---
title: "Global Data Breach, Nokia Data Sold, Schneider Electric Breach, Cybersecurity News [November 04, 2024] | DuoCircle"
description: "Global Data Breach, Nokia Data Sold, Schneider Electric Breach, Cybersecurity News [November 04."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-46-of-2024/"
---

Quick Answer

Cybersecurity news for the week of November 4, 2024\. Canadian authorities arrested 26-year-old Alexander Moucka (aliases Judische, Waifu) for stealing data from Snowflake customers across 160-plus countries, with the activity attributed to UNC5537; AT&T phone records for roughly 110 million people were among the data exfiltrated. Reports also covered Nokia data offered for sale, a breach at Schneider Electric, third-party-risk impact on ISMS controls, a budding ransomware crew demanding large ransoms, advancements in AI-driven vulnerability detection, and an Okta fix for a username-related auth flaw.

Global Data Breach, Nokia Data Sold, Schneider Electric Breach, Cybersecurity News \[November 04, 2024\]

Your browser does not support the audio element.

[ Download episode](https://media.mailhop.org/duocircle/images/2024/11/Global-Data-Breach-Nokia-Data-Sold-Schneider-Electric-Breach-Cybersecurity-News-November-04-2024.mp3) 

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-46-of-2024%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Global%20Data%20Breach%2C%20Nokia%20Data%20Sold%2C%20Schneider%20Electric%20Breach%2C%20Cybersecurity%20News%20%5BNovember%2004%2C%202024%5D&url=undefined%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-46-of-2024%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-46-of-2024%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-46-of-2024%2F&title=Global%20Data%20Breach%2C%20Nokia%20Data%20Sold%2C%20Schneider%20Electric%20Breach%2C%20Cybersecurity%20News%20%5BNovember%2004%2C%202024%5D "Share on Reddit") [ ](mailto:?subject=Global%20Data%20Breach%2C%20Nokia%20Data%20Sold%2C%20Schneider%20Electric%20Breach%2C%20Cybersecurity%20News%20%5BNovember%2004%2C%202024%5D&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-46-of-2024%2F "Share via Email") 

![cybersecurity news](https://media.mailhop.org/duocircle/images/2024/11/dmarc-reporting-service-1.jpg) 

Presenting a fresh bundle of exciting, handpicked news to enhance your knowledge and keep you informed. We will cover points revolving around news items ranging from a man being allegedly involved in significant [data extortion](https://www.bleepingcomputer.com/news/security/interbank-confirms-data-breach-following-failed-extortion-data-leak/), third-party associated risks hampering the [ISMS protocols](https://www.techtarget.com/whatis/definition/information-security-management-system-ISMS), a budding [ransomware](/resources/locky-ransomware) group demanding huge ransom, advancements in AI vulnerability detection, and last but not least, Okta’s recent fix for a **username-related security flaw**. Let’s dive deep into the details!

## Global Data Heist: Hacker Gains Access to Sensitive Data

Allegedly, the sources have suggested that a 26-year-old man has been [arrested for stealing data](https://krebsonsecurity.com/2024/11/canadian-man-arrested-in-snowflake-data-extortions/#more-67735) from over 160 countries using Snowflake’s cloud data service. On a provisional arrest warrant from the United States, Canadian authorities detained Alexander Moucka, a.k.a. Connor Riley Moucka, of Kitchener, Ontario. The actor could access customers’ sensitive PII data by intruding into the systems or accounts protected with **minimal security**.

[![malicious hackers](https://media.mailhop.org/duocircle/images/2024/11/hosted-email-server-6712.jpg)](https://media.mailhop.org/duocircle/images/2024/11/hosted-email-server-6712.jpg)

By the approaching end of 2023, [malicious hackers](https://techcrunch.com/2024/07/19/us-cyber-agency-cisa-says-malicious-hackers-are-taking-advantage-of-crowdstrike-outage/) were very well aware of the fact that many large companies have considered Snowflake accounts as a reliable, safe option for storing and transferring volumes of **data on cloud systems** that were, to our astonishment, protected with little more than just a username and password. After thoroughly searching through the darknet markets for stolen [Snowflake account credentials](https://www.darkreading.com/threat-intelligence/snowflake-account-attacks-driven-by-exposed-legitimate-credentials), the hackers began raiding the data storage repositories used by some of the world’s largest corporations, including [AT&T](https://krebsonsecurity.com/2024/07/hackers-steal-phone-sms-records-for-nearly-all-att-customers/). _This disclosed the fact that previously personal information and phone records for roughly 110 million people were stolen_.

Moucka used the hacker handles Judische and Waifu in an attempt to masquerade himself. He has attributed the **Snowflake compromises** to a group it calls “UNC5537,” with members based from other possibly involved international countries. _This incident highlights the alarming scale of harm an individual can cause using off-the-shelf tools_.

## Malicious Actor Selling Nokia Data For $20,000, Nokia Remains Silent

There’s an infamous BreachForum criminal marketplace, where a recent post suggests that a hacker known as [IntelBroker](https://www.forbes.com/sites/daveywinder/2024/11/07/hacker-selling-nokia-data-for-20000-nokia-says-nothing-to-see-here/) has [breached data claiming](https://hackread.com/hackers-claim-access-nokia-internal-data-selling-20k/) to be related to Nokia and also put it on sale. This data has been allegedly compromised by a **third-party contractor** who has been closely working and collaborating with Nokia. IntelBroker has only suggested the price to be around $20,000 but it has yet not clearly specified.

On the other hand, Nokia has not released an official statement indicating breach attempts. However, the organization is currently [investigating the claims](https://www.bleepingcomputer.com/news/security/nokia-investigates-breach-after-hacker-claims-to-steal-source-code/) and monitoring the situation closely. But still the main issue remains hidden in the fact, which has also kept all cyber security experts puzzled, i.e., why did the [third-party contractors have access to Nokia’s source code](https://www.darkreading.com/cyberattacks-data-breaches/nokia-no-evidence-so-far-hackers-breached-company-data) in the first place? This critically raises concerns about the ISMS (Information Security Management System) handling procedures in an organizational setting. This highlights the need to **implement security measures** relevant to third-party partnerships.

## Schneider Electric Server’s Data Breached by Ransomware

Circling around the media are [news headlines](https://www.forbes.com/sites/daveywinder/2024/11/06/ransomware-gang-demands-125000-payment-in-french-bread-and-crypto/) in which the Hellcat [ransomware group](https://www.forbes.com/sites/daveywinder/2024/09/05/despicable-hackers-hold-disabled-bus-users-to-ransom-in-new-attack/) has demanded unusual ransom demand in Monero, a privacy-focused cryptocurrency. This demanded amount sums up to be exactly $125,000 in figures. These malicious threat players are new to the market, and they have publicly claimed to have successfully compromised the crucial systems of Schneider Electric. They also claim to have stolen approximately 40GB of data from established developer servers (**valuable information assets)**. 

After closely inspecting the incident, matter expert suggests that such bizarre ransom demand may be a part of the **marketing strategy**. The alleged group desperately is need of limelight and top position in the [cybercrime world](https://www.bbc.com/news/articles/cp9535x7vyyo). They seemingly want to instill fear and flaunt their [hacking skills](https://www.techtarget.com/searchsecurity/news/366598834/KnowBe4-catches-North-Korean-hacker-posing-as-IT-employee) among innocent mob. _Schneider Electric has acknowledged the breach of their data and is investigating the matter_.

## Google LLM Finds Zero-Day Via Employing AI-Driven Solutions

Through a blog post medium made available from Google’s [Project Zero](https://googleprojectzero.blogspot.com/2024/10/from-naptime-to-big-sleep.html), the masses were provided with a detailed breakthrough. This document listed that Google’s [large language model (LLM)](https://therecord.media/google-llm-sqlite-vulnerability-artificial-intelligence), commonly called “Big Sleep,” has identified a stack-based overflow in the **SQLite database engine**. But what makes this identification so celebrated? This [identification of vulnerability](https://web.archive.org/web/20250709102334/https://www.sans.org/newsletters/newsbites/xxvi-85/) in the organizational system paves a promising pathway ahead for significant usage and involvement of [artificial intelligence](/email-security/how-artificial-intelligence-approaches-are-changing-the-email-security-landscape/) solutions to uncover flaws in real-world software. Big Sleep was able to discover a flaw that is yet to be released. This was made possible by explicitly targeting vulnerabilities and analyzing recent commits for similar issues. 

_SQLite didn’t even wait for a day and quickly patched its software_. This incident is proof that **AI-driven solutions** can enhance the robustness of software security, consequently safeguarding valuable information assets. This highlights the importance of proactive vulnerability management in a continuously [evolving threat landscape](https://cybermagazine.com/articles/the-rapidly-evolving-threat-landscape-of-2024).

## Okta Fixes Long Username Authorization Bypass Vulnerability

Recently, the esteemed news columns suggested that [Okta has published an advisory](https://trust.okta.com/security-advisories/okta-ad-ldap-delegated-authentication-username/) warning regarding the organization’s system being prone or, more precisely, being vulnerable to hacking. They suggested that **creating and maintaining lengthy** usernames (more than 52 characters) could be [easily exploited](https://www.engadget.com/apps/okta-vulnerability-allowed-accounts-with-long-usernames-to-log-in-without-a-password-150041758.html) by malicious, self-centered [threat actors](/email-security/what-threat-actor-can-do-with-your-emails-without-password/) for exercising ulterior motives.

This can [bypass](https://www.theregister.com/2024/11/04/why%5Fthe%5Flong%5Fname%5Fokta/) an Okta AD/LDAP delegated authentication (DelAuth) established mechanism. However, for our information, **additional conditions** are required for the exploit to work successfully. _That condition states that the user needs to have previously authenticated or have created an authentication cache_.

[![practicing multi-factor authentication](https://media.mailhop.org/duocircle/images/2024/11/dkim-record-check.jpg)](https://media.mailhop.org/duocircle/images/2024/11/dkim-record-check.jpg)

This flaw was first introduced in a **July 2024 update** and was soon [discovered and resolved](https://web.archive.org/web/20250709102334/https://www.sans.org/newsletters/newsbites/xxvi-85/) in Okta’s production environment on October 30, 2024\. Most importantly, organizations practicing [multi-factor authentication (MFA)](/email-security/multi-factor-authentication-mfa-and-its-impact-on-email-security/) were not subjected to damages caused by this flaw.

What’s the takeaway from this [cybersecurity](/) incident? Well, it is learning about the importance of multi-factor authentication systems and keenly following **best practices on the internet** by eradicating the use of long usernames and employing complex passwords (different combinations of alphabets, numerics, special characters, uppercase, lowercase, etc.) in online settings.

## Topics

cyber securityNewsSecurity 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-46-of-2024%2F) [ ](https://twitter.com/intent/tweet?text=Global%20Data%20Breach%2C%20Nokia%20Data%20Sold%2C%20Schneider%20Electric%20Breach%2C%20Cybersecurity%20News%20%5BNovember%2004%2C%202024%5D&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-46-of-2024%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-46-of-2024%2F) Copy 

Related Articles

- [ ![cybersecurity news](https://media.mailhop.org/duocircle/images/2025/01/spf-permerror.jpg)  Microsoft Cybersecurity Transparency, Chrome Update Required, Google Calendar Phishing, Cybersecurity News \[December 23, 2024\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2025/)
- [ ![cybersecurity news](https://media.mailhop.org/duocircle/images/2026/01/email-smtp-service-7865.jpg)  Trust Wallet Hack, Browser Extension Espionage, Unleash Protocol Loss, Cybersecurity News \[December 29, 2025\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2026/)
- [ ![cybersecurity news](https://media.mailhop.org/duocircle/images/2025/03/phishing-protection-5643.jpg)  Bybit’s $1.5B Loss, FatalRAT Hits APAC, GitVenom Targets Wallets,, Cybersecurity News \[February 24, 2025\] News ](/blog/announcements/cyber-security-news-update-week-10-of-2025/)
- [ ![cybersecurity news](https://media.mailhop.org/duocircle/images/2026/03/email-smtp-service-6670.jpg)  LastPass Users Phished, Amazon Down US, UK Cybersecurity Boost, Cybersecurity News \[March 02, 2026\] News ](/blog/announcements/cyber-security-news-update-week-10-of-2026/)

## Related Articles

[  News 6m  Microsoft Cybersecurity Transparency, Chrome Update Required, Google Calendar Phishing, Cybersecurity News \[December 23, 2024\]  Jan 2, 2025 ](/blog/announcements/cyber-security-news-update-week-1-of-2025/)[  News 6m  Trust Wallet Hack, Browser Extension Espionage, Unleash Protocol Loss, Cybersecurity News \[December 29, 2025\]  Jan 5, 2026 ](/blog/announcements/cyber-security-news-update-week-1-of-2026/)[  News 7m  Bybit’s $1.5B Loss, FatalRAT Hits APAC, GitVenom Targets Wallets,, Cybersecurity News \[February 24, 2025\]  Mar 3, 2025 ](/blog/announcements/cyber-security-news-update-week-10-of-2025/)[  News 6m  LastPass Users Phished, Amazon Down US, UK Cybersecurity Boost, Cybersecurity News \[March 02, 2026\]  Mar 9, 2026 ](/blog/announcements/cyber-security-news-update-week-10-of-2026/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Global Data Breach, Nokia Data Sold, Schneider Electric Breach, Cybersecurity News [November 04, 2024]","description":"Global Data Breach, Nokia Data Sold, Schneider Electric Breach, Cybersecurity News [November 04.","url":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-46-of-2024/","datePublished":"2024-11-11T17:32:42.000Z","dateModified":"2025-08-25T14:13:13.000Z","dateCreated":"2024-11-11T17:32:42.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-46-of-2024/"},"articleSection":"announcements","keywords":"cyber security, News, Security","wordCount":979,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2024/11/dmarc-reporting-service-1.jpg","caption":"cybersecurity news","width":900,"height":506},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Global Data Breach, Nokia Data Sold, Schneider Electric Breach, Cybersecurity News [November 04, 2024]","item":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-46-of-2024/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Global Data Breach, Nokia Data Sold, Schneider Electric Breach, Cybersecurity News [November 04, 2024]","item":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-46-of-2024/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Global Data Breach, Nokia Data Sold, Schneider Electric Breach, Cybersecurity News [November 04, 2024]","description":"Global Data Breach, Nokia Data Sold, Schneider Electric Breach, Cybersecurity News [November 04.","url":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-46-of-2024/","datePublished":"2024-11-11T17:32:42.000Z","dateModified":"2025-08-25T14:13:13.000Z","dateCreated":"2024-11-11T17:32:42.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-46-of-2024/"},"articleSection":"announcements","keywords":"cyber security, News, Security","wordCount":979,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2024/11/dmarc-reporting-service-1.jpg","caption":"cybersecurity news","width":900,"height":506},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
