logo

Pure Storage confirms data breach after Snowflake account hack

ID: 22855b79-d7c1-5d71-b9a3-e91db0445c47

STIX ID: report--22855b79-d7c1-5d71-b9a3-e91db0445c47

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-06-11

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Pure Storage confirmed a breach of a Snowflake analytics workspace that exposed telemetry data and customer identifiers; Snowflake, Mandiant, and CrowdStrike link a wider campaign (tracked as UNC5537) to the use of credentials harvested by multiple infostealer malware families (Vidar, RedLine, Racoon, RisePro, Lumm, Metastealer). The campaign exploits accounts without MFA or network allowlists, has led to hundreds of compromised Snowflake credentials and notifications to ~165 organizations, and has resulted in large-scale data exfiltration and extortion, including multiple high-profile breaches and datasets being sold.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.