{
  "id": "case-snowflake-credential-stuffing",
  "slug": "snowflake-multi-tenant-credential-attacks",
  "title": "Snowflake Customer Multi-Tenant Credential Stuffing Campaign",
  "summary": "Coordinated cybercrime campaign targeting over 165 corporate customer tenants of cloud database provider Snowflake using credentials harvested by infostealer malware, exfiltrating billions of consumer records from Ticketmaster, Santander, and AT&T.",
  "case_number": "SEC CIK 0001640147",
  "court": "U.S. District Court for the Northern District of California",
  "district": "N.D. Cal.",
  "country": "United States",
  "opened_at": "2024-05-31",
  "status": "alleged",
  "victim_sector": "Telecommunications, Entertainment, Banking, Cloud Services",
  "victim_country": "United States, Spain, Worldwide",
  "loss_amount_usd": 150000000,
  "loss_amount_note": "Stole records of 110 million AT&T phone accounts and 560 million Ticketmaster users, leading to extensive class-action lawsuits and regulatory filings.",
  "first_seen_at": "2024-04-14T00:00:00Z",
  "last_updated_at": "2026-06-25T14:00:00Z",
  "actor_slug": "unc5537",
  "defendant_slugs": [],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1078",
      "evidence_excerpt": "Threat actors authenticated to victim Snowflake tenants using valid usernames and passwords that had been stolen by info-stealers (Lumma, RedLine) months earlier.",
      "evidence_locator": "Mandiant Joint Advisory \u00b6 2",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Mandiant & Snowflake Joint Security Bulletin",
      "source_url": "https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1041",
      "evidence_excerpt": "Adversaries executed native SQL commands in Snowflake command-line clients (snowsql) to stage and export customer database tables.",
      "evidence_locator": "CISA Advisory Alert",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Alert",
      "source_url": "https://www.cisa.gov/news-events/alerts",
      "technique_name": "Exfiltration Over C2 Channel",
      "tactic": "Exfiltration"
    }
  ],
  "events": [
    {
      "event_type": "advisory",
      "event_date": "2024-06-05",
      "description": "CISA issues alert warning organizations with Snowflake tenants to enforce multi-factor authentication and review network allowlists."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Telecommunications, Entertainment, Banking, Cloud Services networks. Coordinated cybercrime campaign targeting over 165 corporate customer tenants of cloud database provider Snowflake using credentials harvested by infostealer malware, exfiltrating billions of consumer records from Ticketmaster, Santander, and AT&T.",
    "blast_radius": "Stole records of 110 million AT&T phone accounts and 560 million Ticketmaster users, leading to extensive class-action lawsuits and regulatory filings. Impacted Telecommunications, Entertainment, Banking, Cloud Services infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Defense Evasion",
        "title": "Defense Evasion & Security Blindfolding",
        "description": "Threat actors authenticated to victim Snowflake tenants using valid usernames and passwords that had been stolen by info-stealers (Lumma, RedLine) months earlier.",
        "technical_artifacts": [
          "T1078",
          "Valid Accounts"
        ],
        "mitre_technique_id": "T1078"
      },
      {
        "phase": "Phase 2: Exfiltration",
        "title": "Encrypted Cloud Data Exfiltration",
        "description": "Adversaries executed native SQL commands in Snowflake command-line clients (snowsql) to stage and export customer database tables.",
        "technical_artifacts": [
          "T1041",
          "Exfiltration Over C2 Channel"
        ],
        "mitre_technique_id": "T1041"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}