logo

Snowflake Cloud Accounts Felled by Rampant Credential Issues

ID: 1a4faee4-55ef-501b-ace2-616d6efe00e1

STIX ID: report--1a4faee4-55ef-501b-ace2-616d6efe00e1

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-06-10

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Mandiant (part of Google Cloud) investigated a campaign by UNC5537 that systematically accessed at least 165 Snowflake customer accounts using previously stolen credentials from information-stealer malware and other sources; the actor exfiltrated data and attempted extortion or sale of stolen data. Mandiant found no evidence of a Snowflake platform breach and attributes the incidents to customer-side failures such as lack of MFA, long-unused credentials, and absent network allow lists, and concludes that MFA would likely have prevented these compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.