logo

Snowflake compromised creds abuse campaign (Incident)

ID: 2a690f5e-93bb-5578-abd9-e157f845aec0

STIX ID: report--2a690f5e-93bb-5578-abd9-e157f845aec0

Feed Name: Wiz Cloud Threat Landscape

Threat Score
75/100

Date Published: 2024-05-29

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Researchers reported a campaign by UNC5537 that used stolen credentials and a toolkit called "rapeflake" to access Snowflake customer accounts without MFA, with Snowflake confirming illicit access spanning back to mid‑April 2024; the activity appears to involve credential abuse (not a Snowflake product vulnerability), potential data theft/extortion, and may be linked to infostealer infections and other breaches, though some third‑party attribution is unverified.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.