It’s the end of July 2024. Do you know where your passwords are?
On July 4, a plaintext file containing nearly 10 billion passwords was released.
Known as rockyou2024, it is one of the largest password leaks ever recorded.
The file combines data from several sources. It also expands on earlier password collections, including rockyou2021, which contained 8.4 billion passwords.
Some of the leaked passwords may be old.
However, the exposure still creates major security risks.
Attackers can use these passwords for:
- Unauthorized login attempts
- Financial fraud
- Identity theft
- Future data breaches


Combined with data from other major breaches, such as the Mother of All Breaches (MOAB), these password collections become powerful tools for attackers.
Hackers can use them for brute-force attacks.
They test large numbers of usernames and passwords until they find a combination that works.
Credential stuffing attacks can cause serious problems for both businesses and individuals.
The Snowflake breach is one example.
One of the simplest ways to reduce this risk is to avoid reusing passwords across multiple accounts.
In this cybersecurity roundup for June and July 2024, we explore several major events.
These include:
- The ongoing Snowflake fallout
- The Synnovis cyberattack
- Disney’s Slack-related security incident
- Increased cyber activity linked to Russia
- The growing number of insider-related security events
Before updating your passwords, learn more about current cybersecurity trends and NIST’s updated password recommendations for 2024.
The Snowflake Data Breach
A breach of this scale deserves special attention.
Cloud data platform Snowflake has been at the center of cybersecurity discussions for all the wrong reasons this summer.
The incident affected several organizations.
Reports indicated that impacted customers included:
- Ticketmaster
- Santander
- Advance Auto Parts
- LendingTree
- QuoteWizard
AT&T also faced a major impact.
Reports stated that nearly all customer call and text records from a six-month period were exposed.
According to cybersecurity firm Mandiant, the attacks began with stolen customer credentials.
Attackers used these credentials to access and extract database information.
Mandiant found that the credentials were likely stolen through infostealer malware.
In some cases, contractors may have exposed company systems without realizing it.
This may have happened when company devices were used for personal activities such as:
- Gaming
- Downloading pirated software
- Installing unsafe files
These activities can introduce malware that steals sensitive information.
The incident highlights the importance of strong security controls.
Multi-factor authentication (MFA) is especially important.
Similar to other major cyber incidents, the lack of MFA and outdated credentials increased the risk of unauthorized access.
Mandiant noted several common weaknesses in affected environments:
- MFA was not required
- Credentials had not been changed for years
- Network allow lists were not used
- Access was not limited to trusted locations
From Russia with Malice
Spotlight on Password Security 2024…
We started this roundup with the rockyou2024 password leak.
That makes the timing of NIST’s updated Digital Identity Guidelines especially important.
Released in late July 2024, the guidelines include updated recommendations for password security and digital identity protection.
NIST recommends several key security practices.
Organizations should:
- Require multi-factor authentication (MFA)
- Create strong passwords
- Use password managers
- Change default credentials
- Keep antivirus software updated
- Apply security patches
- Train employees to identify phishing
- Provide regular cybersecurity training
The updated password guidance also highlights several important practices:
- Use long, complex passwords: NIST recommends passwords with at least 12 characters. Longer and randomly generated passwords offer stronger protection. Passwords should avoid easy-to-guess details such as names or company information.
- Use a password manager: Password managers can create and store unique passwords. They also help prevent password reuse.
- Avoid password reuse and hints: Every account should have a unique password. Security hints should also be avoided because they can make passwords easier to discover.
- Avoid unnecessary password changes: Frequent password changes can sometimes reduce security. Users may create weaker or more predictable passwords. Strong, unique passwords and password managers are usually a better approach.
As we close this edition of our cybersecurity roundup, another area deserves attention.
That is the growing role of insiders in cybersecurity incidents.
Cybercrime often brings to mind outside attackers using advanced methods.
However, many incidents begin with actions inside an organization.
Most insider-related incidents are not intentional attacks.
They often result from mistakes such as:
- Sending sensitive information to the wrong person
- Clicking malicious links
- Falling for phishing attempts
- Downloading unsafe files
- Using work devices for risky personal activities
These actions may seem simple.
However, they remain some of the hardest security risks for organizations to control.
Phishing attacks are also becoming more advanced.
Attackers now use methods such as:
- Fake customer support chats
- Impersonation of internal IT teams
- Social engineering
- Malware hidden in common downloads
The Disney Slack breach has been linked to several possible causes.
Attackers first claimed that an employee intentionally leaked internal data.
Later reports suggested another type of insider risk may have been involved.
Malware may have been hidden inside a game modification downloaded on the same device used to access Disney’s Slack environment.
In this case, an insider-related event may have helped attackers access more than one tebibyte of internal Disney data.
The incident shows why organizations must pay close attention to:
- Employee devices
- Personal downloads
- Access controls
- Security awareness
- Cybersecurity training


Conclusion
That concludes our coverage of the top cyber attacks and news from June and July 2024.
Subscribe to The PTP Report or check it out on our website for continued coverage of the latest cybersecurity threats.
[And for help with your own cybersecurity needs, contact PTP for onsite or remote consultants.]
You can also catch up on our prior bi-monthly roundups here:
References
RockYou2024: 10 billion passwords leaked in the largest compilation of all time, Cybernews
The Snowflake Attack May Be Turning Into One of the Largest Data Breaches Ever, Wired
Nearly all AT&T subscribers’ call records stolen in Snowflake cloud hack, Ars Technica
Toll of Snowflake Hack Widens With Theft of AT&T Text, Calling Data, Bloomberg
UK’s NHS says hackers have published data stolen in ransomware attack, Reuters
NHS cyber attack delayed my baby son’s life-saving kidney transplant, The i
Breast cancer patient reveals how Russian hackers forced her to delay surgery, The Telegraph
Russian ransomware gangs account for 69% of all ransom proceeds, BleepingComputer
Kaspersky to shut down US operations, lay off employees after US government ban, TechCrunch
How Disinformation From a Russian AI Spam Farm Ended up on Top of Google Search Results, Wired
Russia-linked hackers cut heat to 600 Ukrainian apartment buildings in the dead of winter, researchers say, Engadget
7 password rules to live by in 2024, according to security experts, ZDNet
Disney investigating massive leak of internal messages, BBC
A furry hacktivist group has breached Disney, leaked 1.1TiB of data, and says it’s because Club Penguin shut down, PC Gamer


