HomeData BreachStolen Ticketmaster knowledge from Snowflake assaults briefly on the market once more

Stolen Ticketmaster knowledge from Snowflake assaults briefly on the market once more

The Arkana Safety extortion gang briefly listed over the weekend what seemed to be newly stolen Ticketmaster knowledge however is as a substitute the information stolen through the 2024 Snowflake knowledge theft assaults.

The extortion group posted screenshots of the allegedly stolen knowledge, promoting over 569 GB of Ticketmaster knowledge on the market, inflicting hypothesis that this was a brand new breach.

Listing of Ticketmaster data being sold by Arkana
Itemizing of Ticketmaster knowledge being offered by Arkana
Supply: BleepingComputer

Nevertheless, BleepingComputer has decided that the recordsdata proven within the Arkana publish match samples of Ticketmaster knowledge we beforehand noticed through the 2024 Snowflake knowledge theft assaults.

Moreover, one of many pictures had the caption “rapeflaked copy 4 fast sale 1 purchaser,” which is a reference to a device named “RapeFlake.”

RapeFlake is a customized device created by the menace actors to carry out reconnaissance and exfiltrate knowledge from Snowflake’s databases.

As beforehand reported, the Snowflake assaults focused many organizations, together with Santander, Ticketmaster, AT&T, Advance Auto Elements, Neiman Marcus, Los Angeles Unified, Pure Storage, and Cylance. These assaults have been claimed by an extortion group often called ShinyHunters.

See also  Qantas discloses cyberattack amid Scattered Spider aviation breaches

These assaults have been carried out utilizing compromised Snowflake credentials stolen by infostealers, which have been then used to obtain firm knowledge to be used in extortion schemes.

Ticketmaster was among the many most generally extorted victims within the Snowflake assault, which led to the theft of private and ticketing info. After the information was provided on the market on-line, the corporate confirmed the breach on the finish of Might and started notifying affected clients.

Following the preliminary leak, the menace actors ramped up their extortion makes an attempt by releasing what they claimed have been print-at-home tickets and even alleged Taylor Swift tickets in a sequence of posts on a hacking discussion board.

Whereas Arkana didn’t specify the origin of the information, using Snowflake references and the file names matching beforehand leaked recordsdata signifies that the group was making an attempt to resell outdated stolen knowledge.

Whether or not or not Arkana beforehand bought this knowledge, whether or not the group is made up of menace actors who beforehand had the information, or whether or not they’re working with ShinyHunters to promote it’s unclear.

See also  Sticky Werewolf Makes use of Undocumented Implant to Deploy Lumma Stealer in Russia and Belarus

On June 9, the entry for the Ticketmaster knowledge had been faraway from the Arkana Safety knowledge leak web site.

The identify “ShinyHunters” has been linked to numerous breaches over time, together with the large PowerSchool data breach the place knowledge was stolen for 62.4 million college students and 9.5 million academics for six,505 faculty districts throughout the U.S., Canada, and different nations.

Extra not too long ago, Mandiant tied ShinyHunters to a current marketing campaign concentrating on Salesforce accounts, the place menace actors have been breaching accounts to steal buyer knowledge and extort corporations.

As quite a few menace actors tied to ShinyHunters have been arrested over the previous three years  [1, 2, 3], it’s unclear if that is the unique group or different menace actors claiming to be them to throw off regulation enforcement.

BleepingComputer contacted Arkana and Ticketmaster concerning the itemizing however didn’t obtain a response.

- Advertisment -spot_img
RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -

Most Popular