Customers of a major online retailer reported receiving unsolicited app push notifications that appeared to come from hackers demanding engagement with the company's data protection and IT teams. The messages claimed the attackers had "fully compromised" a Snowflake instance and threatened to leak it unless the company engaged, directing recipients to a new Telegram channel run by a group calling itself Xuanye Group. Dozens of users posted about the strange pop-ups, which were sent directly to phones, and the retailer had not issued a public comment at the time. It is not known whether the retailer is a Snowflake customer or what, if any, data is held there.
Cyber-security specialists call the incident unusually brazen because it used the retailer's own notification system as a ransom note. Experts say the claim to control Snowflake alone would not explain the ability to send app pushes, implying the attackers obtained credentials that allowed access to multiple systems. Snowflake has featured in several high-profile breaches of other organisations, and extortion campaigns typically aim to remain private, making this public, wide-reaching notification striking both for its tactics and potential scale.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.