As many as 165 companies ‘potentially exposed’ in Snowflake-related attacks, Mandiant says
ID: 44109f25-f07a-57f3-b57e-2e3a3b4db0ae
STIX ID: report--44109f25-f07a-57f3-b57e-2e3a3b4db0ae
Feed Name: CyberScoop
Threat Score
Mandiant reports that a financially motivated group tracked as UNC5537 used credentials stolen by infostealer malware to access Snowflake customer instances that lacked multi-factor authentication or location restrictions, resulting in data exfiltration affecting dozens to potentially hundreds of organizations — including Ticketmaster and Santander — and potentially hundreds of millions of individuals; stolen datasets have appeared for sale on cybercrime forums.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
