logo

Snowflake customers not using MFA are not unique – over 165 of them have been compromised

ID: 6764cb26-73c3-5215-a4e2-f8fe6a3d986d

STIX ID: report--6764cb26-73c3-5215-a4e2-f8fe6a3d986d

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-06-11

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Mandiant attributes a campaign (UNC5537) to a financially motivated crime crew that exfiltrated data from roughly 165 Snowflake customer accounts by using valid credentials stolen via infostealer malware (e.g., VIDAR, REDLINE, RISEPRO, RACCOON, LUMMA, METASTEALER). The attackers used a reconnaissance/exfiltration utility tracked as Frostbite (aka "rapeflake") and tools like DBeaver, exploited contractor/shared devices, and targeted accounts lacking MFA and network allow-lists; stolen data began appearing for sale by late May.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.