CASE DOSSIER alleged

Snowflake Customer Multi-Tenant Credential Stuffing Campaign

Docket: SEC CIK 0001640147 Court: U.S. District Court for the Northern District of California Opened: 2024-05-31 Sector: Telecommunications, Entertainment, Banking, Cloud Services

Key Facts

Status
ALLEGED
Legal disposition
Loss Amount
$150.0 million
Stole records of 110 million AT&T phone accounts and 560 million Ticketmaster users, leading to extensive class-action lawsuits and regulatory filings.
Techniques
2
Verified mappings
Defendants
0
Named in charges
  • Legal Status: ALLEGED in U.S. District Court for the Northern District of California.
  • Primary Target Sector: Telecommunications, Entertainment, Banking, Cloud Services.
  • Documented Financial Loss: $150.0 million.
  • 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Coordinated cybercrime campaign targeting over 165 corporate customer tenants of cloud database provider Snowflake using credentials harvested by infostealer malware, exfiltrating billions of consumer records from Ticketmaster, Santander, and AT&T.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Unauthorized intrusion originating from targeted infiltration directed against Telecommunications, Entertainment, Banking, Cloud Services networks. Coordinated cybercrime campaign targeting over 165 corporate customer tenants of cloud database provider Snowflake using credentials harvested by infostealer malware, exfiltrating billions of consumer records from Ticketmaster, Santander, and AT&T.

Operational & Financial Fallout

Stole records of 110 million AT&T phone accounts and 560 million Ticketmaster users, leading to extensive class-action lawsuits and regulatory filings. Impacted Telecommunications, Entertainment, Banking, Cloud Services infrastructure and associated victim operations.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: ALLEGED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Unauthorized intrusion originating from targeted infiltration directed against Telecommunications, Entertainment, Banking, Cloud Services networks. Coordinated cybercrime campaign targeting over 165 corporate customer tenants of cloud database provider Snowflake using credentials harvested by infostealer malware, exfiltrating billions of consumer records from Ticketmaster, Santander, and AT&T.

Adversary Kill Chain Flow

2 Documented Phases
1
Phase 1: Defense Evasion Defense Evasion & Security Blindfolding
MITRE ATT&CK T1078 →

Threat actors authenticated to victim Snowflake tenants using valid usernames and passwords that had been stolen by info-stealers (Lumma, RedLine) months earlier.

Artifacts & Tooling: T1078 Valid Accounts
2
Phase 2: Exfiltration Encrypted Cloud Data Exfiltration
MITRE ATT&CK T1041 →

Adversaries executed native SQL commands in Snowflake command-line clients (snowsql) to stage and export customer database tables.

Artifacts & Tooling: T1041 Exfiltration Over C2 Channel
Real-World Blast Radius & Operational Fallout

Stole records of 110 million AT&T phone accounts and 560 million Ticketmaster users, leading to extensive class-action lawsuits and regulatory filings. Impacted Telecommunications, Entertainment, Banking, Cloud Services infrastructure and associated victim operations.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.
✓ Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.
✓ Maintain isolated, immutable backups of critical directory services and transaction databases.
✓ Deploy real-time endpoint detection and response (EDR) agents with automated containment policies.

Procedural & Incident Timeline

2024-06-05 advisory

CISA issues alert warning organizations with Snowflake tenants to enforce multi-factor authentication and review network allowlists.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1078 Valid Accounts
Defense Evasion
"Threat actors authenticated to victim Snowflake tenants using valid usernames and passwords that had been stolen by info-stealers (Lumma, RedLine) months earlier." Mandiant Joint Advisory ¶ 2 reviewed
T1041 Exfiltration Over C2 Channel
Exfiltration
"Adversaries executed native SQL commands in Snowflake command-line clients (snowsql) to stage and export customer database tables." CISA Advisory Alert reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, Snowflake Customer Multi-Tenant Credential Stuffing Campaign, No. SEC CIK 0001640147 (U.S. District Court for the Northern District of California 2024), https://cybercaselibrary.com/cases/snowflake-multi-tenant-credential-attacks/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/snowflake-multi-tenant-credential-attacks" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>