In the spring of 2024, a financially motivated group that Mandiant tracks as UNC5537 logged into the Snowflake accounts of around 165 organisations and walked out with their data. Nothing in Snowflake's platform was exploited. The attackers simply used usernames and passwords that infostealer malware had harvested from infected computers, some of them stolen as far back as November 2020. The accounts had no multi-factor authentication, the credentials had not been rotated, and nothing restricted where logins could come from. Victims included AT&T, whose call and text records for nearly all of its wireless customers were taken, Ticketmaster, Santander and Advance Auto Parts. The group then tried to extort victims and sell the data. One of the alleged hackers, Connor Moucka, pleaded guilty in the United States in August 2026, and the case shows what happens when static credentials to a cloud data platform are left unmanaged.
Key takeaways
- Snowflake says it saw increased threat activity from mid-April 2024 and became aware of unauthorised access on 23 May 2024, a day after Mandiant alerted it to a broader campaign.
- Mandiant says at least 79.7% of the accounts used had prior credential exposure in infostealer logs, and that success came down to three gaps: no MFA, credentials not rotated for years, and no network allow lists.
- Mandiant and Snowflake notified about 165 potentially exposed organisations. Snowflake and Mandiant found no vulnerability or breach of Snowflake's own platform.
- US prosecutors say the scheme raised more than $2.5 million in ransom payments and affected about 100 million people. The Justice Department announced Moucka's guilty plea on 5 August 2026, with sentencing set for 27 October 2026.
- Lesson: any long-lived password to a data platform, whether it belongs to an employee, a contractor or a service account, needs strong authentication, rotation, network restrictions and an owner.
At a glance
| Organisation | Snowflake customers, including AT&T, Ticketmaster (Live Nation), Santander, Advance Auto Parts and others; about 165 organisations notified |
|---|---|
| When | Activity from mid-April 2024 according to Snowflake, with AT&T data taken from 14 April (the US Justice Department describes the scheme as running from February to October 2024); disclosed from May 2024 |
| Attacker | UNC5537, a financially motivated group Mandiant assesses has members in North America and a collaborator in Turkey; Connor Moucka and John Binns were indicted in the US |
| Entry point | Direct logins to customer Snowflake instances with credentials stolen by infostealer malware |
| Identities abused | Snowflake user credentials protected only by a password, including credentials taken from contractors' devices and valid for years; one former Snowflake employee's demo account |
| Impact | Bulk data theft, extortion and sale of data; more than $2.5 million in ransom paid and about 100 million people affected, according to the Justice Department |
| Category | Human identity and NHI (static, unrotated credentials to a cloud data platform) |
What happened
Mandiant says that in April 2024 it received threat intelligence on database records "subsequently determined to have originated from a victim's Snowflake instance." On 22 May 2024, with more evidence of a broader campaign, it notified Snowflake and began contacting potential victims. Snowflake says it "became aware of potentially unauthorized access to certain customer accounts on May 23, 2024" and that it had seen "increased threat activity beginning mid-April 2024". It published detection and hardening guidance on 30 May, and on 10 June Mandiant released its full analysis of UNC5537.
The central finding from both companies was that nothing had been hacked inside Snowflake itself. Snowflake says it had "not identified evidence suggesting this activity was caused by a vulnerability, misconfiguration, or breach of Snowflake's platform", describing it instead as "a targeted campaign directed at users with single-factor authentication". The one Snowflake-owned account involved was a demo account belonging to a former employee, which Snowflake says "did not contain sensitive data."
The credentials came from infostealer malware. Mandiant says the credentials were "primarily obtained from multiple infostealer malware campaigns that infected non-Snowflake owned systems", that "at least 79.7% of the accounts leveraged by the threat actor in this campaign had prior credential exposure", and names VIDAR, RISEPRO, REDLINE, RACOON STEALER, LUMMA and METASTEALER among the families involved. The earliest infection linked to a credential used in the campaign dated back to November 2020. Mandiant also highlights contractors, who may use personal or unmonitored laptops to reach several clients' systems: "a single contractor's laptop can facilitate threat actor access across multiple organizations."
Once inside, the attackers worked through Snowflake's own interfaces. Mandiant describes logins through the Snowsight web interface and the SnowSQL command line tool, a reconnaissance utility it tracks as FROSTBITE, and the database tool DBeaver Ultimate. Standard SQL commands listed tables, created temporary stages and copied whole tables out. Connections came mostly from Mullvad and Private Internet Access VPN addresses, and Mandiant observed virtual private servers from a Moldovan provider used during exfiltration, with stolen data stored on several VPS providers and the MEGA cloud storage service.
Victims began to surface. Santander said on 14 May 2024 that there had been "unauthorized access to a Santander database hosted by a third-party provider". On 31 May, Live Nation told the US Securities and Exchange Commission it had found "unauthorized activity within a third-party cloud database environment containing Company data" on 20 May, after a criminal offered its user data for sale. TechCrunch reported that a Ticketmaster spokesperson identified that provider as Snowflake, and that a BreachForums administrator claimed to be selling data on about 560 million customers.
On 12 July 2024, AT&T disclosed that threat actors had accessed "an AT&T workspace on a third-party cloud platform" and, between 14 and 25 April 2024, exfiltrated files containing "records of calls and texts of nearly all of AT&T's wireless customers". The US Justice Department had twice agreed that disclosure could be delayed.
Timeline
| Date | Event |
|---|---|
| November 2020 onwards | Earliest infostealer infection Mandiant linked to a credential later used in the campaign. |
| 14 to 25 April 2024 | Files exfiltrated from AT&T's workspace; Snowflake later says it saw increased threat activity from mid-April. |
| 14 May 2024 | Santander reports unauthorised access to a database hosted by a third-party provider. |
| 22 to 23 May 2024 | Mandiant notifies Snowflake of a broader campaign; Snowflake becomes aware of unauthorised access to customer accounts. |
| 30 to 31 May 2024 | Snowflake publishes guidance; Live Nation files an 8-K on the Ticketmaster data theft. |
| 10 June 2024 | Mandiant publishes its UNC5537 analysis; about 165 organisations notified. |
| 12 July 2024 | AT&T discloses theft of call and text records for nearly all of its wireless customers. |
| Late October to November 2024 | Moucka arrested in Canada; indictment against Moucka and Binns unsealed in the US. |
| July 2025 | Moucka extradited from Canada to the United States. |
| 5 August 2026 | Justice Department announces Moucka's guilty plea to four counts; sentencing set for 27 October 2026. |
How it happened: the identity attack path
- Credentials harvested far from the target. Infostealer malware on employee and contractor computers captured Snowflake usernames and passwords, sometimes years before the attack. Mandiant says the infected systems were not owned by Snowflake.
- Stolen logs turned into a target list. According to Mandiant, UNC5537 took Snowflake credentials from the output of multiple infostealer campaigns, and at least 79.7% of the accounts it used had prior exposure.
- Password was the only check. Mandiant says the affected accounts "were not configured with multi-factor authentication enabled, meaning successful authentication only required a valid username and password."
- Old credentials still worked. Credentials "were still valid, in some cases years after they were stolen, and had not been rotated or updated." No expiry, rotation or review had retired them.
- Logins accepted from anywhere. The affected instances had no network allow lists, so logins from commercial VPN addresses were accepted like any other.
- Legitimate tools used for bulk export. The attackers used Snowsight, SnowSQL and ordinary SQL to enumerate and copy tables, making the activity look like normal database use.
- Extortion and sale. Mandiant says UNC5537 advertised data on criminal forums and tried to extort many victims; prosecutors say at least some paid.
Impact
- Organisations: Mandiant and Snowflake notified about 165 potentially exposed organisations. The Justice Department says over 165 customers were hacked, while its announcement quotes an official saying Moucka "hacked over 150 companies and organizations".
- People: the Justice Department says the scheme affected about 100 million individuals. AT&T says the stolen records covered nearly all of its wireless customers; BleepingComputer reported about 50 billion call and text records relating to 109 million customers.
- Data: AT&T says its records, covering roughly May to October 2022 and 2 January 2023, identify the numbers its customers interacted with, counts of those interactions and aggregate call duration, with cell site identifiers for a subset, but not the content of calls or texts. Santander said customer data in Chile, Spain and Uruguay and data on all current and some former employees was affected, but no transactional data or banking credentials.
- Money: prosecutors say victims paid more than $2.5 million in ransom, that Moucka personally obtained at least $495,000, and that victim companies lost more than $9.5 million.
What this means for identity security
The Snowflake campaign is a credential hygiene failure, not a platform breach. Each stolen login was a single secret, a password, with nothing behind it. Mandiant's three conditions for success (no MFA, no rotation, no network restriction) are the same controls identity teams already know they need. The damage came from scale: credentials sat in infostealer logs for years, and behind them were whole warehouses of customer records.
The entry point was human credentials stolen from endpoints, including contractor laptops that the victims did not manage. That is why this page sits under identity security. But the pattern is the same one seen with non-human identities: a long-lived static credential, no clear owner, no expiry and no check on where it is used from. Public sources do not say how many of the accounts abused were service or integration accounts rather than people, but data platforms carry many such accounts, and they are exactly the kind that rarely get MFA or rotation.
Snowflake's response points in that direction. In December 2024 it announced a phased block on single-factor password sign-ins that, according to Cybersecurity Dive, covers "all human users that use interactive login and service users that use programmatic access", while key pair authentication, SAML and OAuth are not affected. For machine access, the fix is not MFA but a different kind of credential that cannot be lifted from a browser store in the same way.
Recommendations
- Enforce MFA for every human login to data platforms, including contractors, and prefer single sign-on so that access follows the corporate identity provider. The Workforce Identity Security Guide covers the options.
- Take passwords away from service accounts. Move programmatic access to key pair, OAuth or workload identity federation, and record an owner for every service user. See the Service Account Security Guide and NHI Authentication Guide.
- Rotate and expire credentials. A credential valid since 2020 should not exist. Set maximum ages and disable accounts that have not been used, following Challenges of Rotating NHIs.
- Restrict where logins can come from. Apply network policies so that data platform accounts, especially service users, only accept connections from known ranges.
- Watch for infostealer exposure. Monitor for company credentials in stealer logs and reset them quickly, and extend endpoint requirements to contractors who hold access.
- Detect bulk export. Alert on logins from commercial VPN addresses, new client tools and large COPY or GET operations to temporary stages, as covered in the ITDR Guide.
Frequently asked questions
What happened in the Snowflake breach?
In 2024, a group Mandiant tracks as UNC5537 used usernames and passwords stolen by infostealer malware to log into Snowflake customer accounts that had no MFA. It copied data from about 165 organisations, including AT&T, Ticketmaster, Santander and Advance Auto Parts, then tried to extort them and sell the data.
Was Snowflake itself hacked?
No. Snowflake says it found no evidence of a vulnerability, misconfiguration or breach of its platform, and Mandiant's investigation reached the same conclusion. The only Snowflake-owned account involved was a former employee's demo account, which Snowflake says held no sensitive data.
Who was charged over the Snowflake attacks?
US prosecutors charged Connor Moucka and John Binns. Moucka was arrested in Canada in late 2024, extradited in July 2025 and pleaded guilty to four counts, including computer fraud, wire fraud and aggravated identity theft. The Justice Department announced the plea on 5 August 2026 and set sentencing for 27 October 2026.
Related NHI Mgmt Group resources
ShinyHunters Salesforce data theft campaign 2025 · 23andMe credential stuffing breach · Change Healthcare breach 2024 · Human vs Non-Human Identity · NHI breaches
How NHI Mgmt Group can help
The Snowflake campaign shows how static passwords to data platforms, whether held by people, contractors or service accounts, become skeleton keys once they leak. Our NHI Foundation Level Training Course shows teams how to find those credentials, give them owners and replace them with stronger, short-lived alternatives.
References
- Google Cloud (Mandiant): UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion (10 June 2024)
- Snowflake (Brad Jones, CISO): Detecting and Preventing Unauthorized User Access (31 May 2024, updated 10 June 2024)
- AT&T: Form 8-K, Item 1.05 Material Cybersecurity Incidents (12 July 2024)
- TechCrunch: Live Nation confirms Ticketmaster was hacked, says personal information stolen in data breach (31 May 2024)
- Banco Santander: Statement (14 May 2024)
- Cybersecurity Dive: Snowflake to phase out single-factor authentication by late 2025 (10 December 2024)
- BleepingComputer: US indicts Snowflake hackers who extorted $2.5 million from 3 victims (13 November 2024)
- US Department of Justice: Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions (5 August 2026)