top of page

Snowflake Breaches 2024: Credential Theft and Shared Responsibility

Updated: Aug 31

No one hacked Snowflake. Attackers took passwords harvested by commodity malware, some stolen back in 2020 and never changed, and logged into customer data warehouses that asked for nothing more. Roughly 165 organizations, 560 million Ticketmaster records, nearly every AT&T customer's call history, and a guilty plea two years later.


Case type: Credential abuse / cloud data theft / extortion     

Identified: May 23, 2024   Disclosed: May 31, 2024

Attribution: UNC5537 / ShinyHunters




In the spring of 2024, some of the largest companies in America began learning, mostly from criminals, that their cloud data warehouses had been emptied. Ticketmaster's parent disclosed a theft eventually advertised at 560 million records. AT&T lost the call and text history of nearly every cellular customer. In all, roughly 165 organizations were hit in one coordinated campaign, and the entire thing ran on stolen passwords typed into login pages.


The Snowflake campaign is this series' enterprise-scale echo of 23andMe. There, consumers reused passwords and an organization failed to require more; here, enterprises left their most concentrated data assets behind single-factor logins, using credentials that commodity malware had harvested from employee and contractor devices years earlier and that nobody had ever rotated. No exploit anywhere. No breach of the platform itself. Mandiant, brought in to investigate, wrote the epitaph in its own report: the campaign was “not the result of any particularly novel or sophisticated tool, technique, or procedure.” It was the consequence of missed basics, multiplied by concentration.




The raw material was assembled years before anyone attacked anything. Infostealer malware, sold as a subscription on criminal forums under names like RedLine, Raccoon, Lumma, and Vidar, quietly harvested saved usernames and passwords from infected computers, including employees' and contractors' devices that also held corporate logins. Those credential logs circulated and were sold. Mandiant later traced the earliest infection date of a credential used in this campaign to November 2020, and found that roughly 80 percent of the accounts eventually compromised had credentials already exposed in those markets. The passwords sat there, valid, for years, because nobody rotated them and nothing required a second factor.


Beginning around April 14, 2024, the actor Mandiant designates UNC5537, operating publicly as ShinyHunters, put the archive to work: logging directly into Snowflake customer instances with the stolen credentials, no MFA challenge, no network restriction, no exploit required. Custom tooling tracked as “Frostbite” automated the triage, scanning each compromised tenant for organization names, roles, and high-value data before bulk exfiltration. Then came the extortion, aimed directly at the victims, and when that stalled, the sales threads. The May 28 advertisement of 560 million Ticketmaster records, at $500,000, is how the world found out.



The victim roll call ran through corporate America: Santander confirmed roughly 30 million customers' data; Advance Auto Parts, Neiman Marcus, LendingTree, and Pure Storage confirmed or were named; and on July 12, AT&T disclosed the campaign's heaviest single loss, the call and text metadata of roughly 110 million customers covering six months of 2022, a dataset alarming enough that federal law enforcement worried about its own agents' records inside it. Reporting later described AT&T paying roughly $370,000 for a video of the data being deleted, a transaction AT&T has never confirmed. Snowflake, for its part, maintained accurately that its platform was never compromised, and within months moved to enforce MFA by default for new accounts, retrofitting the control whose absence had defined the campaign.







Whose breach was it?


Snowflake's platform was never compromised, and every statement it made to that effect was true. The campaign still carries its name, in headlines, in this series, everywhere except the Justice Department's filings, and that tension is the first lesson. Under the cloud's shared responsibility model, customer authentication settings belonged to customers, and 165 of them left the door on one lock. But platforms inherit the reputational blast radius of their customers' worst defaults, which is why the most consequential fix came from Snowflake itself: making MFA the default, converting the shared-responsibility gap into a platform guarantee. The control was always available. The campaign is what it cost for optional to become standard.


The attackers didn't breach the cloud. They logged into it.

The second lesson is about what a data warehouse is. These platforms exist to concentrate: an organization's customer records, transactions, telemetry, and history, aggregated into one queryable place. That's their value, and it's also why one working credential was worth 560 million records. The series has seen concentration as shared software (MOVEit), and concentration as shared operations (CDK). Snowflake completes the set: concentration as aggregated data, where the blast radius of a single login is everything the organization ever loaded.



Passwords age like uranium, not like milk


The campaign's supply chain deserves its own look, because it is now the standard one. Infostealers are cheap commodity malware, sold by subscription, infecting personal and work devices through cracked software, malicious ads, and phishing, and harvesting every saved browser login in seconds. The logs are sold in bulk, indexed and searchable. What made them lethal here wasn't freshness, it was durability: credentials stolen in 2020 still opened enterprise data warehouses in 2024, because nothing forced rotation and nothing asked for a second factor. Every organization should assume some of its current credentials are already in those markets, roughly 80 percent of this campaign's victims' were, and the defenses that matter are the ones that make a stolen password insufficient rather than the ones that hope it stays secret.





Not one decision. A set of conditions.

 

Mandiant's report reads like this series' recurring section written by someone else: no novel tools, just missed opportunities. The conditions:





Named, arrested, and pleading guilty


Unusually for this series, the campaign's authors are now named men in court records. Connor Moucka, arrested at home in Canada five months after the campaign peaked, pleaded guilty in August 2026, with prosecutors documenting more than $9.5 million in direct victim losses and conduct that included re-extorting a victim with threats built on a government officer's family's data. John Binns was already in custody in Turkey over a previous telecom breach. And Cameron Wagenius was a serving US Army soldier when he joined the campaign, pleading guilty across 2025. Like the teenagers of the UK retail wave, the roster undercuts the imagined adversary: not a state, not an elite unit, but young men with subscription malware and a market that sold them the keys. The defense that beats them isn't exotic either. It's the second factor they were counting on nobody having.










"A Password Alone Is Not Identity."


The Snowflake campaign will be cited for years as the argument-ender on multi-factor authentication, and it should be. One hundred sixty-five organizations, some of the largest datasets ever stolen, more than nine and a half million dollars in documented losses, and every bit of it contingent on a single missing control that cost nothing and was sitting in the settings. But the fuller lesson includes the supply side: an economy of commodity malware had already stolen the passwords, years earlier, from machines nobody was watching, and time did not degrade them. Secrecy failed long before the campaign began. Only sufficiency, requiring more than the secret, could have held.


For this series, Snowflake closes a loop that opened with consumers reusing passwords at 23andMe: the habit scales, the consequence scales faster, and the fix was identical at both ends. The organizations that internalize it won't be the ones with perfect password hygiene. They'll be the ones for whom a stolen password is a non-event.


BECAUSE THE CLOUD DOESN'T CARE WHO TYPES THE PASSWORD. THAT'S THE WHOLE POINT OF ASKING FOR MORE THAN ONE.



Sources

Comments


bottom of page