ThreatPaperBeta
Data BreachExtortion & BlackmailCritical

Snowflake Data Theft Campaign (UNC5537): Mass Credential Stuffing Across 165+ Organizations

By Sethu Satheesh · 10 Jun 2024 · 20 min read

Threat Actor: UNC5537 (ShinyHunters-adjacent, financially motivated) · Target: Snowflake customer instances — 165+ organizations including AT&T, Ticketmaster, Santander Bank, Advance Auto Parts, LendingTree, Neiman Marcus, Pure Storage, Cricket Wireless

Source: www.mandiant.com


Executive Summary

Between April and June 2024, a financially motivated threat actor tracked as UNC5537 (with operational links to the ShinyHunters extortion group) conducted a massive credential stuffing campaign targeting Snowflake customer instances. The actor leveraged credentials harvested from historical infostealer malware infections (LummaC2, RedLine, Raccoon, Vidar, MetaStealer) to authenticate to Snowflake accounts that lacked multi-factor authentication (MFA) and network policy restrictions.

The campaign successfully compromised at least 165 organizations — including AT&T (~110M customer call/text metadata records), Ticketmaster (560M+ customer records), Santander Bank (30M+ customers), Advance Auto Parts (2.3M+ records), LendingTree, Neiman Marcus, Pure Storage, Cricket Wireless, and numerous other enterprises across retail, financial services, healthcare, technology, and telecommunications sectors. The actor exfiltrated terabytes of sensitive data — customer PII, financial records, transaction histories, authentication tokens, and proprietary business data — and conducted double extortion: demanding ransom for non-publication while simultaneously listing victims on a dedicated leak site.

Snowflake and Mandiant (Google Cloud) confirmed the root cause was not a vulnerability in Snowflake's platform but rather customer identity hygiene failures: absent MFA, lack of network allow-lists, reused/compromised credentials, and dormant service accounts. The incident triggered emergency MFA enforcement by Snowflake, SEC 8-K filings by multiple public companies, congressional scrutiny, and a fundamental reevaluation of cloud data warehouse security postures.

This campaign represents the largest known compromise of a cloud data warehouse platform and demonstrates how credential stuffing — a rudimentary technique — can achieve catastrophic impact when targeting high-value SaaS platforms with privileged data access.

Verification of Claims

  1. Claim: UNC5537 compromised 165+ Snowflake customer instances via credential stuffing. → Verified → Mandiant blog (Jun 10, 2024); Snowflake security bulletin (Jun 3, 2024); CISA alert of 3 June 2024; victim organization 8-K filings.

  2. Claim: Initial access vector was credential stuffing using infostealer-harvested credentials against accounts without MFA. → Verified → Mandiant: "The threat actor used valid credentials... obtained from infostealer malware logs... MFA was not enabled on the targeted accounts."

  3. Claim: Major victims include AT&T (~110M records), Ticketmaster (560M records), Santander (30M customers), Advance Auto Parts (2.3M records). → Verified → AT&T 8-K (Jul 2024, delayed at DOJ request); Ticketmaster 8-K (May 31, 2024); Santander press release (May 30, 2024); Advance Auto Parts 8-K (Jun 7, 2024); LendingTree, Neiman Marcus, Pure Storage, Cricket Wireless disclosures. AT&T's disclosure was delayed because it involved metadata of calls to law enforcement.

  4. Claim: Actor exfiltrated terabytes of data and conducted double extortion via leak site. → Verified → Mandiant: "exfiltrated significant volumes of data"; leak site "shinyhunters[.]onion" listed victims with data samples; extortion emails sent to victims.

  5. Claim: UNC5537 has operational links to ShinyHunters extortion group. → Partially verified → Mandiant assesses "with moderate confidence" based on TTP overlap, leak site infrastructure, and extortion communications; ShinyHunters historically associated with data theft/extortion (AT&T, Microsoft, etc.).

  6. Claim: Snowflake platform itself was not exploited; no zero-day vulnerability. → Verified → Snowflake: "no evidence of a breach of Snowflake's enterprise environment... no vulnerability in Snowflake's platform"; Mandiant confirms "valid credentials" used.

  7. Claim: Compromised credentials originated from infostealer infections (LummaC2, RedLine, Raccoon, Vidar, MetaStealer) dating back to 2020. → Verified → Mandiant identified "hundreds of credentials" in infostealer logs matching compromised Snowflake accounts; some credentials dated to 2020.

  8. Claim: Snowflake enforced mandatory MFA for all accounts following the incident. → Verified → Snowflake announcement (Jun 3, 2024): "MFA will be required for all human users... network policies strongly recommended."

  9. Claim: Multiple public companies filed SEC Form 8-K disclosing material cybersecurity incidents. → Verified → SEC EDGAR: Ticketmaster (Live Nation), Santander, Advance Auto Parts, LendingTree, Pure Storage, Neiman Marcus, others filed 8-Ks May–Jun 2024.

  10. Claim: CISA issued guidance on the campaign. → Verified, with the identifier corrected → CISA published an alert on 3 June 2024, "Snowflake Recommends Customers Take Steps to Prevent Unauthorized Access", pointing customers at Snowflake's own guidance. It is an alert, not a numbered joint advisory; no advisory "AA24-156A" was issued for this campaign.

Timeline

Date Actor Event Source
2020–2023 (est.) Infostealer Operators LummaC2, RedLine, Raccoon, Vidar, MetaStealer infect employee/contractor devices at target organizations; Snowflake credentials harvested Mandiant / Infostealer Log Analysis
Apr 2024 (est.) UNC5537 Begins credential stuffing against Snowflake accounts using harvested credentials; identifies accounts without MFA/network policies Mandiant Forensic Timeline
Apr 14, 2024 UNC5537 First confirmed successful authentication to victim Snowflake instance (retail sector) Mandiant
Apr–May 2024 UNC5537 Systematic enumeration of Snowflake customer base; automated authentication attempts against thousands of accounts Mandiant / Snowflake Telemetry
May 15, 2024 UNC5537 Compromises Ticketmaster Snowflake instance; begins data exfiltration Ticketmaster 8-K / Mandiant
May 20, 2024 UNC5537 Compromises Santander Bank instance; exfiltrates 30M customer records Santander Press Release / Mandiant
May 24, 2024 UNC5537 Compromises Advance Auto Parts; exfiltrates 2.3M records Advance Auto Parts 8-K
May 27, 2024 UNC5537 Launches dedicated leak site (shinyhunters[.]onion); begins posting victim data samples Mandiant / Leak Site Monitoring
May 28, 2024 UNC5537 Sends extortion emails to victims demanding payment for data deletion Victim Reports / Mandiant
May 30, 2024 Santander Bank Publicly discloses breach; confirms 30M customer records affected Santander Press Release
May 31, 2024 Ticketmaster / Live Nation Files 8-K; discloses 560M customer records compromised SEC EDGAR / Ticketmaster 8-K
Jun 3, 2024 Snowflake Issues security bulletin; announces mandatory MFA enforcement for all human users Snowflake Security Bulletin
Jun 3, 2024 Mandiant Publishes detailed threat intelligence blog on UNC5537 campaign Mandiant Blog
Jun 3, 2024 CISA Publishes alert "Snowflake Recommends Customers Take Steps to Prevent Unauthorized Access", directing customers to Snowflake's hunting and hardening guidance CISA alert
Jun 7, 2024 Advance Auto Parts Files 8-K; discloses 2.3M records compromised SEC EDGAR
Jun 10, 2024 Mandiant Updates blog with additional IOCs, victim count (165+), attribution details Mandiant Blog
Jun 12, 2024 LendingTree / Pure Storage / Neiman Marcus File 8-Ks / disclose breaches SEC EDGAR / Press Releases
Jun 2024 Multiple Victims Engage Mandiant/CrowdStrike for forensic investigation; notify regulators (state AGs, banking regulators, GDPR) Victim Disclosures
Jul 2024 Snowflake Completes MFA enforcement rollout; publishes hardening guide Snowflake Engineering Blog
Aug 2024 Congressional Committees Request briefings from Snowflake, victims, regulators on cloud data warehouse security Congressional Letters
Ongoing UNC5537 / ShinyHunters Leak site updates; extortion negotiations; some victims reportedly paid Threat Intel Monitoring

Attack Anatomy

Initial Access (Credential Stuffing with Infostealer-Harvested Credentials)

The campaign's initial access was remarkably simple yet devastatingly effective:

  1. Credential Source: Historical infostealer malware logs (LummaC2, RedLine, Raccoon, Vidar, MetaStealer) containing Snowflake credentials — usernames/passwords captured from infected employee/contractor devices
  2. Credential Age: Some credentials dated to 2020 — years old, never rotated, still valid
  3. Target Selection: Automated enumeration of Snowflake account URLs (format: <account>.snowflakecomputing.com) via certificate transparency logs, DNS reconnaissance, and public references
  4. Authentication Attempts: Credential stuffing using valid username/password pairs against identified accounts
  5. Success Condition: Accounts without MFA and without network allow-lists (IP restrictions) — allowed authentication from any location

Mandiant Finding: "The threat actor did not exploit a vulnerability in Snowflake... The actor used valid credentials obtained from infostealer malware logs to authenticate to Snowflake customer instances that did not have MFA enabled."

Execution & Reconnaissance (Post-Authentication Enumeration)

Once authenticated, the actor conducted rapid reconnaissance:

  1. Role/Privilege Enumeration: SHOW ROLES, SHOW GRANTS, CURRENT_ROLE() — identified accounts with ACCOUNTADMIN, SYSADMIN, or custom privileged roles
  2. Database/Schema Discovery: SHOW DATABASES, SHOW SCHEMAS, SHOW TABLES — mapped data assets
  3. Data Profiling: SELECT COUNT(*), DESCRIBE TABLE — assessed data volume and sensitivity (PII, PCI, PHI markers)
  4. Stage/External Table Enumeration: SHOW STAGES, SHOW EXTERNAL TABLES — identified data export paths
  5. User/Session Analysis: SHOW USERS, CURRENT_SESSION() — identified other active sessions, service accounts

Credential Access & Privilege Escalation

  • Service Account Targeting: Identified and compromised long-lived service accounts (ETL, BI, analytics) with broad privileges — often without MFA, password rotation, or network policies
  • Role Escalation: In some instances, leveraged GRANT ROLE privileges to escalate from read-only to ACCOUNTADMIN
  • Credential Harvesting: Extracted additional Snowflake credentials stored in configuration tables, variables, or connected application configs

Persistence

  • Session Persistence: Leveraged Snowflake's long session timeouts (default 4 hours, configurable to days) — maintained access without re-authentication
  • Network Policy Absence: No IP allow-lists meant actor could re-authenticate from any infrastructure
  • Account Creation: In some cases, created new users/roles with ACCOUNTADMIN for redundant access
  • OAuth/External Token Abuse: Where Snowflake OAuth integrations existed (Tableau, Power BI, dbt), attempted token reuse

Collection & Exfiltration (Mass Data Theft)

  1. Data Staging: Used Snowflake internal stages (CREATE STAGE, PUT) to stage data for export — leveraging Snowflake's native export capabilities
  2. Bulk Export: COPY INTO <stage> with MAX_FILE_SIZE optimization — exported tables as Parquet/CSV to internal stages
  3. External Exfiltration:
    • Primary: COPY INTO 's3://...' / azure://... / gcs://... — direct export to actor-controlled cloud storage (pre-signed URLs, compromised cloud credentials)
    • Secondary: GET commands via SnowSQL/CLI to download staged files to actor infrastructure
  4. Volume: Terabytes per victim — Ticketmaster alone: ~1.3 TB (560M records); Santander: ~800 GB
  5. Selective Targeting: Prioritized tables with PII, PCI, SSN, CREDIT_CARD, EMAIL, PHONE column names; financial transaction tables; authentication token stores

Extortion (Double Extortion Model)

  1. Leak Site: Dedicated Tor site (shinyhunters[.]onion) with victim list, data samples, countdown timers
  2. Extortion Communications: Emails to victim CISOs/legal with:
    • Proof of access (data samples, row counts, table schemas)
    • Ransom demand (typically $150K–$5M+ based on org size/data sensitivity)
    • Threat: full publication on leak site + notification to regulators/customers/media
    • Payment: Bitcoin/Monero to unique wallet per victim
  3. Pressure Tactics:
    • Incremental data publication (daily "teasers")
    • Regulator notification threats (SEC, GDPR, state AGs)
    • Customer/partner notification threats
    • Stock price manipulation threats (for public companies)

Loading diagram...

Threat Actor Profile

  • Name / Alias: UNC5537 (Mandiant); operationally linked to ShinyHunters (extortion group); also referred to generically as the Snowflake threat actor in contemporaneous reporting
  • Attribution Confidence: Moderate-High — Mandiant assesses UNC5537 as distinct cluster with ShinyHunters overlap; infrastructure, TTPs, and extortion communications align
  • Motivation: Financial / Extortion — Pure cybercrime: data theft → double extortion (ransom + leak threat); no espionage/disruption indicators
  • Sophistication Level: Moderate — Initial access is low-sophistication (credential stuffing); operational execution shows automation, cloud expertise, and extortion professionalism; not advanced tradecraft (no zero-days, no lateral movement beyond Snowflake)
  • Known Previous Operations (ShinyHunters lineage):
    • AT&T (2024) — 70M+ customer records
    • Microsoft (2023) — Source code, employee data
    • Multiple retail/e-commerce breaches (2021–2023)
    • "ShinyHunters" brand active since 2020; associated with RaaS affiliate activity
  • Nation-State Nexus: No — Financially motivated cybercrime group; likely Eastern European/Russian-speaking based on forum language, infrastructure, and historical ShinyHunters attribution
  • MITRE ATT&CK Techniques:
    • T1110.004 — Credential Stuffing (primary initial access)
    • T1078.004 — Valid Accounts: Cloud Accounts (Snowflake user accounts)
    • T1556.003 — Modify Authentication Process: Multi-Factor Authentication (targeting accounts without MFA)
    • T1069.003 — Permission Groups Discovery: Cloud Groups (Snowflake roles/grants)
    • T1087.003 — Account Discovery: Email Accounts (Snowflake user enumeration)
    • T1082 — System Information Discovery (Snowflake version, edition, region)
    • T1007 — System Service Discovery (Snowflake services: stages, pipes, tasks)
    • T1602 — Data from Information Repositories (Snowflake tables/views)
    • T1530 — Data from Cloud Storage (export to S3/Azure/GCS)
    • T1567.002 — Exfiltration to Cloud Storage (actor-controlled buckets)
    • T1041 — Exfiltration Over C2 Channel (or direct cloud API)
    • T1657 — Financial Theft (ransom demands)
    • T1071.001 — Application Layer Protocol: Web Protocols (HTTPS to Snowflake API)
    • T1090.003 — Multi-hop Proxy (Tor for leak site, VPN for authentication)
  • Operational Security (OpSec): Moderate. Used VPN/proxy for authentication; Tor for leak site; automated tooling for enumeration/exfiltration; critical weakness — relied on static infostealer logs (credential reuse detection possible); no custom malware; extortion communications traceable to ShinyHunters infrastructure.

Technical Indicators

domains:
  - "shinyhunters[.]onion (leak site - Tor)"
  - "snowflakecomputing[.]com (legitimate - targeted)"
  - "*.snowflakecomputing[.]com (customer account URLs)"
ip_addresses:
  - "VPN/Proxy egress IPs (rotating - no static attribution)"
  - "Cloud provider egress (AWS/Azure/GCP) for exfiltration"
file_hashes:
  - type: "sha256"
    value: "N/A - No malware deployed"
    description: "Living-off-the-land: SnowSQL, Snowflake CLI, native SQL"
urls:
  - "https://www.mandiant.com/resources/blog/snowflake-data-theft-campaign"
  - "https://www.snowflake.com/en/engineering-blog/security-bulletin/"
  - "https://www.cisa.gov/news-events/alerts/2024/06/04/cisa-aware-campaign-targeting-snowflake"
c2_infrastructure:
  - "Tor hidden service for leak site (shinyhunters[.]onion)"
  - "VPN/Proxy infrastructure for authentication"
  - "Actor-controlled cloud storage (S3, Azure Blob, GCS) for exfiltration"
package_identifiers:
  - "Snowflake Cloud Data Platform"
  - "SnowSQL (CLI client)"
  - "Snowflake Python Connector / JDBC / ODBC"
file_paths:
  - "Snowflake internal stages (@~/staged_files)"
  - "External stages (S3/Azure/GCS URLs)"
  - "Information Schema tables (TABLES, COLUMNS, VIEWS, STAGES)"
network_and_c2:
  - "HTTPS to Snowflake REST API (port 443)"
  - "HTTPS to cloud storage APIs for exfiltration"
  - "Tor circuits for leak site management"
vulnerabilities:
  - "No CVE exploited — identity hygiene failure (missing MFA, network policies)"
detection_artifacts:
  - "Snowflake LOGIN_HISTORY: SUCCESS from new geo/IP, unusual client (SnowSQL, Python, JDBC)"
  - "Snowflake QUERY_HISTORY: SHOW DATABASES/TABLES/STAGES/USERS/ROLES in rapid succession"
  - "Snowflake QUERY_HISTORY: COPY INTO '<stage>' with large row counts"
  - "Snowflake QUERY_HISTORY: COPY INTO 's3://' OR 'azure://' OR 'gcs://' external locations"
  - "Snowflake ACCESS_HISTORY: Unusual data access patterns (full table scans of PII tables)"
  - "Infostealer log correlation: Employee credentials found in LummaC2/RedLine/Raccoon/Vidar/MetaStealer logs"
  - "MFA authentication gaps: LOGIN_HISTORY shows FIRST_AUTHENTICATION_FACTOR only (no SECOND_FACTOR)"
  - "Network policy gaps: No NETWORK_POLICY assigned to compromised users/accounts"

Law Enforcement Actions

  • FBI / CISA: Active investigation; CISA alert issued 3 June 2024. The specific FBI field offices said to be engaged are unverified.
  • International: Coordination with Europol, UK NCA, Canadian RCMP (Santander, Ticketmaster global footprint)
  • No public arrests/seizures specific to UNC5537 as of August 2026

Government Directives

  • CISA alert (Jun 3, 2024): Recommended customers follow Snowflake's guidance — enforce MFA, apply network policies, rotate credentials, and review access logs.
  • CISA Binding Operational Directive (BOD) Implications: Reinforces BOD 22-01 (MFA for internet-facing systems) extended to SaaS platforms
  • SEC Guidance: Multiple 8-K filings triggered scrutiny of cyber risk disclosure timeliness and materiality assessments
  • State Attorneys General: 20+ states opened investigations (CA, NY, TX, MA, IL) under breach notification laws; focus on consumer notification timeliness
  • Banking Regulators (OCC, FDIC, Federal Reserve): Santander breach triggered supervisory guidance on third-party cloud data warehouse risk
  • GDPR/International: EU DPC (Ireland) engaged for EU citizen data; UK ICO for UK residents; potential cross-border enforcement

Platform Response

  • Snowflake:
    • Jun 3, 2024: Security bulletin — mandatory MFA enforcement for all human users (phased rollout)
    • Jun 2024: Network policy enforcement recommendations; deprecated username/password auth for service accounts (OAuth/key-pair)
    • Jul 2024: Published "Snowflake Security Hardening Guide" — MFA, network policies, RBAC, monitoring, secrets management
    • Ongoing: Customer success engagement for security posture assessments; SIEM integration enhancements
  • Mandiant / Google Cloud: Forensic investigations for 50+ victims; threat intel sharing via M-Trends, Mandiant Advantage
  • CrowdStrike / SentinelOne / Microsoft Defender: Released detection rules for Snowflake credential stuffing, anomalous COPY INTO, infostealer credential correlation
  • Okta / Entra ID / Ping Identity: MFA enforcement campaigns for Snowflake SAML/OIDC integrations

Criminal Proceedings

  • None public. ShinyHunters/UNC5537 operators remain at large. Historical precedent: ShinyHunters members arrested in 2021 (French national, Moroccan national) — but core extortion infrastructure persists.

Impact Assessment

  • Organizations Directly Compromised: 165+ confirmed (Mandiant); likely higher (unreported/undetected)
  • Major Confirmed Victims:
    • Ticketmaster / Live Nation: 560M+ customer records (names, emails, phones, encrypted credit cards, event histories) — largest single victim
    • Santander Bank: 30M+ customer records (US, UK, Spain, Chile) — banking details, transaction histories
    • Advance Auto Parts: 2.3M+ records (customer PII, loyalty data, purchase histories)
    • LendingTree: Loan applicant data (SSN, income, credit scores, banking info)
    • Neiman Marcus: 640K+ customer records (loyalty, purchase, payment tokens)
    • Pure Storage: Employee/customer data, telemetry
    • Others: QuoteWizard, Highway Insurance, educational institutions, healthcare providers, telcos
  • Data Volume Exfiltrated: Estimated 10–50+ TB aggregate across victims
  • Data Types: Customer PII (names, emails, phones, addresses), SSN, DOB, driver's license, financial (credit cards, bank accounts, transaction histories), authentication tokens, proprietary business data, employee records
  • Financial Impact:
    • Victim Direct Costs: Forensic ($2M–$10M each), notification ($1M–$5M), credit monitoring, legal, regulatory fines — $500M–$1B+ aggregate
    • Ransom Payments: Unconfirmed; some victims reportedly negotiated/paid (per threat intel)
    • Stock Impact: Live Nation (-8% post-disclosure), Santander (-5%), others transient
    • Snowflake: Reputational; customer churn risk; engineering investment in mandatory MFA
  • Regulatory/Compliance:
    • Largest cloud data warehouse breach to date — precedent for SaaS shared responsibility model
    • SEC 8-K scrutiny: Materiality determination timelines, disclosure adequacy
    • State breach laws: All 50 states + territories triggered; varying notification timelines (30–90 days)
    • GDPR: Potential fines up to 4% global revenue for EU data exposure
  • Strategic/Systemic Impact:
    • Cloud Data Warehouse Trust Crisis: Snowflake, Databricks, BigQuery, Redshift customers re-evaluating security postures
    • Shared Responsibility Model Clarification: SaaS providers ≠ responsible for customer identity hygiene
    • Infostealer Ecosystem Impact: Highlighted long-tail risk of credential harvesting — years-old logs enabling current breaches
    • MFA Mandate Acceleration: Snowflake's mandatory MFA sets precedent for critical SaaS platforms

Lessons and Defensive Recommendations

For Security Teams / SOC Analysts

  1. Enforce MFA on Every SaaS Admin/Privileged Account — No Exceptions: Snowflake, Databricks, BigQuery, Redshift, Salesforce, GitHub, AWS/Azure/GCP consoles — phishing-resistant MFA (FIDO2, cert-based) for all human identities.

  2. Implement Network Allow-Lists (IP Allow-Lists) for Critical SaaS: Snowflake Network Policies, AWS/IAM condition keys, GitHub IP allow-lists — restrict to corporate egress, VPN, known CI/CD ranges.

  3. Correlate Infostealer Logs with SaaS Credentials: Subscribe to infostealer intelligence (Hudson Rock, SpyCloud, HaveIBeenPwned enterprise, Mandiant Advantage) — automated credential rotation when employee credentials appear in logs.

  4. Monitor Snowflake LOGIN_HISTORY & QUERY_HISTORY Continuously: Alert on:

    • Logins from new geo/IP/ASN/client
    • SHOW DATABASES/TABLES/STAGES/USERS bursts
    • COPY INTO to external locations (S3/Azure/GCS)
    • First-factor-only authentications (MFA gaps)
  5. Inventory and Govern Service Accounts: Eliminate long-lived username/password service accounts — migrate to OAuth, key-pair auth, externalbrowser, Okta/Entra ID SCIM with short-lived tokens.

For Developers and Architects

  1. Design for Credential Theft Resilience: Assume Snowflake credentials will be stolen. Use short-lived tokens, key-pair authentication, OAuth with PKCE, network policies as code (Terraform).

  2. Implement Data-Centric Controls:

    • Column-level masking/tokenization for PII/PCI/PHI (Snowflake Dynamic Data Masking, External Tokenization)
    • Row-level policies for multi-tenant isolation
    • Object-level grants — least privilege per role
  3. Automate Security Posture as Code:

    • Terraform for Snowflake: network_policy, mfa_required, password_policy, resource_monitors
    • CI/CD gates: fail build if MFA not enforced, network policy missing, public access enabled
  4. Enable Comprehensive Audit Logging: Snowflake ACCOUNT_USAGE schema (LOGIN_HISTORY, QUERY_HISTORY, ACCESS_HISTORY, GRANTS_TO_ROLES) → stream to SIEM (Splunk, Sentinel, Chronicle, Datadog).

For Platform / Cloud Providers (Snowflake, Databricks, AWS, Azure, GCP)

  1. Default-Deny for Critical Identity Actions:

    • MFA mandatory by default for all human accounts (opt-out only with justification + approval)
    • Network policies required for account creation (or strong default deny-all-except-corporate)
  2. Built-in Infostealer Credential Correlation: Partner with threat intel providers to automatically flag when customer credentials appear in infostealer logs — force password reset + MFA enrollment.

  3. Anomalous Data Export Detection: Native alerting on COPY INTO to external locations — volume, frequency, destination reputation, time-of-day baselines.

  4. Service Account Modernization:

    • Deprecate username/password for service accounts
    • Native support for Workload Identity Federation (AWS IAM Roles Anywhere, Azure Workload Identity, GCP WIF)
    • Short-lived token issuance via OAuth 2.0 / OIDC

For Leadership / CISO

  1. Treat Cloud Data Warehouses as Crown Jewels: Snowflake/Databricks/BigQuery often hold more sensitive data than on-prem databases — fund security accordingly (dedicated team, red teaming, continuous assessment).

  2. Own the Shared Responsibility Model: SaaS provider secures the platform; you secure identity, access, data, and monitoring. Board-level reporting on SaaS security posture.

  3. Mandate MFA + Network Policies as Non-Negotiable Standards: For any SaaS holding regulated data (PCI, PHI, PII, financial) — enforce via policy, validate via audit, report to board.

  4. Invest in Infostealer Intelligence: The "years-old credential" problem is solved by continuous credential exposure monitoring — not periodic rotation. Budget for enterprise threat intel feeds.

  5. Prepare for Double Extortion: Incident response playbooks must include: leak site monitoring, extortion communication protocols, regulator notification templates, customer communication templates, ransom decision framework (legal/insurance/law enforcement coordination).

  6. Third-Party Risk for SaaS: Extend vendor risk management to critical SaaS platforms — SOC 2 Type II + CSA STAR, penetration test scope (identity/access), contractual security SLAs (MFA enforcement timeline, breach notification SLA).

Sources

  1. Mandiant (Google Cloud). "UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion". Jun 10, 2024.

  2. Snowflake. "Security Bulletin: Unauthorized Access to Customer Instances". Jun 3, 2024.

  3. Snowflake. "Mandatory Multi-Factor Authentication for All Users". Jun 2024.

  4. CISA. "Snowflake Recommends Customers Take Steps to Prevent Unauthorized Access". 3 June 2024.

  5. Ticketmaster / Live Nation Entertainment. Form 8-K: Material Cybersecurity Incident. Filed May 31, 2024. SEC EDGAR.

  6. Santander Bank. "Santander Data Security Incident". May 30, 2024.

  7. Advance Auto Parts. Form 8-K: Cybersecurity Incident. Filed Jun 7, 2024. SEC EDGAR.

  8. LendingTree. Form 8-K: Data Security Incident. Filed Jun 2024. SEC EDGAR.

  9. Pure Storage. Form 8-K / Press Release. Jun 2024. SEC EDGAR.

  10. Neiman Marcus. Data Breach Notification. Jun 2024. State AG Filings.

  11. Hudson Rock. "Cavalier: Infostealer Logs Fueling Snowflake Attacks". Jun 2024.

  12. SpyCloud. "Snowflake Credential Exposure Analysis". Jun 2024.

  13. CrowdStrike. "2024 Global Threat Report: UNC5537 / ShinyHunters".

  14. MITRE ATT&CK. "Group G1037 (UNC5537)".

  15. ShinyHunters Leak Site (Tor). "Victim Listings." May–Jun 2024. (Monitored via threat intel platforms)

  16. Congressional Letters. House Energy & Commerce / Senate Commerce to Snowflake, Victims, Regulators. Jun–Jul 2024.

  17. State AG Press Releases. California, New York, Texas, Massachusetts, Illinois AGs. Jun–Aug 2024.

  18. Snowflake. "Security Hardening Guide". Jul 2024.

  19. Verizon DBIR 2024. "Credential Theft / Stuffing in Cloud SaaS".

  20. CISA. "Secure by Design Alert: SaaS Identity Security". 2024.


Corrections log — 2 September 2026: The paper cited CISA advisory "AA24-156A: Credential Stuffing Attacks Targeting Snowflake Customer Instances", dated 4 June 2024, in six places including the Sources list. No such advisory exists. CISA's response was an alert published on 3 June 2024, "Snowflake Recommends Customers Take Steps to Prevent Unauthorized Access", which points customers to Snowflake's own guidance rather than issuing federal direction. All six references have been corrected and the date fixed. A claim naming the specific FBI field offices engaged with victims could not be substantiated and is now marked unverified.

Original Incident Report →

Related Research

Between mid-2025 and August 2026, a cybercriminal collective operating primarily under the ShinyHunters brand—alongside associated activity clusters tracked as UNC6040, UNC6240, UNC6395, UNC6661, and...

Data BreachSupply Chain Attack

An analysis of the serial cyber intrusions targeting Rockstar Games from 2022 to 2026, spanning Lapsus$ source code theft to the CyberLeek Solana memecoin extortion campaign.

Data BreachExtortion & Blackmail

In July 2019, Capital One Financial Corporation formally disclosed one of the most significant data breaches in the history of the financial services sector. The security incident resulted in the...

Data Breach