Snowflake says up to 165 customer accounts hit in credential theft campaign
- Organization
- Snowflake
- Exploit
- Credential Compromise
- Industry
- Cloud Computing
Snowflake and Google-owned Mandiant said in June 2024 that roughly 165 organisations had been notified that their Snowflake instances were potentially exposed in a data theft and extortion campaign. Mandiant published its findings on 10 June and attributed the activity to a financially motivated group it tracks as UNC5537.
Mandiant said the intrusions did not stem from a breach of Snowflake's own systems. The attackers signed in using valid customer credentials harvested by infostealer malware including Vidar, RedLine, Raccoon Stealer, Lumma, Metastealer and RisePro, some of it running on contractor machines also used for gaming and pirated downloads. Around 80 percent of the affected accounts had credentials exposed in earlier infostealer activity, in some cases dating back to November 2020, and those passwords had never been rotated.
Three conditions made the accounts reachable: no multi-factor authentication, credentials left unchanged after exposure, and no network allow lists restricting where connections could originate. Mandiant dated the campaign's start to around 14 April 2024 and said UNC5537 members appeared to be based in North America, with at least one associate in Turkey.
Snowflake had initially described the impact as limited to a small number of customers. It subsequently worked with Mandiant on the investigation, published detection and hardening guidance on 30 May, and said it was developing plans to require advanced security controls such as multi-factor authentication and network policies. Mandiant released a Snowflake threat hunting guide on 17 June.