Snowflake—Stolen Snowflake customer credentials enabled mass breach chain affecting Ticketmaster, Santander, AT&T and others
Beginning in April 2024, threat actor UNC5537 used credentials stolen via prior infostealer malware to access approximately 165 Snowflake customer tenants that lacked multi-factor authentication, exfiltrating hundreds of millions of records belonging to downstream customers including Ticketmaster (560M records), Santander, AT&T (~110M wireless customers), Advance Auto Parts, LendingTree, Neiman Marcus, and others. Snowflake initially attributed responsibility to customer credential management while critics noted Snowflake's product defaults did not require MFA. Snowflake later enabled MFA-by-default policies for new accounts.
Scoring Impact
| Topic | Direction | Relevance | Contribution |
|---|---|---|---|
| Corporate Transparency | -against | secondary | -0.50 |
| Data Security | -against | primary | -1.00 |
| Infrastructure Accountability | -against | primary | -1.00 |
| Overall incident score = | -0.492 | ||
Score = avg(topic contributions) × significance (critical ×2) × confidence (0.59)× agency (negligent ×0.5)
Evidence (1 signal)
Mandiant attributed 165 Snowflake customer breaches to UNC5537 using stolen credentials
Mandiant's June 10, 2024 threat intelligence publication attributed approximately 165 Snowflake customer breaches to threat actor UNC5537 using infostealer-derived credentials against accounts that did not require multi-factor authentication. Downstream victims included Ticketmaster, Santander, AT&T, Advance Auto Parts and Neiman Marcus.