{"id":3885,"date":"2024-06-04T11:41:09","date_gmt":"2024-06-04T16:41:09","guid":{"rendered":"https:\/\/www.darkreading.com\/cloud-security\/ticketmaster-breach-showcases-saas-data-security-risks"},"modified":"2024-06-04T11:41:09","modified_gmt":"2024-06-04T16:41:09","slug":"ticketmaster-breach-showcases-saas-data-security-risks","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/06\/04\/ticketmaster-breach-showcases-saas-data-security-risks\/","title":{"rendered":"Ticketmaster Breach Showcases SaaS Data Security Risks"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltdb5ab7a29883602b\/665e29332798528b823d2149\/ticketmaster_T._Schneider_shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ticketmaster-breach-showcases-saas-data-security-risks.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ticketmaster-breach-showcases-saas-data-security-risks.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A massive data breach at Ticketmaster and another one at Santander Bank last month may have both resulted from a fundamental failure by the companies to properly secure access to the data on a third-party cloud storage service.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The incidents are the latest reminder of why organizations storing sensitive data in the cloud need to implement multifactor authentication (MFA), IP restrictions, and other mechanisms to protect access to it. This might seem like low-hanging fruit, but it&#8217;s clear that even IT-mature companies continue to overlook cloud security in the rush toward digital transformation.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Massive Breaches\">Massive Breaches<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.sec.gov\/Archives\/edgar\/data\/1335258\/000133525824000081\/lyv-20240520.htm\" rel=\"noopener\">regulatory filing<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> over the weekend, Ticketmaster parent Live Nation Entertainment said it was the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/ticketmaster-confirms-cloud-breach-murky-details\" rel=\"noopener\">victim of a May 20 breach<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> involving a database hosted by a third-party cloud storage provider. The company&#8217;s May 31 disclosure came after reports <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/leak-site-breachforums-springs-back-to-life-weeks-after-fbi-takedown\" rel=\"noopener\">surfaced last week of data<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> belonging to some 550 million Ticketmaster customers being put up for sale on a Dark Web forum by &#8220;ShinyHunters,&#8221; an entity believed associated with the BreachForums leak site. Ticketmaster itself has not publicly disclosed any details of the breach beyond what it has included in the SEC filing.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Santander Bank <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/santander-falls-victim-to-data-breach-involving-third-party-provider\" rel=\"noopener\">disclosed a similar breach<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> on May 14. <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.santander.com\/en\/stories\/statement\" rel=\"noopener\">In a statement<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> at the time, the Spanish banking institution said someone had obtained unauthorized access to a database hosted by a third-party cloud services provider that contained employee and customer data. Among those primarily impacted were Santander Bank customers in Spain, Chile, and Uruguay.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">ShinyHunters has claimed credit for the Santander theft as well and said the database it accessed <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/x.com\/DarkWebInformer\/status\/1796230210947268628\" rel=\"noopener\">contains data on some 30 million Santander customers<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, 28 million credit card numbers, account balances, HR employee lists, and other data. The threat actor has put the data up for sale for $2 million.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Both Ticketmaster and Santander have not disclosed the identity of the third-party cloud service. But numerous security analysts have identified the provider as Snowflake, a cloud storage provider that counts companies such as MasterCard, Honeywell, Disney, Albertsons, JetBlue, and other major brands as its customers.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"A Failure to Protect?\">A Failure to Protect?<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/community.snowflake.com\/s\/question\/0D5VI00000Emyl00AB\/detecting-and-preventing-unauthorized-user-access\" rel=\"noopener\">Snowflake has acknowledged<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> that there has been malicious activity that has targeted some of its customer accounts in recent weeks, but so far it has not identified which customers are affected. The company said an investigation that it conducted with help from Mandiant and CrowdStrike has shown no evidence to suggest the activity is linked to any &#8220;vulnerability, misconfiguration, or breach of Snowflake&#8217;s platform.&#8221; &nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Instead, the attacks appear to be part of a broader &#8220;targeted campaign directed at users with single-factor authentication,&#8221; Snowflake said. &#8220;As part of this campaign, threat actors have leveraged credentials previously purchased or obtained through infostealing malware,&#8221; and used them to access customer accounts, the cloud storage vendor said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">David Bradbury, chief security officer (CSO) at Okta, says the recent incidents highlight the importance of ensuring that software-as-a-service (SaaS) applications within corporate environments have phishing-resistant MFA as well as network IP restrictions that limit access from only trusted locations. &#8220;However, MFA and inbound IP restrictions aren&#8217;t enough on their own,&#8221; he adds.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Attackers are increasingly focusing on post-authentication <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/cyberattackers-double-down-bypassing-mfa\" rel=\"noopener\">attacks that bypass MFA altogether<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, he says. An attacker that cannot steal user credentials will pivot to stealing proof of authentication, which is why security mechanisms such as session token binding are vital for SaaS applications, Bradbury says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Based on the available information so far, the data leaks via the Snowflake platform do not appear to be the result of any mistake on the cloud vendor&#8217;s part. Rather, it appears to be a failure by the victim organizations to follow cloud security and configuration baselines, says Michael Lyborg, CISO at Swimlane.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"The Cloud Security Shared Responsibility Model\">The Cloud Security Shared Responsibility Model<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Under most current <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/shouldering-the-increasingly-heavy-cloud-shared-responsibility-model\" rel=\"noopener\">cloud shared responsibility models,<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> the cloud vendor and customer typically split responsibility for identity and access management (IAM) and the enforcement of MFA. But ultimately, it&#8217;s up to customers to follow the provider&#8217;s best practices, configuration and implementation guidelines to mitigate risks to data, Lyborg says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;I believe providers should enforce MFA and least privilege and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/zero-trust-takes-over-63-percent-of-orgs-implementing-globally\" rel=\"noopener\">zero trust by default<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> to assist customers in their digital transformation journey,&#8221; he says. &#8220;If an exception is made to circumvent the configuration baseline, other compensating controls should be a requirement.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">However, Patrick&nbsp;Tiquet, vice president, security and architecture, at Keeper Security, says it&#8217;s unreasonable to expect cloud providers to implement mandatory MFA and other secure by default practices in all cases.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Each organization has unique security requirements and preferences, and uniform security measures could limit the flexibility and customization that customers seek from cloud services,&#8221; he says. &#8220;Additionally, some customers may already have robust security protocols in place or may prefer to implement their own security measures, which are tailored to their specific needs.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Even so, the Ticketmaster and Santander breaches show that organizations must be aware of the potential risks in relying on their own security measures, and recognize the fact that weak or absent authentication mechanisms are prime targets for hackers to gain unauthorized access.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;As cloud adoption continues to rise, and more organizations transition their operations to the cloud,&#8221; Tiquet says, &#8220;it&#8217;s imperative for both cloud providers and customers to prioritize security and implement robust measures to protect against cyber threats.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cloud-security\/ticketmaster-breach-showcases-saas-data-security-risks\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A massive data breach at Ticketmaster and another one at<\/p>\n","protected":false},"author":12,"featured_media":3886,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3885","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ticketmaster-breach-showcases-saas-data-security-risks.jpg?fit=1000%2C562&ssl=1",1000,562,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ticketmaster-breach-showcases-saas-data-security-risks.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ticketmaster-breach-showcases-saas-data-security-risks.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ticketmaster-breach-showcases-saas-data-security-risks.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ticketmaster-breach-showcases-saas-data-security-risks.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ticketmaster-breach-showcases-saas-data-security-risks.jpg?fit=1000%2C562&ssl=1",1000,562,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ticketmaster-breach-showcases-saas-data-security-risks.jpg?fit=1000%2C562&ssl=1",1000,562,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ticketmaster-breach-showcases-saas-data-security-risks.jpg?fit=1000%2C562&ssl=1",1000,562,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ticketmaster-breach-showcases-saas-data-security-risks.jpg?resize=825%2C562&ssl=1",825,562,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ticketmaster-breach-showcases-saas-data-security-risks.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/ticketmaster-breach-showcases-saas-data-security-risks.jpg?fit=1000%2C562&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3885","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3885"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3885\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3886"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3885"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3885"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3885"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}