Snowflake Customer Multi-Tenant Credential Stuffing Campaign
Key Facts
- Legal Status: ALLEGED in U.S. District Court for the Northern District of California.
- Primary Target Sector: Telecommunications, Entertainment, Banking, Cloud Services.
- Documented Financial Loss: $150.0 million.
- 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Unauthorized intrusion originating from targeted infiltration directed against Telecommunications, Entertainment, Banking, Cloud Services networks. Coordinated cybercrime campaign targeting over 165 corporate customer tenants of cloud database provider Snowflake using credentials harvested by infostealer malware, exfiltrating billions of consumer records from Ticketmaster, Santander, and AT&T.
Operational & Financial Fallout
Stole records of 110 million AT&T phone accounts and 560 million Ticketmaster users, leading to extensive class-action lawsuits and regulatory filings. Impacted Telecommunications, Entertainment, Banking, Cloud Services infrastructure and associated victim operations.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Unauthorized intrusion originating from targeted infiltration directed against Telecommunications, Entertainment, Banking, Cloud Services networks. Coordinated cybercrime campaign targeting over 165 corporate customer tenants of cloud database provider Snowflake using credentials harvested by infostealer malware, exfiltrating billions of consumer records from Ticketmaster, Santander, and AT&T.
Adversary Kill Chain Flow
2 Documented PhasesThreat actors authenticated to victim Snowflake tenants using valid usernames and passwords that had been stolen by info-stealers (Lumma, RedLine) months earlier.
Adversaries executed native SQL commands in Snowflake command-line clients (snowsql) to stage and export customer database tables.
Stole records of 110 million AT&T phone accounts and 560 million Ticketmaster users, leading to extensive class-action lawsuits and regulatory filings. Impacted Telecommunications, Entertainment, Banking, Cloud Services infrastructure and associated victim operations.
Procedural & Incident Timeline
CISA issues alert warning organizations with Snowflake tenants to enforce multi-factor authentication and review network allowlists.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1078 | Valid Accounts Defense Evasion | "Threat actors authenticated to victim Snowflake tenants using valid usernames and passwords that had been stolen by info-stealers (Lumma, RedLine) months earlier." | Mandiant Joint Advisory ¶ 2 | reviewed |
| T1041 | Exfiltration Over C2 Channel Exfiltration | "Adversaries executed native SQL commands in Snowflake command-line clients (snowsql) to stage and export customer database tables." | CISA Advisory Alert | reviewed |