logo

Snowflake Account Attacks Driven by Exposed Legitimate Credentials

ID: 564579c4-44c0-52af-9f2c-50b64d160fef

STIX ID: report--564579c4-44c0-52af-9f2c-50b64d160fef

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2024-07-17

Date Updated: 2026-04-21

Author: Stephanie Schneider

...
...

A financially motivated actor (UNC5537) exploited exposed and stolen credentials—often obtained via infostealer malware or dark‑web sales—to access Snowflake customer accounts that lacked MFA and network allow lists, leading to data exfiltration from roughly 165 companies and the sale/extortion of that data; the report emphasizes enabling MFA, rotating credentials, and monitoring for targeted campaigns as primary mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.