Snowflake customers not using MFA are not unique – over 165 of them have been compromised
ID: 6764cb26-73c3-5215-a4e2-f8fe6a3d986d
STIX ID: report--6764cb26-73c3-5215-a4e2-f8fe6a3d986d
Feed Name: The Register (Security)
Mandiant attributes a campaign (UNC5537) to a financially motivated crime crew that exfiltrated data from roughly 165 Snowflake customer accounts by using valid credentials stolen via infostealer malware (e.g., VIDAR, REDLINE, RISEPRO, RACCOON, LUMMA, METASTEALER). The attackers used a reconnaissance/exfiltration utility tracked as Frostbite (aka "rapeflake") and tools like DBeaver, exploited contractor/shared devices, and targeted accounts lacking MFA and network allow-lists; stolen data began appearing for sale by late May.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
