메뉴
BL
404 Media 34일 전

해커들은 어떻게 매디슨 스퀘어 가든을 해킹했나

IMP
8/10
핵심 요약

해커 그룹 '샤이니헌터스(ShinyHunters)'는 직원에게 전화를 걸어 정체를 속이는 음성 피싱(비싱, Vishing) 방식을 통해 매디슨 스퀘어 가든(MSG)의 시스템에 침투했습니다. 이들은 다단계 인증(MFA) 과정을 교묘하게 우회하여 45GB에 달하는 내부 데이터를 탈취했습니다. 이 사건은 이메일 기반의 피싱을 넘어, 전화를 이용한 사회공학적 공격이 기업 보안에 매우 심각한 위협으로 자리 잡았음을 보여줍니다.

번역된 본문

해커들과 IT 전문 매체 404 Media의 탈취 데이터 검토 결과에 따르면, 매디슨 스퀘어 가든(MSG)에서 대량의 데이터를 훔친 해커들은 하급 직원에게 전화를 걸어 속임수를 쓴 뒤 MSG 시스템에 접근할 수 있었습니다. 이번 침해 사고는 음성 전화를 이용한 사회공학적 공격의 위험성을 잘 보여주며, 이를 흔히 '비싱(Vishing)'이라고 부릅니다. 해커가 이메일을 통해 누군가를 속이거나 가짜 로그인 페이지를 보내는 기존의 피싱(Phishing)은 수십 년간 흔했지만, 비싱은 특히 젊고 영어를 모국어로 구사하는 해커들이 심각한 사이버 보안 위협으로 떠오르면서 최근에야 널리 퍼지게 되었습니다.

💡 본 해킹이나 다른 사건에 대해 알고 계신 것이 있나요? 제보를 환영합니다. 업무용 기기가 아닌 개인 기기를 이용해 Signal(joseph.404)로 보안 메시지를 보내거나 joseph@404media.co로 이메일을 보내주시면 됩니다.

“직원을 상대로 Microsoft Entra를 대상으로 비싱을 시도했습니다.” MSG 침해의 배후에 있는 해커 그룹 ‘샤이니헌터스(ShinyHunters)’의 일원이 침투 과정에 대해 설명해 달라는 404 Media의 요청에 답변했습니다. Microsoft Entra는 Okta와 유사한 마이크로소프트의 ID 관리 제품으로, 직원들이 업무에 필요한 도구나 서비스에 로그인할 수 있게 해줍니다.

지난주 404 Media는 해커들이 MSG에서 훔친 데이터를 업로드했다고 보도했습니다. 당시 404 Media가 검토한 샘플에는 농구팀 뉴욕 닉스(Knicks) 관련 인사들을 언급한 파일이 포함되어 있었으며, 여기에는 '주소', '유명해진 이유', '인력 비용' 등의 항목이 있었습니다. 경우에 따라 특정 연예인의 위험도 점수도 포함되어 있었는데, 배우이자 감독이자 열성적인 닉스 팬인 벤 스틸러(Ben Stiller)는 '저위험(Low Risk)'으로, 래퍼 부기 위드 다 후디(Boogie with da Hoodie)는 '고위험(High Risk)'으로 표시되어 있었습니다.

이후 404 Media는 45GB 전체 데이터 덤프를 다운로드했고, 특정 MSG 직원의 OneDrive 콘텐츠를 발견했습니다. 여기에는 업무 문서, 사진, 스크린샷 및 기타 첨부 파일들이 포함되어 있었습니다. '개인용(Personal)'이라는 폴더에는 해당 직원의 이름과 기타 개인정보가 포함된 W-2 세금 양식이 들어 있었습니다. 이는 침해 사고가 이 특정 직원에게서 시작되었을 수 있음을 시사합니다. 404 Media는 동일한 이름의 링크드인(LinkedIn) 프로필을 찾았고, 이 사람이 MSG에서 근무했음을 확인했습니다. 404 Media는 개인정보 보호를 위해 해당 직원의 이름을 공개하지 않았습니다.

404 Media는 샤이니헌터스 일원에게 그룹이 어떻게 MSG 시스템을 침해했는지 추가로 질문했습니다. 해당 일원은 이 직원의 이름을 제공했습니다. 404 Media가 공격 방식에 대해 더 자세히 설명해 달라고 요청하자, 그들은 자신들에 대한 내용이라고 주장하며 5월에 마이크로소프트에서 게시한 블로그 포스트를 가리켰습니다. 해당 포스트는 마이크로소프트가 '체계적이고 정교하며 다층적인 공격'이라고 부른 방식을 설명하고 있습니다. 비록 5월 18일에 게시되어 다른 공격을 묘사하고 있고(샤이니헌터스 일원은 MSG 해킹이 6월 5일에 발생했다고 밝혔습니다) 공격 시점이 다르지만, 그 과정에는 유사점이 있습니다.

마이크로소프트의 블로그 포스트에 따르면, 해커들은 먼저 Microsoft Entra 자격 증명을 얻기 위해 특정 인물을 표적으로 삼았습니다. 해커들은 셀프 서비스 비밀번호 재설정(SSPR) 프로세스를 시작한 뒤, 정상적인 요청처럼 보이는 다단계 인증(MFA) 프롬프트를 완료하도록 사용자를 속였다고 마이크로소프트는 전했습니다. 블로그 포스트는 다음과 같이 설명합니다. “예를 들어, 위협 행위자는 내부 IT 지원 담당자를 가장해 사용자에게 연락한 뒤 계정에 긴급 확인이 필요하다고 주장하며, 일상적인 비밀번호 재설정 절차의 일부로 MFA 프롬프트를 승인하도록 지시할 수 있습니다.”

이처럼 시스템에 침투한 후, 해커들은 데이터가 저장된 다른 애플리케이션이나 시스템으로 침투를 확장할 수 있습니다. MSG의 경우, 데이터 덤프에는 마이크로소프트의 공유 및 협업 플랫폼인 SharePoint 인스턴스에서 가져온 데이터가 포함되어 있었습니다.

샤이니헌터스 일원은 블로그 포스트 이상의 자세한 설명은 하지 않았지만, MSG 해킹과 관련하여 구체적으로 언급하며 404 Media에 다음과 같이 말했습니다. “우리는 직원에게 전화를 걸어 그들이 SSPR 프로세스를 수행하도록 만들었습니다.”

로펌 모건 앤 모건(Morgan and Morgan)은 이번 침해 사고와 관련하여 MSG의 방문객 감시 관행이 원인이 되었다며 집단 소송을 제기했습니다. 404 Media가 샤이니헌터스 일원에게 MSG의 감시 관행 때문에 표적이 되었는지 묻자, 그들은 “그렇습니다. 그 이유로 돈을 지불할 줄 알았지만 놀랍게도 지불하지 않았다”라고 대답했습니다. MSG는 404 Media의 요청에 응답하지 않았습니다.

원문 보기
원문 보기 (영어)
The hackers that stole a large cache of data from Madison Square Garden called a low level employee and tricked them into letting the hackers into MSG’s systems, according to the hackers and 404 Media’s review of the stolen data. The breach highlights the risk of social engineering over voice calls, sometimes called ‘vishing’. Whereas phishing, where hackers social engineer someone over email or send them a fake login page, has been common for decades, vishing has only become prevalent more recently, especially as young and native English speaking hackers have become a serious cybersecurity threat. 💡 Do you know anything else about this hack or others? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co. “Employee vishing on their Microsoft Entra,” a member of the hacking group behind the MSG breach, called ShinyHunters, told 404 Media when asked to explain how the group got in. Microsoft Entra is Microsoft’s identity management product , similar to Okta, which lets employees log into whatever tools or services they need to at work. Last week 404 Media reported hackers had uploaded data stolen from MSG. A sample 404 Media reviewed at the time included files mentioning Knicks-related personalities, with fields such as “address,” “claim to fame,” and “cost of talent.” In some cases the data included a risk score for certain celebrities, with actor, director and Knicks fan Ben Stiller described as “Low Risk” and rapper Boogie with da Hoodie marked “High Risk.” Since then 404 Media downloaded the full 45GB data dump and found the contents of a specific MSG employee’s OneDrive. It included work documents, photos, screenshots, and other attachments. A folder called “Personal,” contained the employee’s W-2 form, which included their name and other personal information. This indicated that the breach may have originated from this specific employee. 404 Media found a LinkedIn profile under the same name showing this person worked at MSG. 404 Media is not naming the employee for their privacy. 404 Media then asked a member of ShinyHunters how the group breached MSG. The member provided this employee’s name. When 404 Media asked the ShinyHunters member to elaborate on how the group compromised MSG, they pointed to a May blog post from Microsoft , which they said was “about us.” That post described what Microsoft called a “methodical, sophisticated, and multi-layered attack.” It details another attack—the blog post was published May 18 and the ShinyHunters member said the MSG hack happened on June 5—but there are similarities. The Microsoft blog post says hackers first targeted specific people to get their Microsoft Entra credentials. The hackers started the Self-Service Password Reset (SSPR) process, and then tricked users into completing the multifactor authentication prompts that appear legitimate, Microsoft said. “For example, the threat actor might impersonate an internal information technology (IT) support representative and contact the user claiming that their account requires urgent verification, instructing them to approve MFA prompts as part of a routine password reset procedure,” the blog post reads. Once in, the hackers can then pivot onto other apps or systems where data may be stored. In MSG’s case, the dump includes data taken from a SharePoint instance, Microsoft’s sharing and collaboration platform. The ShinyHunters member didn’t elaborate beyond the blog post, but told 404 Media: “​​We called the employee and had them do the SSPR process,” referring specifically to the MSG hack. Law firm Morgan and Morgan has filed a class action lawsuit related to the breach, arguing MSG’s surveillance of visitors led to it. When asked if ShinyHunters targeted MSG because of the venue’s surveillance practices, the member said, “Yes we thought they would pay for that reason but they surprisingly did not.” MSG did not respond to a request for comment. 404 Media reported this week the data dump contained a dossier on activists who had opposed MSG’s facial recognition program. About the author Joseph is an award-winning investigative journalist focused on generating impact. His work has triggered hundreds of millions of dollars worth of fines, shut down tech companies, and much more. More from Joseph Cox