Cybersecurity Incident AnalysisAug 6, 20266 min read← All posts
Snowflake Data Breach Analysis: Credential-Based Cloud Intrusion Exposes Over 100 Million Records (2024–2026)
Executive Summary
On August 6, 2026, it was publicly confirmed that the individual later identified as the primary attacker pleaded guilty in U.S. federal court to charges related to the 2024 breaches of Snowflake customer accounts. The breaches affected at least 165 organizations and exposed records belonging to at least 100 million people, with some estimates suggesting the number of impacted individuals is even higher. The attacker, tracked as part of the UNC5537 group, leveraged credentials harvested by infostealer malware from as early as 2020. These credentials were never rotated and were used to access Snowflake customer accounts that did not have multi-factor authentication (MFA) enabled. There was no exploitation of a vulnerability in the Snowflake platform itself; access was achieved solely through valid, stolen credentials and the absence of MFA. The breach resulted in significant financial and reputational damage to affected organizations, including major enterprises in telecommunications, entertainment, finance, and retail. The incident underscores the critical importance of credential hygiene and MFA enforcement in cloud environments.
Technical Information
The Snowflake data breach represents one of the largest credential-based cloud intrusions on record. The attack did not exploit any vulnerability in the Snowflake platform. Instead, the threat actor, identified as UNC5537 and led by an individual known as “Judische”, systematically acquired credentials stolen by infostealer malware such as Vidar, RISEPRO, and LummaC2. These malware families are designed to harvest credentials from infected endpoints, including browser-saved passwords and application credentials.
The initial access vector was the use of valid, but previously compromised, credentials to log in to Snowflake customer tenants that did not have MFA enforced. Investigations by Mandiant and CrowdStrike confirmed that the campaign was a large-scale credential-based account takeover operation targeting enterprise cloud data environments. After gaining entry, the attackers moved laterally within customer tenants and conducted significant data exfiltration. No backdoors or exploits were used within Snowflake‘s shared infrastructure; access was entirely through legitimate authentication using compromised credentials.
The attackers used a combination of custom and commercial tools, including a reconnaissance tool known as rapeflake (tracked by Mandiant as FROSTBITE) to enumerate users, roles, and session data within victim instances. They also used the commercial database tool DBeaver_DBeaverUltimate and other client application strings such as Go 1.1.5, JDBC 3.13.30, JDBC 3.15.0, PythonConnector 2.7.6, and SnowSQL 1.2.32. For operational security and data exfiltration, the attackers relied on VPN services such as Mullvad and Private Internet Access (PIA), VPS infrastructure from ALEXHOST SRL (AS200019), and cloud storage providers like MEGA.
The campaign targeted a broad range of sectors, including telecommunications (e.g., AT&T), entertainment (Ticketmaster/Live Nation), financial services (Santander Bank), retail (Advance Auto Parts, Neiman Marcus), technology (Pure Storage), and government entities. The selection of victims appears to have been opportunistic, based on the availability of valid credentials rather than sector-specific targeting.
Forensic investigations confirmed that the root cause was credential theftcombined with the absence of MFA enforcement on customer Snowflake accounts. Audits also revealed that inadequate logging practices within some affected tenants slowed initial detection and incident response
The breach resulted in the exposure of a wide range of sensitive data, including personally identifiable information (PII) such as full names, addresses, phone numbers, financial records, call and text metadata (in the case of AT&T), and partial payment card data (in the case of Ticketmaster). Some files were encrypted, but in affected tenants, attackers had full read access consistent with the privileges of the compromised account credentials used to authenticate.
The incident prompted Snowflake to accelerate its plans to enforce MFA by default for all human users on accounts created since October 2024, with a phased rollout to block password-only sign-ins for every remaining human and service user by October 2026. However, reader and trial accounts remain exempt from this requirement.
Affected Versions & Timeline
The breaches affected Snowflake customer accounts that did not have MFA enabled and where credentials had been previously compromised by infostealer malware. The timeline of the attack is as follows: infostealer malware infections harvesting Snowflake credentials date back to at least November 2020. The active exfiltration campaign against specific named victims began in April 2024 and continued through June 2024. Public disclosure of the campaign occurred in late May 2024, following coordinated investigations by Snowflake, Mandiant, and CrowdStrike. The primary individual responsible was arrested in October 2024, and a federal indictment was unsealed in November 2024. The final phase of mandatory MFA enforcement by Snowflake is scheduled to be completed between August and October 2026.
Threat Activity
The threat actor UNC5537 is a financially motivated group specializing in large-scale credential-based cloud intrusions. The group systematically acquires infostealer logs and targets cloud data repositories. The campaign against Snowflake customers is notable for its scale and impact, affecting at least 165 organizations and exposing records belonging to at least 100 million people. The attackers used stolen credentials to access customer tenants, moved laterally within those environments, and exfiltrated large volumes of sensitive data. The use of VPNs, VPS infrastructure, and cloud storage providers helped the attackers evade detection and complicate attribution.
The campaign did not involve the use of sophisticated exploits or novel attack techniques. Instead, it relied on the widespread availability of stolen credentials and the lack of MFA enforcement on customer accounts. The attackers also engaged in re-extortion, threatening further disclosure of stolen data to pressure victims into paying additional ransoms.
Mitigation & Workarounds
The following mitigation steps are prioritized by severity:
Critical: Enforce multi-factor authentication (MFA) on all Snowflake accounts, including both human and service users. Audit all existing accounts to ensure MFA is enabled and functioning correctly.
High: Conduct a comprehensive review of credential hygiene across all cloud and SaaS environments. Identify and rotate any credentials that may have been exposed to infostealer malware, especially those that have not been changed since 2020.
High: Implement robust endpoint protection and infostealer malware detection capabilities on all devices used to access Snowflake and other cloud services.
Medium: Review and enhance logging and monitoring practices within Snowflake tenants to ensure timely detection of unauthorized access and anomalous activity. Monitor for suspicious client application strings and unusual access patterns.
Medium: Educate employees about the risks of infostealer malware and the importance of credential hygiene, including the dangers of saving passwords in browsers or unsecured applications.
Low: Regularly review and update network allow lists and access controls for Snowflake tenants to limit exposure to only trusted networks and devices.
Indicators of Compromise
The following caveat applies: Indicators of compromise are point-in-time and should be validated before enforcement. No public indicators of compromise (such as IP addresses, domains, or hashes) were available at the time of writing.
References
About Rescana
Rescana provides a third-party risk management (TPRM) platform that enables organizations to continuously monitor and assess the security posture of their vendors and cloud service providers. Our platform supports credential hygiene reviews, detection of infostealer malware exposure, and enforcement of authentication best practices across cloud environments.
We are happy to answer questions at info@rescana.com.
Aug 6, 2026
Claude Mythos 5 AI Exposes Advanced Supply Chain Risks: Autonomous Backdoor Attempt in Open-
Aug 6, 2026
Unitel Angola Cyberattack Disrupts Telecom Services Nationwide Hours Before Record IPO
Aug 6, 2026
Active Exploitation Alert: Critical Gitea CVE-2026-59774 Lets Unauthenticated Attackers Read Server Files and Gain RCE
