Between April and June 2024 an actor tracked as UNC5537 exfiltrated data from around 165 organisations that used Snowflake, the cloud data platform. Victims later linked to the campaign include Ticketmaster, Santander, AT&T, Advance Auto Parts, Pure Storage and Neiman Marcus.
The route was valid credentials rather than a flaw in Snowflake. Reporting attributes the credentials to infostealer malware on machines with access to customer environments, including demo accounts, and identifies the absence of mandatory multi-factor authentication on customer accounts as the condition that made the logins work. Consolidated litigation later described personal information of more than 500 million consumers and employees.
The Platform Did Nothing Wrong And That Is The Problem
Snowflake was not compromised. Each affected customer was, individually, through its own account, using its own credentials, exactly as the product was designed to allow.
Where a platform makes a second factor optional, the customers who skip it are the population an attacker works through. A shared-responsibility model is accurate as a description of accountability and useless as a description of outcome: 165 separate failures with one shape reads, from the outside, as one incident.
Infostealer Output Is The Supply
The credentials came from ordinary malware on ordinary machines, harvested and sold in bulk long before anyone worked out what they unlocked.
Our own audit found infostealer output to be the single most common named origin across the file set. This campaign is what happens at the far end of that pipeline, when someone buys a batch and checks which of the logins reach a data warehouse.
One Credential, An Entire Warehouse
A data platform account is not access to one system. It is access to whatever the organisation loaded into it, which is generally everything worth analysing.
That is why individual victim counts in this campaign run into the hundreds of millions from a small number of logins. The credential was ordinary; what sat behind it was not.
Compiled from vendor research, public reporting and litigation filings, listed below. The 165 figure and the UNC5537 designation are the researchers’ own. The 500 million figure comes from consolidated litigation and is an allegation, not a finding. Corrections: corrections@forensicpost.com.
- Snowflake Data Breach: What Happened, Impact, and LessonsHuntress
- Snowflake, Data Security Breach LitigationUS District Court, District of Montana