{
  "id": "case-snowflake-credential-theft",
  "slug": "snowflake-customer-credential-theft",
  "title": "Snowflake Enterprise Credential Stuffing & Customer Cloud Thefts",
  "summary": "Financially motivated threat actor collective UNC5537 systematically infiltrated over 165 corporate customer tenants hosted on Snowflake (including Ticketmaster, Santander Bank, Advance Auto Parts, and LendingTree). Attackers leveraged infostealer malware logs dating back years against enterprise user accounts that lacked multi-factor authentication and IP network allowlists, exfiltrating billions of consumer records.",
  "case_number": "SEC-2024-8K-SNOW",
  "court": "U.S. Securities and Exchange Commission & FBI Cyber Division",
  "district": "N.D. Cal.",
  "country": "United States",
  "opened_at": "2024-05-23",
  "status": "alleged",
  "victim_sector": "Cloud Services, Entertainment, Financial Services, Retail",
  "victim_country": "United States",
  "loss_amount_usd": 500000000,
  "loss_amount_note": "Extensive corporate data breach notification costs, extortion demands, and regulatory inquiries across 165+ global enterprise organizations.",
  "first_seen_at": "2024-04-14T00:00:00Z",
  "last_updated_at": "2026-09-01T00:00:00Z",
  "actor_slug": "unc5537-scattered-spider",
  "defendant_slugs": [],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1078",
      "evidence_excerpt": "UNC5537 authenticated directly to enterprise customer Snowflake tenants using single-factor credentials previously captured by RedLine, Vidar, and Lumma infostealer Trojans on employee personal devices.",
      "evidence_locator": "Mandiant Threat Intelligence Special Report: UNC5537 Snowflake Campaign",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Mandiant UNC5537 Report",
      "source_url": "https://cloud.google.com/blog/topics/threat-intelligence",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1110",
      "evidence_excerpt": "Adversaries utilized custom automated tooling named FROSTBITE to systematically test credentials across hundreds of customer tenant URLs and generate presigned staging URLs.",
      "evidence_locator": "Snowflake & CrowdStrike Joint Forensic Investigation Statement",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Snowflake Security Advisory",
      "source_url": "https://www.snowflake.com",
      "technique_name": "Brute Force",
      "tactic": "Credential Access"
    },
    {
      "technique_id": "T1567",
      "evidence_excerpt": "Attackers generated time-limited pre-signed Amazon S3 storage URLs using tenant privileges, transferring hundreds of terabytes of relational data directly to adversary-controlled cloud infrastructure.",
      "evidence_locator": "CISA Advisory AA24-165A",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Alert AA24-165A",
      "source_url": "https://www.cisa.gov",
      "technique_name": "Exfiltration Over Web Service",
      "tactic": "Exfiltration"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2024-04-14",
      "description": "UNC5537 begins querying customer Snowflake tenants with infostealer-harvested credentials."
    },
    {
      "event_type": "breach_leak",
      "event_date": "2024-05-27",
      "description": "Threat actors post 560 million Ticketmaster customer records for sale on BreachForums for $500,000."
    },
    {
      "event_type": "advisory",
      "event_date": "2024-06-10",
      "description": "CISA, Mandiant, and Snowflake publish joint advisory warning of credential stuffing against accounts lacking MFA."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "UNC5537 threat actors leveraged historical infostealer malware logs (RedLine, Vidar, Lumma) capturing username and password combinations for contractor accounts. Crucially, the target Snowflake customer accounts lacked multi-factor authentication and network IP allowlisting.",
    "blast_radius": "Systematic theft of corporate data spanning 165+ enterprise organizations, including 560 million Ticketmaster customer records, Santander customer databases, and Advance Auto Parts records, leading to widespread consumer fraud and extortion demands on BreachForums.",
    "kill_chain": [
      {
        "phase": "Initial Credential Acquisition",
        "title": "Infostealer Log Ingestion",
        "description": "Adversaries acquired corporate employee credentials harvested by consumer infostealer Trojans that had infected non-managed personal devices between 2020 and 2024.",
        "technical_artifacts": [
          "RedLine stealer logs",
          "Lumma stealer archives",
          "Single-factor username/password pairs"
        ],
        "mitre_technique_id": "T1078"
      },
      {
        "phase": "Automated Reconnaissance",
        "title": "Custom FROSTBITE Enumeration Tooling",
        "description": "UNC5537 utilized custom scripts (dubbed FROSTBITE) to query Snowflake customer tenant URLs, validating credentials and assessing available data schemas without triggering brute-force lockouts.",
        "technical_artifacts": [
          "FROSTBITE Python scripts",
          "Snowflake API requests",
          "Customer tenant URL enumeration"
        ],
        "mitre_technique_id": "T1110"
      },
      {
        "phase": "Cloud Storage Exfiltration",
        "title": "Presigned Amazon S3 URL Staging",
        "description": "Using tenant query privileges, attackers generated short-lived pre-signed Amazon S3 storage URLs and dumped relational tables directly to adversary staging servers.",
        "technical_artifacts": [
          "COPY INTO s3:// stage commands",
          "Presigned AWS S3 URLs",
          "Relational database parquet dumps"
        ],
        "mitre_technique_id": "T1567"
      },
      {
        "phase": "Public Extortion",
        "title": "BreachForums Auction and Ransom Threats",
        "description": "Adversaries posted samples on darknet cybercrime forums, contacting corporate victims directly via email and Telegram demanding cryptocurrency ransoms between $300,000 and $5,000,000.",
        "technical_artifacts": [
          "BreachForums listings",
          "Telegram extortion channels",
          "Sample proof CSV leaks"
        ],
        "mitre_technique_id": "T1041"
      }
    ],
    "defensive_takeaways": [
      "Enforce mandatory multi-factor authentication (MFA) across all SaaS and cloud data warehouse user accounts.",
      "Deploy Network Policy Allowlisting to restrict Snowflake database access strictly to corporate VPN and office IP addresses.",
      "Prohibit session tokens or credentials from non-managed or personal endpoints from accessing enterprise cloud resources.",
      "Audit third-party contractor accounts regularly and terminate inactive access credentials immediately upon contract conclusion."
    ]
  }
}