Snowflake Cloud Accounts Felled by Rampant Credential Issues
ID: 1a4faee4-55ef-501b-ace2-616d6efe00e1
STIX ID: report--1a4faee4-55ef-501b-ace2-616d6efe00e1
Feed Name: Dark Reading
Mandiant (part of Google Cloud) investigated a campaign by UNC5537 that systematically accessed at least 165 Snowflake customer accounts using previously stolen credentials from information-stealer malware and other sources; the actor exfiltrated data and attempted extortion or sale of stolen data. Mandiant found no evidence of a Snowflake platform breach and attributes the incidents to customer-side failures such as lack of MFA, long-unused credentials, and absent network allow lists, and concludes that MFA would likely have prevented these compromises.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
