CASE DOSSIER alleged

Snowflake Enterprise Credential Stuffing & Customer Cloud Thefts

Docket: SEC-2024-8K-SNOW Court: U.S. Securities and Exchange Commission & FBI Cyber Division Opened: 2024-05-23 Sector: Cloud Services, Entertainment, Financial Services, Retail

Key Facts

Status
ALLEGED
Legal disposition
Loss Amount
$500.0 million
Extensive corporate data breach notification costs, extortion demands, and regulatory inquiries across 165+ global enterprise organizations.
Techniques
3
Verified mappings
Defendants
0
Named in charges
  • Legal Status: ALLEGED in U.S. Securities and Exchange Commission & FBI Cyber Division.
  • Primary Target Sector: Cloud Services, Entertainment, Financial Services, Retail.
  • Documented Financial Loss: $500.0 million.
  • 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Financially motivated threat actor collective UNC5537 systematically infiltrated over 165 corporate customer tenants hosted on Snowflake (including Ticketmaster, Santander Bank, Advance Auto Parts, and LendingTree). Attackers leveraged infostealer malware logs dating back years against enterprise user accounts that lacked multi-factor authentication and IP network allowlists, exfiltrating billions of consumer records.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

UNC5537 threat actors leveraged historical infostealer malware logs (RedLine, Vidar, Lumma) capturing username and password combinations for contractor accounts. Crucially, the target Snowflake customer accounts lacked multi-factor authentication and network IP allowlisting.

Operational & Financial Fallout

Systematic theft of corporate data spanning 165+ enterprise organizations, including 560 million Ticketmaster customer records, Santander customer databases, and Advance Auto Parts records, leading to widespread consumer fraud and extortion demands on BreachForums.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: ALLEGED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

UNC5537 threat actors leveraged historical infostealer malware logs (RedLine, Vidar, Lumma) capturing username and password combinations for contractor accounts. Crucially, the target Snowflake customer accounts lacked multi-factor authentication and network IP allowlisting.

Adversary Kill Chain Flow

4 Documented Phases
1
Initial Credential Acquisition Infostealer Log Ingestion
MITRE ATT&CK T1078 →

Adversaries acquired corporate employee credentials harvested by consumer infostealer Trojans that had infected non-managed personal devices between 2020 and 2024.

Artifacts & Tooling: RedLine stealer logs Lumma stealer archives Single-factor username/password pairs
2
Automated Reconnaissance Custom FROSTBITE Enumeration Tooling
MITRE ATT&CK T1110 →

UNC5537 utilized custom scripts (dubbed FROSTBITE) to query Snowflake customer tenant URLs, validating credentials and assessing available data schemas without triggering brute-force lockouts.

Artifacts & Tooling: FROSTBITE Python scripts Snowflake API requests Customer tenant URL enumeration
3
Cloud Storage Exfiltration Presigned Amazon S3 URL Staging
MITRE ATT&CK T1567 →

Using tenant query privileges, attackers generated short-lived pre-signed Amazon S3 storage URLs and dumped relational tables directly to adversary staging servers.

Artifacts & Tooling: COPY INTO s3:// stage commands Presigned AWS S3 URLs Relational database parquet dumps
4
Public Extortion BreachForums Auction and Ransom Threats
MITRE ATT&CK T1041 →

Adversaries posted samples on darknet cybercrime forums, contacting corporate victims directly via email and Telegram demanding cryptocurrency ransoms between $300,000 and $5,000,000.

Artifacts & Tooling: BreachForums listings Telegram extortion channels Sample proof CSV leaks
Real-World Blast Radius & Operational Fallout

Systematic theft of corporate data spanning 165+ enterprise organizations, including 560 million Ticketmaster customer records, Santander customer databases, and Advance Auto Parts records, leading to widespread consumer fraud and extortion demands on BreachForums.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce mandatory multi-factor authentication (MFA) across all SaaS and cloud data warehouse user accounts.
✓ Deploy Network Policy Allowlisting to restrict Snowflake database access strictly to corporate VPN and office IP addresses.
✓ Prohibit session tokens or credentials from non-managed or personal endpoints from accessing enterprise cloud resources.
✓ Audit third-party contractor accounts regularly and terminate inactive access credentials immediately upon contract conclusion.

Procedural & Incident Timeline

2024-04-14 incident

UNC5537 begins querying customer Snowflake tenants with infostealer-harvested credentials.

2024-05-27 breach_leak

Threat actors post 560 million Ticketmaster customer records for sale on BreachForums for $500,000.

2024-06-10 advisory

CISA, Mandiant, and Snowflake publish joint advisory warning of credential stuffing against accounts lacking MFA.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1078 Valid Accounts
Defense Evasion
"UNC5537 authenticated directly to enterprise customer Snowflake tenants using single-factor credentials previously captured by RedLine, Vidar, and Lumma infostealer Trojans on employee personal devices." Mandiant Threat Intelligence Special Report: UNC5537 Snowflake Campaign reviewed
T1110 Brute Force
Credential Access
"Adversaries utilized custom automated tooling named FROSTBITE to systematically test credentials across hundreds of customer tenant URLs and generate presigned staging URLs." Snowflake & CrowdStrike Joint Forensic Investigation Statement reviewed
T1567 Exfiltration Over Web Service
Exfiltration
"Attackers generated time-limited pre-signed Amazon S3 storage URLs using tenant privileges, transferring hundreds of terabytes of relational data directly to adversary-controlled cloud infrastructure." CISA Advisory AA24-165A reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, Snowflake Enterprise Credential Stuffing & Customer Cloud Thefts, No. SEC-2024-8K-SNOW (U.S. Securities and Exchange Commission & FBI Cyber Division 2024), https://cybercaselibrary.com/cases/snowflake-customer-credential-theft/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/snowflake-customer-credential-theft" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>