Snowflake Breach Exposes 165 Customers' Data in Ongoing Extortion Campaign
ID: 70bf552b-7dd5-5691-bda3-9d728965dab3
STIX ID: report--70bf552b-7dd5-5691-bda3-9d728965dab3
Feed Name: The Hacker News
Threat Score
Mandiant and Snowflake are investigating a financially motivated campaign (UNC5537) that has used stolen credentials—often acquired via information-stealer malware—to access customer Snowflake instances, run reconnaissance (via a utility dubbed FROSTBITE and legitimate tools like DBeaver), exfiltrate data, and attempt extortion; up to 165 customers have been potentially exposed and the activity highlights widespread credential exposure and lack of MFA/network controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
