
criticalThreat Intelligence
Massive Data Exfiltration Campaign Targets Snowflake Customers via Stolen Credentials and Lack of MFA
Threat actor UNC5537 has compromised hundreds of Snowflake customer environments, leading to high-profile data breaches at Ticketmaster and Santander Bank through credential stuffing.
02 August 2026Last updated 20 August 20266 min readMandiant
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- Cybercriminal
- Geography:
- Global
- Confidence:
- Confirmed
- Source:
- Mandiant
- Read Time:
- 6 min
Executive Summary\nIn the last 48 hours, intelligence reports from Mandiant and Snowflake have confirmed a large-scale data exfiltration campaign targeting Snowflake's cloud data platform. A financially motivated threat actor, tracked as UNC5537, has successfully compromised a significant number of customer instances by leveraging stolen credentials. The campaign has already resulted in massive data breaches involving major corporations, including Ticketmaster and Santander Bank, with hundreds of millions of user records reportedly stolen and offered for sale on underground forums. This activity underscores the critical importance of multi-factor authentication (MFA) for cloud-based data warehouses.\n\n## Threat Analysis\nThe campaign is not a breach of the Snowflake platform itself but rather a systematic exploitation of individual customer accounts that lacked MFA protection. UNC5537 utilizes credentials harvested from historical infostealer malware infections (such as Lumma, Vidar, and Redline) to gain initial access. Once inside, the actor uses specialized automation to rapidly discovery and export large volumes of data from the target's databases. The scale and speed of the exfiltration indicate a highly organized operation with a focus on high-value data sets that can be used for extortion or sold to other cybercriminals on the dark web.\n\n## Technical Details\nTechnical analysis reveals that UNC5537 uses a custom utility, dubbed 'FROSTBITE' by researchers, to interface with the Snowflake API and automate data extraction. The actor typically connects using the 'snowsql' and 'snowflake-connector-python' clients from a consistent set of IP addresses, often associated with commercial VPN providers or TOR exit nodes. In many cases, the compromised accounts were service accounts or administrative accounts that had been active for years without password rotation. Mandiant observed the actor performing reconnaissance queries to identify tables containing Personally Identifiable Information (PII) before initiating bulk exports to attacker-controlled cloud storage buckets. The absence of network policies allowed these connections to originate from unauthorized IP ranges without triggering alerts.\n\n## Attribution Assessment\nMandiant tracks this activity as UNC5537, a group likely composed of individuals with ties to the broader 'Com' community—a loose affiliation of cybercriminals known for sophisticated social engineering, SIM swapping, and data theft. While the primary motive is financial, the efficiency of their data harvesting suggests a level of operational maturity previously associated with advanced persistent threats (APTs). The actor has been observed interacting with victims on Telegram and data-leak sites like BreachForums to negotiate ransoms and advertise the stolen data.\n\n## Implications\nThis campaign highlights a critical weakness in the cloud shared responsibility model: the risk of credential mismanagement at the customer layer. Organizations relying on cloud-native data warehouses must recognize that platform security is insufficient if individual accounts are not hardened. The incident also underscores the long shelf-life of infostealer-harvested credentials, which can remain valid for years if not proactively managed. The downstream impact of these breaches will likely include a surge in targeted phishing, identity theft, and secondary supply chain attacks against the affected customers.\n\n## Recommendations\nEncrygma recommends all Snowflake customers immediately audit their environments for unauthorized access. Key mitigation steps include: 1. Enforcing Multi-Factor Authentication (MFA) on all accounts without exception; 2. Rotating all credentials for service accounts and administrative users; 3. Reviewing network logs for connections from unauthorized IP ranges or known VPN/TOR exit nodes; 4. Implementing 'Network Policies' within Snowflake to restrict access to trusted source IPs; 5. Utilizing Snowflake's 'SYSTEM$GET_ACCESS_CONTROL_REPORT' to identify high-risk accounts and permission anomalies.
ENCRYGMA
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Share
Back to News Room