&T stated within the submitting.

An AT&T spokesperson advised CNBC that the cloud service was owned by Snowflake. Shares of Snowflake fell 1.8% on Friday, whereas the Nasdaq rose 0.6%.

It’s the most extreme incident since Snowflake disclosed the breach on Could 30, writing in a weblog publish on the time, “We turned conscious of probably unauthorized entry to sure buyer accounts on Could 23, 2024.” Snowflake enlisted the assistance of cybersecurity software program vendor CrowdStrike and Alphabet’s Mandiant to research.

Mandiant wrote in a weblog publish final month that, via its “Sufferer Notification Program,” the corporate and Snowflake have alerted 165 “doubtlessly uncovered organizations” of the incident. Mandiant blamed the hack on a financially motivated group it calls UNC5537, with members in North America and Turkey. UNC5537 drew on login credentials that had been accessible on-line after they’d been stolen individually utilizing malware.

Previous to Friday, probably the most notable firms related to the Snowflake breach had been Advance Auto Components, LendingTree, Ticketmaster operator Reside Nation and Santander Financial institution, which stated in mid-Could, previous to Snowflake’s disclosure, “We not too long ago turned conscious of an unauthorized entry to a Santander database hosted by a third-party supplier.” 

AT&T is far larger. The corporate had 242 million clients for its U.S. wi-fi mobility companies on the finish of final 12 months, with 128 million related gadgets.

The provider stated knowledge within the breach includes “almost all of AT&T’s wi-fi clients and clients of cellular digital community operators” utilizing its wi-fi community.

“Whereas the information doesn’t embrace buyer names, there are sometimes methods, utilizing publicly accessible on-line instruments, to seek out the identify related to a selected phone quantity,” AT&T wrote. Attackers didn’t get entry to the content material of calls or texts.

A Snowflake spokesperson didn’t present a remark when requested concerning the AT&T hack. The spokesperson pointed to the corporate’s prior statements concerning the assault.

Mandiant stated in its weblog publish that among the malware infections in Snowflake’s programs date to 2020, and the credentials had been, in some instances, nonetheless legitimate years after being stolen. In sure cases, the credentials had been taken on PCs utilized by contractors for Snowflake clients — gadgets that had been additionally used for private actions, together with downloading pirated software program.

The usernames and passwords had been ample for UNC5537 to enter clients’ Snowflake environments as a result of they’d not turned on multi-factor authentication, Mandiant stated. From there, the hackers exported “a major quantity of buyer knowledge.” UNC5537 has since began extorting victims and attempting to promote buyer knowledge on-line, Mandiant added.

AT&T stated Friday that it doesn’t consider the assault could have a cloth impact on its funds.

However Snowflake has warned buyers that it’d face reputational hurt and “vital liabilities” if the corporate had been to “expertise an precise or perceived safety breach or unauthorized events in any other case acquire entry to our clients’ knowledge, our knowledge, or our platform.”

Earlier this week, Snowflake printed a weblog publish saying directors can implement the obligatory use of multi-factor authentication.

The deepening saga represents a rising problem for Sridhar Ramaswamy, a former Google govt who in February changed Frank Slootman as Snowflake’s CEO. Days earlier than the hacking disclosure, Snowflake inventory declined 5% after administration lowered the corporate’s full-year adjusted working revenue forecast.

Snowflake, based in 2012, went public in 2020, elevating greater than $3 billion within the largest preliminary public providing ever for a software program firm. Since a giant first-day pop that lifted its market cap previous $70 billion, Snowflake has slid in worth, with its inventory closing at $134.73 on Friday for a valuation of about $45 billion.

Don’t miss these insights from CNBC PRO

Snowflake CEO joins Jim Cramer after earnings report drives stock higher