March 2010 April 2010 May 2010 June 2010 July 2010
August 2010
September 2010 October 2010
November 2010
December 2010 January 2011 February 2011 March 2011 April 2011 May 2011 June 2011 July 2011 August 2011 September 2011 October 2011 November 2011 December 2011 January 2012 February 2012 March 2012 April 2012 May 2012 June 2012 July 2012 August 2012 September 2012 October 2012 November 2012 December 2012 January 2013 February 2013 March 2013 April 2013 May 2013 June 2013 July 2013 August 2013 September 2013 October 2013 November 2013 December 2013 January 2014 February 2014 March 2014 April 2014 May 2014 June 2014 July 2014 August 2014 September 2014 October 2014 November 2014 December 2014 January 2015 February 2015 March 2015 April 2015 May 2015 June 2015 July 2015 August 2015 September 2015 October 2015 November 2015 December 2015 January 2016 February 2016 March 2016 April 2016 May 2016 June 2016 July 2016 August 2016 September 2016 October 2016 November 2016 December 2016 January 2017 February 2017 March 2017 April 2017 May 2017 June 2017 July 2017 August 2017 September 2017 October 2017 November 2017 December 2017 January 2018 February 2018 March 2018 April 2018 May 2018 June 2018 July 2018 August 2018 September 2018 October 2018 November 2018 December 2018 January 2019 February 2019 March 2019 April 2019 May 2019 June 2019 July 2019 August 2019 September 2019 October 2019 November 2019 December 2019 January 2020 February 2020 March 2020 April 2020 May 2020 June 2020 July 2020 August 2020 September 2020 October 2020 November 2020 December 2020 January 2021 February 2021 March 2021 April 2021 May 2021 June 2021 July 2021 August 2021 September 2021 October 2021 November 2021 December 2021 January 2022 February 2022 March 2022 April 2022 May 2022 June 2022 July 2022 August 2022 September 2022 October 2022 November 2022 December 2022 January 2023 February 2023 March 2023 April 2023 May 2023 June 2023 July 2023 August 2023 September 2023 October 2023 November 2023 December 2023 January 2024 February 2024 March 2024 April 2024 May 2024 June 2024 July 2024 August 2024 September 2024 October 2024 November 2024
1 2 3 4 5 6 7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
News Every Day |

AT&T Hacker Arrested: How the Cybersecurity Landscape Evolved Post-Snowflake Breach

Over 160 of the world’s largest enterprises had their data stolen this year. All by the same attack strategy.

Each of the businesses, ranging from AT&T and Santander Bank to Advance Auto Parts and Ticketmaster parent company LiveNation, had uploaded massive volumes of sensitive customer data to accounts hosted by cloud data service Snowflake but protected those accounts with little more than a username and password, failing to take further steps like requiring multi-factor authentication (MFA).

That might as well have been a bullseye for scammers.

After acquiring stolen Snowflake account credentials on criminal forums like Telegram and the dark web, a hacker raided the data storage repositories. They then used the theft of millions of people’s personal data to extort the companies, demanding ransom payments ranging from $300,000 to $5 million in exchange for promises not to sell or abuse the data.

But the story has a happy ending. On Monday (Nov. 4), a report broke that 26-year-old man from Ontario, Alexander Moucka, a.k.a. Connor Riley Moucka, was arrested by Canadian authorities on a provisional arrest warrant from the United States. While the charges Moucka is being specifically indicted for remain confidential, the report places him as the suspect behind the far-reaching Snowflake data breach.

That same day, Monday, cloud provider Google Cloud announced that it was planning to make MFA mandatory 100% of its cloud customers by 2025, with Phase 1 already having begun. Around 70% of Google Cloud customers already use MFA to secure their federated accounts.

Still, the fact that for the months during which the Snowflake breaches were occurring, at least 30% of Google Cloud’s customers found themselves in the same vulnerable security position as the Snowflake victims, without MFA account protection, underscores that, while advances are continually being made, the enterprise cybersecurity landscape still has room to do more when it comes to securing sensitive — and valuable — information.

Read more: Almost All of AT&T’s Wireless Customers Hacked as Snowflake Breach Snowballs

What’s in MFA, Anyway?

As businesses across sectors increasingly migrate sensitive operations to the cloud, MFA has emerged as a non-negotiable defense against unauthorized access. It acts as a first-line barrier to protect against the common vulnerabilities that attackers often exploit in credential-based attacks.

American cybersecurity firm and Google subsidiary Mandiant investigated the Snowflake attack and reported that the threat campaign resulted in “numerous successful compromises” because of poor security practices on impacted accounts.

While Snowflake’s data breach was specific to its platform, a similar lack of MFA protection affected a much broader swath of the enterprise cloud landscape.

As PYMNTS wrote Friday (Nov. 1), with MFA, even if a hacker manages to obtain a password, they would need the additional authentication factor to gain access to the account. MFA requires users to confirm their identity using two or more authentication factors.  This generally includes something they know (such as a password), something they have (like a smartphone or security token) or something they are (such as a fingerprint or facial recognition).

An absence of MFA essentially weakens an organization’s defenses, increasing the potential for breaches that can lead to financial and reputational damage.

Read also: Firms Look to Mitigate Consequences From Data Breaches

The Industry’s Response and Ongoing Challenges

While many enterprises understand the importance of MFA, some are reluctant to adopt these cybersecurity controls due to usability concerns, increased friction in user experience, or perceived costs.

This highlights a dual challenge in cybersecurity: Educating clients about the necessity of security measures while implementing safeguards that do not hinder productivity or user accessibility. Technology companies find themselves balancing the need for airtight security with the need to maintain streamlined access for legitimate users.

“What you want is a system that is designed to let in good actors as easily as possible, and that presents enough of a barrier to deter bad actors,” Siddharth Vijayakrishnan, SVP of product and financial intelligence at FIS, told PYMNTS.

Today’s threat actors are sophisticated, leveraging artificial intelligence (AI), social engineering and automation to exploit system weaknesses at unprecedented speeds. While MFA can prevent many common breaches, it is not a cure-all; organizations must adopt a multi-layered approach that includes identity and access management (IAM), endpoint protection, network monitoring and behavioral analytics to catch abnormal activity before it escalates.

“The barrier for entry has never been lower for threat actors,” Sunil Mallik, chief information security officer at Discover Global Network, told PYMNTS.

In separate interviews for the “What’s Next in Payments” series, executives also told PYMNTS that a multilayered security strategy, also known as defense in depth, is crucial for reducing risks at various levels. This approach means implementing multiple defensive measures across the enterprise network.

By embedding security into the DNA of their services providers can help to shield businesses from both known and emerging threats.

The post AT&T Hacker Arrested: How the Cybersecurity Landscape Evolved Post-Snowflake Breach appeared first on PYMNTS.com.

Москва

В Щелковском городском парке отпраздновали День народного единства

UK will urge Trump administration not to curb free trade, Reeves says

An Idaho health department isn’t allowed to give COVID-19 vaccines anymore. Experts say it’s a first

Karachi industrial park to be declared model special economic zone

‘We do not get to sit this one out’: Oprah delivers powerful election eve speech

Ria.city






Read also

‘Blow Me… You Don’t Know Sh*t About Sh*t!’: Furious Jon Stewart Goes Off on Liberal Pollsters After Trump Landslide (VIDEO)

Pennock thanks fans for support after frustrating night at Potters Bar Town

GCSAA selects Bret Corbett to receive Larry Powell Scholarship

News, articles, comments, with a minute-by-minute update, now on Today24.pro

News Every Day

Karkala MLA slams Karnataka govt for failing to fund plank installations on Udupi dams

Today24.pro — latest news 24/7. You can add your news instantly now — here


News Every Day

Karachi industrial park to be declared model special economic zone



Sports today


Новости тенниса
WTA

Касаткину признали автором лучшего удара месяца в туре WTA



Спорт в России и мире
Москва

Хватило на час: хоккейная «Волга» начала чемпионат с поражения в Москве



All sports news today





Sports in Russia today

Москва

«Динамо» Москва — «Витязь» — 4:3. Видеообзор матча КХЛ


Новости России

Game News

Стартовал пробный запуск Castle Doombad: Free To Slay на iOS и Android


Russian.city


Киев

СМИ: в Киеве придумали схему, как при Трампе закрыть кейс «курской операции»


Губернаторы России
Meta

Meta-funded regulator for AI disinformation on Meta's platform comes under fire: 'You are not any sort of check and balance, you are merely a bit of PR spin'


Проверено временем: для спуска на воду ледокола «Чукотка» использовались петровские технологии

Байден впервые прокомментировал поражение Харрис на выборах президента США

Филиал № 4 ОСФР по Москве и Московской области информирует: Социальный фонд выплатит остатки материнского капитала менее 10 тысяч рублей

Джиган, Artik & Asti и NILETTO спели о худи, а Дина Саева стала новым артистом: в Москве прошел BRUNCH Rocket Group


Работал с Джексоном и Синатрой. Умер лауреат 28 премий «Грэмми» Куинси Джонс

Дочь Тимати трогательно поздравила бабушку с юбилеем: «Я бы подарила ей бессмертие»

Съемки фильма Лунгина про Мамонова пройдут там же, где снимали «Остров» и «Царя»

Владимир Высоцкий: сотрудничество музыкантов с предпринимателями даст Ида-Вирумаа новый толчок в развитии культурной жизни


Касаткину признали автором лучшего удара месяца в туре WTA

Соболенко обыграла Паолини и вышла в полуфинал Итогового турнира WTA

Корнеева проиграла Сёнмез и не смогла выйти в финал турнира WTA в Мериде

Российская теннисистка Анастасия Потапова сообщила о разводе



Глава ТПП РФ Сергей Катырин: бизнес предлагает донастроить налоговое законодательство

Более 511,3 тысячи семей Московского региона получили сертификаты на материнский капитал в проактивном формате

Угадать хит и выиграть автомобиль

В Подмосковье росгвардейцы помогли автолюбительнице, оказавшейся в сложной ситуации из-за гололеда


В "Динамо" опубликовали фото Мостового в образе царя

A college student put on a free, stage adaptation of Silent Hill 2 'to make a truly frightening theatrical experience' all without an appearance by Pyramid Head

Собянин: Победители и призеры XVII летних Паралимпийских игр в Париже получат призовые от Москвы

Стартовал пробный запуск Castle Doombad: Free To Slay на iOS и Android


Во Владикавказе завершился инклюзивный фестиваль «Алтын майдан» в котором впервые приняли участие артисты красноуфимского культурного центра

Кубок Ил Дархана: Будет яркое шоу, в лучших традициях Якутии

Госсектор заселяет бизнес-центры // Чиновники и госкомпании увеличивают спрос на офисную недвижимость

Слезы принцессы. «Вице-мисс мира- 2015» Никитчук светит срок за контрабанду



Путин в России и мире






Персональные новости Russian.city
Николай Цискаридзе

Цискаридзе назвал ненормальными цены на билеты в театры России



News Every Day

Karachi industrial park to be declared model special economic zone




Friends of Today24

Музыкальные новости

Персональные новости