zerofox logo
Advisories

ZeroFox Intelligence Flash Report - Threat Actor Linked to ShinyHunters Advertises Extortionate Data Breach

|by Alpha Team

banner image

ZeroFox Intelligence Flash Report - Threat Actor Linked to ShinyHunters Advertises Extortionate Data Breach

Product Serial: F-2024-06-12a

TLP:CLEAR

In this Flash Report, ZeroFox researchers report on the recent, extortionate data breach advertised for sale in the dark web forum xss, by a threat actor linked to ShinyHunters.

Standing Intelligence Requirements

Deep Dark Web and Criminal Underground DDW

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:

https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report here

Key Findings

  • On June 11, 2024, untested threat actor “sp1d3r'' advertised the sale of a notably-large leaked data set in the Russian-speaking dark web forum xss. The breach allegedly contains 65,000 records of data stolen from a U.S.-based financial organization that purportedly include both personal financial information (PFI) and personally identifiable information (PII).
  • The owner of this stolen data is likely a victim of the ongoing fallout of the alleged breach of cloud-based service provider Snowflake. Since the alleged breach on May 23, 2024, several of Snowflake’s assumed customers’ data have been advertised on deep and dark web (DDW) forums.
  • Sp1d3r is almost certainly synonymous with, or heavily associated with, threat actor “ShinyHunters”, who is very likely responsible for recent attacks against Snowflake customers.
  • In the coming weeks, it is very likely that additional Snowflake customers will be implicated in data breaches, with the stolen information being advertised for sale in DDW forums.

Tags: tlp:clear,  dark web,  data breach,  threat actor