C
月内に
米陸軍兵士のキャメロン・ワゲニウス(Kiberphant0m)が、AT&TやVerizonなどの通信会社から顧客データを盗み出した罪で禁錮70ヶ月の判決を受けま…
📌 一言でいうと
米陸軍兵士のキャメロン・ワゲニウス(Kiberphant0m)が、AT&TやVerizonなどの通信会社から顧客データを盗み出した罪で禁錮70ヶ月の判決を受けました。攻撃者はSnowflakeのクラウドストレージを利用している企業の、多要素認証(MFA)が未設定で資格情報が露出していたアカウントを悪用して侵入しました。AT&Tの顧客1億人分以上の通話・テキストメタデータが窃取され、その後恐喝に使用されました。
🔍該当判定
- クラウドデータストレージサービス『Snowflake』を利用している
- Snowflakeの管理アカウントで『多要素認証 (MFA)』を有効にしていない
- AT&TやVerizonなどの米国系通信キャリアのサービスを業務で利用している
- 自社で顧客の電話番号や通話履歴などのメタデータをSnowflake上に保存している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
クラウドサービス(特にSnowflake等のデータストレージ)において、すべての管理・ユーザーアカウントに多要素認証(MFA)を強制的に適用すること。また、資格情報の露出がないか定期的に監査することを推奨します。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Snowflake等のクラウドストレージにおけるMFA強制適用の重要性について
お疲れさまです。他社での侵害事例に関する情報共有です。
■ 概要
攻撃者がSnowflakeのクラウドストレージを利用している企業の、資格情報が露出しており、かつ多要素認証(MFA)が未設定のアカウントを悪用して侵入し、大量の顧客データを窃取した事例が報告されました。
■ 影響範囲
- Snowflake等のクラウドストレージサービスを利用し、MFAを強制していない環境
■ 対応手順
1. 自社で利用しているクラウドストレージおよびSaaSアカウントのMFA設定状況を確認する
2. 未設定のアカウントがある場合、直ちにMFAを有効化し、組織全体でMFAを強制するポリシーを適用する
3. 露出した資格情報がないか、ログの確認およびパスワードリセットを検討する
■ 参考情報
- Snowflake公式ドキュメント(MFA設定ガイド)
対応優先度: 高
対応期限: 直ちに
お疲れさまです。他社での侵害事例に関する情報共有です。
■ 概要
攻撃者がSnowflakeのクラウドストレージを利用している企業の、資格情報が露出しており、かつ多要素認証(MFA)が未設定のアカウントを悪用して侵入し、大量の顧客データを窃取した事例が報告されました。
■ 影響範囲
- Snowflake等のクラウドストレージサービスを利用し、MFAを強制していない環境
■ 対応手順
1. 自社で利用しているクラウドストレージおよびSaaSアカウントのMFA設定状況を確認する
2. 未設定のアカウントがある場合、直ちにMFAを有効化し、組織全体でMFAを強制するポリシーを適用する
3. 露出した資格情報がないか、ログの確認およびパスワードリセットを検討する
■ 参考情報
- Snowflake公式ドキュメント(MFA設定ガイド)
対応優先度: 高
対応期限: 直ちに
Subject: [Security Notice] Importance of Enforcing MFA for Cloud Storage (Snowflake Case)
Dear IT/Security Team,
We are sharing information regarding a recent breach involving the exploitation of cloud storage accounts.
■ Overview
An attacker (Kiberphant0m) gained unauthorized access to several large customers of Snowflake by exploiting exposed credentials on accounts that did not have multi-factor authentication (MFA) enabled. This led to the theft of metadata for over 100 million AT&T customers.
■ Scope
- Environments utilizing Snowflake or similar cloud storage services without enforced MFA.
■ Action Items
1. Audit all cloud storage and SaaS accounts to verify MFA status.
2. Immediately enable MFA for any accounts lacking it and implement a policy to enforce MFA across the organization.
3. Review access logs for unauthorized activity and consider a password reset for exposed accounts.
■ Reference
- Snowflake Official Documentation (MFA Setup Guide)
Priority: High
Deadline: Immediate
Dear IT/Security Team,
We are sharing information regarding a recent breach involving the exploitation of cloud storage accounts.
■ Overview
An attacker (Kiberphant0m) gained unauthorized access to several large customers of Snowflake by exploiting exposed credentials on accounts that did not have multi-factor authentication (MFA) enabled. This led to the theft of metadata for over 100 million AT&T customers.
■ Scope
- Environments utilizing Snowflake or similar cloud storage services without enforced MFA.
■ Action Items
1. Audit all cloud storage and SaaS accounts to verify MFA status.
2. Immediately enable MFA for any accounts lacking it and implement a policy to enforce MFA across the organization.
3. Review access logs for unauthorized activity and consider a password reset for exposed accounts.
■ Reference
- Snowflake Official Documentation (MFA Setup Guide)
Priority: High
Deadline: Immediate