A breach at a third-party SaaS integration provider allegedly exposed authentication tokens that were then used to steal data from more than a dozen companies, with most of the activity targeting Snowflake customer environments. Snowflake said it detected unusual activity affecting a small number of customers tied to a specific third-party integration and emphasized that its own platform was not compromised through a vulnerability. Reporting identified the suspected source as Anodot, a data anomaly detection company owned by Glassbox, though neither company publicly responded at the time.
The threat actor identified as ShinyHunters claimed responsibility, saying it stole data from dozens of organizations and sought extortion payments to prevent publication of the information. The campaign reportedly also targeted other cloud and SaaS providers, while an attempted theft involving Salesforce was said to have been blocked by AI-based detection. Google Threat Intelligence Group said it was tracking the incident, and Payoneer said it was aware of the provider breach linked to Anodot but had determined it was not affected.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Vimeo disclosed that attackers accessed some customer and user data as a downstream result of the Anodot breach, including technical data, video titles, metadata, and in some cases email addresses. The company said uploaded video content, credentials, and payment card data were not affected, and it disabled Anodot credentials, removed the integration, and notified law enforcement.
Rockstar Games was named as one of the companies affected by the Anodot-linked token theft campaign. The company said attackers accessed only a limited amount of non-material company information.
As part of its response to the Anodot-linked intrusion activity, Snowflake said it locked potentially impacted customer accounts and notified affected customers. The company reiterated that its own systems were not compromised and no software vulnerability was exploited.
Google Threat Intelligence Group said it was aware of and tracking the incident. Payoneer also acknowledged awareness of the Anodot-related provider breach and said it determined it was not affected.
The ShinyHunters threat actor claimed responsibility for the attacks, saying it stole data from dozens of companies and demanded ransom payments to prevent publication. The campaign was described as an extortion operation following the token theft.
The threat actor said it also attempted to steal data from Salesforce, but the effort was blocked by AI-based detection systems. This was reported as part of the broader token-enabled intrusion campaign.
Snowflake said it detected unusual activity affecting a small number of customers linked to a specific third-party integration. The company stated its own systems were not compromised and no Snowflake vulnerability was involved.
Using the stolen tokens, attackers conducted data theft attacks against more than a dozen companies across cloud and SaaS environments. Most of the observed activity targeted Snowflake customer accounts.
A security issue at SaaS integration provider Anodot allegedly led to the theft of authentication tokens later used to access customer environments. Anodot and parent company Glassbox had not responded publicly at the time of reporting.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcetechcrunch.com
Open sourcescworld.com
Open sourcetechradar.com
Open sourcebleepingcomputer.com
Open sourcethreats.wiz.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.