All vulnerabilities
CRITICALOpSec

OPSEC-SNOWFLAKE-2024

Cloud · Snowflake (customer tenants)

Summary

Between roughly April and June 2024, the threat group UNC5537 conducted mass data theft from about 165 Snowflake customer tenants. The attackers did not exploit any flaw in Snowflake itself; they logged in with valid usernames and passwords harvested by infostealer malware from employee and contractor machines and sold on criminal markets, some credentials years old. The targeted accounts had no MFA enabled and no network allow-listing, so stolen single-factor credentials granted direct access. Victims included Ticketmaster/Live Nation (about 560 million customers), Santander (about 30 million customers), and AT&T (call and text metadata for roughly 110 million customers, with AT&T reportedly paying about $370,000).

How to avoid it in your code

  • Enforce MFA on every cloud data-platform account, especially admin and service accounts; never leave it optional.
  • Restrict warehouse access with network policies/allowlists or private connectivity to known sources.
  • Replace static user passwords with SSO and key-pair auth; rotate credentials immediately on exposure.
  • Detect infostealer-harvested credentials and alert on logins from new locations, clients, or IPs.
  • Apply least privilege to warehouse roles and alert on large or unusual data exports.

References

Related vulnerabilities

All OpSec →