Snowflake Enterprise Credential Stuffing & Customer Cloud Thefts
Key Facts
- Legal Status: ALLEGED in U.S. Securities and Exchange Commission & FBI Cyber Division.
- Primary Target Sector: Cloud Services, Entertainment, Financial Services, Retail.
- Documented Financial Loss: $500.0 million.
- 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
UNC5537 threat actors leveraged historical infostealer malware logs (RedLine, Vidar, Lumma) capturing username and password combinations for contractor accounts. Crucially, the target Snowflake customer accounts lacked multi-factor authentication and network IP allowlisting.
Operational & Financial Fallout
Systematic theft of corporate data spanning 165+ enterprise organizations, including 560 million Ticketmaster customer records, Santander customer databases, and Advance Auto Parts records, leading to widespread consumer fraud and extortion demands on BreachForums.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
UNC5537 threat actors leveraged historical infostealer malware logs (RedLine, Vidar, Lumma) capturing username and password combinations for contractor accounts. Crucially, the target Snowflake customer accounts lacked multi-factor authentication and network IP allowlisting.
Adversary Kill Chain Flow
4 Documented PhasesAdversaries acquired corporate employee credentials harvested by consumer infostealer Trojans that had infected non-managed personal devices between 2020 and 2024.
UNC5537 utilized custom scripts (dubbed FROSTBITE) to query Snowflake customer tenant URLs, validating credentials and assessing available data schemas without triggering brute-force lockouts.
Using tenant query privileges, attackers generated short-lived pre-signed Amazon S3 storage URLs and dumped relational tables directly to adversary staging servers.
Adversaries posted samples on darknet cybercrime forums, contacting corporate victims directly via email and Telegram demanding cryptocurrency ransoms between $300,000 and $5,000,000.
Systematic theft of corporate data spanning 165+ enterprise organizations, including 560 million Ticketmaster customer records, Santander customer databases, and Advance Auto Parts records, leading to widespread consumer fraud and extortion demands on BreachForums.
Procedural & Incident Timeline
UNC5537 begins querying customer Snowflake tenants with infostealer-harvested credentials.
Threat actors post 560 million Ticketmaster customer records for sale on BreachForums for $500,000.
CISA, Mandiant, and Snowflake publish joint advisory warning of credential stuffing against accounts lacking MFA.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1078 | Valid Accounts Defense Evasion | "UNC5537 authenticated directly to enterprise customer Snowflake tenants using single-factor credentials previously captured by RedLine, Vidar, and Lumma infostealer Trojans on employee personal devices." | Mandiant Threat Intelligence Special Report: UNC5537 Snowflake Campaign | reviewed |
| T1110 | Brute Force Credential Access | "Adversaries utilized custom automated tooling named FROSTBITE to systematically test credentials across hundreds of customer tenant URLs and generate presigned staging URLs." | Snowflake & CrowdStrike Joint Forensic Investigation Statement | reviewed |
| T1567 | Exfiltration Over Web Service Exfiltration | "Attackers generated time-limited pre-signed Amazon S3 storage URLs using tenant privileges, transferring hundreds of terabytes of relational data directly to adversary-controlled cloud infrastructure." | CISA Advisory AA24-165A | reviewed |