logo

Snowflake customers hit in data theft attacks after SaaS integrator breach

ID: e7fdfe85-decc-5ce3-9538-0566efc342d5

STIX ID: report--e7fdfe85-decc-5ce3-9538-0566efc342d5

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-04-07

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

A breach at a SaaS integration provider (reported as Anodot) led to theft of authentication tokens that attackers used to access and steal data from multiple companies' cloud accounts—most significantly Snowflake—after which the ShinyHunters extortion group began demanding ransoms; Snowflake detected unusual activity, locked affected accounts, and notified customers, and attempts to access Salesforce were reportedly blocked.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.