Executive Summary
Between February and October 2024, cybercriminals exploited stolen credentials to access Snowflake customer accounts lacking multi-factor authentication (MFA). This led to unauthorized access to sensitive data from at least 165 organizations, including AT&T, Ticketmaster, and Santander. The attackers, notably Connor Riley Moucka and John Erin Binns, utilized infostealer malware to harvest login information, resulting in the theft of terabytes of data and extortion of millions of dollars from affected companies.
The incident underscores the critical importance of implementing robust security measures, such as MFA, to protect cloud-based data. As cloud services become increasingly integral to business operations, organizations must prioritize stringent access controls and continuous monitoring to mitigate the risk of similar breaches.
Why This Matters Now
The Snowflake data breach highlights the urgent need for organizations to enforce multi-factor authentication and strengthen access controls to safeguard sensitive information in cloud environments.
Attack Path Analysis
Attackers used credentials stolen via infostealer malware to access Snowflake accounts lacking multi-factor authentication (MFA). Once inside, they identified and escalated privileges to access sensitive data. They moved laterally within the cloud environment to locate and aggregate valuable information. The attackers established command and control channels to manage data exfiltration. They exfiltrated terabytes of sensitive data, including PII and financial records. Finally, they extorted victims by threatening to disclose the stolen data unless ransoms were paid.
Kill Chain Progression
Initial Compromise
Description
Attackers used credentials stolen via infostealer malware to access Snowflake accounts lacking multi-factor authentication (MFA).
MITRE ATT&CK® Techniques
Valid Accounts: Cloud Accounts
Compromise Accounts: Cloud Accounts
Account Manipulation: Additional Cloud Credentials
Exfiltration Over Web Service: Exfiltration to Cloud Storage
Data Encrypted for Impact
Brute Force: Password Spraying
Application Layer Protocol: Web Protocols
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Multi-Factor Authentication for All Access
Control ID: 8.3.6
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – ICT Risk Management Framework
Control ID: Article 6
CISA Zero Trust Maturity Model 2.0 – Multi-Factor Authentication Implementation
Control ID: Identity Pillar
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Banking/Mortgage
Critical exposure to cloud data theft targeting banking records, financial information, and PII requiring enhanced egress security and zero trust segmentation controls.
Telecommunications
High-risk sector with call/text history exposure demonstrated by AT&T breach, necessitating encrypted traffic protection and anomaly detection for customer data.
Entertainment/Movie Production
Significant vulnerability shown through Ticketmaster breach affecting customer databases, requiring multicloud visibility and threat detection for large-scale consumer data protection.
Financial Services
Severe impact from Santander breach exposing customer financial data, demanding comprehensive egress policy enforcement and inline inspection for sensitive transaction information.
Sources
- Canadian pleads guilty to Snowflake cloud data-theft attackshttps://www.bleepingcomputer.com/news/security/canadian-pleads-guilty-to-snowflake-cloud-data-theft-attacks/Verified
- Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millionshttps://www.justice.gov/opa/pr/canadian-man-pleads-guilty-hacking-us-cloud-storage-provider-and-extorting-its-customersVerified
- Snowflake: No evidence of platform breachhttps://www.techtarget.com/searchsecurity/news/366587555/Snowflake-No-evidence-of-platform-breachVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely have constrained the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix Zero Trust CNSF may not prevent initial unauthorized access due to compromised credentials, it would likely limit the attacker's ability to exploit this access to move laterally or escalate privileges.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation would likely limit the attacker's ability to escalate privileges by enforcing strict access controls and minimizing trust between workloads.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security would likely constrain the attacker's lateral movement by enforcing strict segmentation and monitoring internal traffic.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control would likely limit the establishment of command and control channels by monitoring and controlling outbound communications.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement would likely constrain data exfiltration by enforcing strict outbound data policies and monitoring egress traffic.
With Aviatrix Zero Trust CNSF controls in place, the attacker's ability to exfiltrate sensitive data would likely be constrained, thereby reducing the leverage for extortion.
Impact at a Glance
Affected Business Functions
- Customer Data Management
- Financial Transactions
- Communication Records
- Employee Information Systems
Estimated downtime: N/A
Estimated loss: $9,500,000
Non-content call and text history records, banking and financial information, payroll records, DEA registration numbers, driver's license numbers, passport numbers, Social Security numbers, and other personally identifiable information (PII) affecting over 100 million individuals.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce multi-factor authentication (MFA) on all accounts to prevent unauthorized access.
- • Implement Zero Trust Segmentation to limit lateral movement within the cloud environment.
- • Utilize East-West Traffic Security to monitor and control internal traffic flows.
- • Deploy Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.
- • Establish Threat Detection & Anomaly Response mechanisms to identify and respond to suspicious activities promptly.



