ZeroFox Intelligence Flash Report - ShinyHunters: An Insight into Future Extortion Tactics?
|by Alpha Team

ZeroFox Intelligence Flash Report - ShinyHunters: An Insight into Future Extortion Tactics?
Product Serial: F-2024-06-07a
TLP:CLEAR
In this Flash Report, ZeroFox researchers report on the recent data breach targeting the cloud computing platform Snowflake, other effected organizations, and the numerous aliases allegedly behind these attacks.
Standing Intelligence Requirements
Deep Dark Web and Criminal Underground

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- Threat actors have allegedly stolen the data of an unknown number of organizations via a compromise of the cloud data platform Snowflake. ZeroFox cannot yet independently confirm or deny the extent to which Snowflake is involved or how the alleged accessing of a demo environment could lead to the breach of multiple downstream customers.
- To date, at least three organizations are alleged to be victims of this breach, with data being sold in deep and dark web forums. ZeroFox anticipates there is a likely chance that other as-yet-unnamed organizations have also had data leaked, but may have chosen to buy back their data, or threat actors have yet to list it.
- The alleged breach of the cloud data platform Snowflake, and subsequent sale of data from alleged customers, may provide threat actors with a blueprint for the development of digital extortion tactics in the near future.
- The omission of encrypting payloads from extortion attacks will likely become increasingly popular amongst established extortion collectives—and will likely facilitate a larger pool of threat actors not historically involved in extortion to enter the digital extortion space.
Tags: tlp:clear, data breach, DDW Victims, DDW Markets, dark web, threat actor