snowflake-unc5537-2024 · Disclosed 2024-06-10
Snowflake customers: stolen credentials used for data theft
Mandiant found stolen customer credentials used to access Snowflake environments. Missing MFA, unrotated credentials, and absent network restrictions enabled the investigated compromises.
Outcome: Confirmed breach
Entry path and evidence
- Reported fact
Investigated compromises were traced to stolen customer credentials; investigators found no evidence of a Snowflake platform breach.
[s1]Initial access - Reported fact
Affected investigated accounts lacked MFA, rotation of exposed credentials, and network allow-list controls.
[s1]Three primary factors
Timeline
Reported response
- Reported fact
Mandiant recommended MFA, credential management, trusted network restrictions, and abnormal-access detection.
[s1]Recommendations
Evidence relevant to prevention
Operational controls to inspect
These are factors in investigated compromises, not all Snowflake customers. Inspect customer-side settings and audit logs.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The cited primary sources do not establish AI involvement. This does not establish that AI was absent.
This campaign record does not establish each victim’s entry date or impact.
Sources
[s1] Mandiant · Primary source
UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion ↗Published 2024-06-10 · Reviewed 2026-10-02