Snowflake Account Attacks Driven by Exposed Legitimate Credentials
ID: 564579c4-44c0-52af-9f2c-50b64d160fef
STIX ID: report--564579c4-44c0-52af-9f2c-50b64d160fef
Feed Name: Dark Reading
Threat Score
A financially motivated actor (UNC5537) exploited exposed and stolen credentials—often obtained via infostealer malware or dark‑web sales—to access Snowflake customer accounts that lacked MFA and network allow lists, leading to data exfiltration from roughly 165 companies and the sale/extortion of that data; the report emphasizes enabling MFA, rotating credentials, and monitoring for targeted campaigns as primary mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
