← Incident database

snowflake-unc5537-2024 · Disclosed 2024-06-10

Snowflake customers: stolen credentials used for data theft

Mandiant found stolen customer credentials used to access Snowflake environments. Missing MFA, unrotated credentials, and absent network restrictions enabled the investigated compromises.

CredentialsEndpoint / sessionConfiguration / exposure

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    Investigated compromises were traced to stolen customer credentials; investigators found no evidence of a Snowflake platform breach.

    [s1]Initial access
  • Reported fact

    Affected investigated accounts lacked MFA, rotation of exposed credentials, and network allow-list controls.

    [s1]Three primary factors

Timeline

  1. Mandiant published its findings. [s1]

  2. Threat hunting guide added. [s1]

Reported response

  • Reported fact

    Mandiant recommended MFA, credential management, trusted network restrictions, and abnormal-access detection.

    [s1]Recommendations

Evidence relevant to prevention

Operational controls to inspect

These are factors in investigated compromises, not all Snowflake customers. Inspect customer-side settings and audit logs.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The cited primary sources do not establish AI involvement. This does not establish that AI was absent.

This campaign record does not establish each victim’s entry date or impact.

Sources

  1. [s1] Mandiant · Primary source

    UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion ↗

    Published 2024-06-10 · Reviewed 2026-10-02