Executive Summary
In 2024, threat actor UNC5537 exploited stolen credentials to access Snowflake customer accounts lacking multi-factor authentication (MFA), compromising at least 165 organizations and exposing data of over 100 million individuals. The attackers utilized infostealer malware to harvest credentials, some dating back to 2020, leading to significant data breaches affecting companies like AT&T and Ticketmaster.
This incident underscores the critical importance of implementing robust security measures, such as MFA and regular credential rotation, to protect against credential-based attacks. Organizations must remain vigilant as similar tactics continue to pose significant threats to data security.
Why This Matters Now
The Snowflake breaches highlight the ongoing risks associated with inadequate credential management and the absence of MFA. As cybercriminals increasingly exploit stolen credentials, organizations must prioritize strengthening their authentication protocols to mitigate potential data breaches.
Attack Path Analysis
Attackers used stolen credentials from infostealer malware to access Snowflake customer accounts lacking multi-factor authentication. Once inside, they escalated privileges by exploiting misconfigured access controls. They moved laterally within the cloud environment to access sensitive data. Established command and control channels to exfiltrate data. Exfiltrated large volumes of sensitive customer data. Impacted over 165 organizations, exposing records of at least 100 million individuals.
Kill Chain Progression
Initial Compromise
Description
Attackers used stolen credentials from infostealer malware to access Snowflake customer accounts lacking multi-factor authentication.
MITRE ATT&CK® Techniques
Valid Accounts
Credentials from Password Stores
Automated Exfiltration
Exfiltration Over C2 Channel
Exfiltration to Cloud Storage
Data Encrypted for Impact
Inhibit System Recovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Multi-Factor Authentication
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – ICT Risk Management Framework
Control ID: Article 6
CISA ZTMM 2.0 – Multi-Factor Authentication
Control ID: Identity Pillar
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
AT&T breach exposed call/text records of nearly all cellular customers, demonstrating critical vulnerability to credential-based attacks and data exfiltration in telecom infrastructure.
Financial Services
Exposed payroll records and Social Security numbers create severe identity theft risks, while weak credential management violates PCI compliance requirements for financial institutions.
Health Care / Life Sciences
DEA registration numbers and personal health data exposure violates HIPAA compliance, with encrypted traffic and zero trust segmentation failures enabling patient data exfiltration.
Government Administration
Government officer data used for re-extortion attacks highlights critical need for enhanced egress security and threat detection in public sector cloud environments.
Sources
- Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million Peoplehttps://thehackernews.com/2026/08/snowflake-hacker-pleads-guilty-over.htmlVerified
- Snowflake: No evidence of platform breachhttps://www.techtarget.com/searchsecurity/news/366587555/Snowflake-No-evidence-of-platform-breachVerified
- Snowflake 2024 Data Breach: 165 Companies Hit (Not Snowflake)https://databreachcost.com/case/snowflake-2024Verified
- Snowflake UNC5537 (2024), When Single-Factor Credentials Break at Scalehttps://nhigovernance.com/breaches/snowflake-unc5537-2024.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely have constrained the attacker's ability to escalate privileges, move laterally, and exfiltrate data by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix CNSF may not prevent initial unauthorized access due to credential theft, it would likely limit the attacker's ability to exploit this access further.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation would likely limit the attacker's ability to escalate privileges by enforcing strict access controls and minimizing implicit trust.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security would likely constrain lateral movement by restricting unauthorized inter-workload communications.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control would likely detect and limit unauthorized command and control communications.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement would likely limit the attacker's ability to exfiltrate large volumes of data.
With Aviatrix CNSF controls in place, the overall impact of the breach would likely be reduced, limiting the exposure of sensitive data.
Impact at a Glance
Affected Business Functions
- Customer Data Management
- Billing Systems
- Customer Support Services
Estimated downtime: N/A
Estimated loss: $9,500,000
Personal Identifiable Information (PII) of over 100 million individuals, including call and text records, payroll data, DEA registration numbers, passport and Social Security numbers.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce multi-factor authentication (MFA) across all user accounts to prevent unauthorized access.
- • Regularly rotate credentials and monitor for compromised credentials to mitigate the risk of credential-based attacks.
- • Implement least privilege access controls to limit the potential for privilege escalation.
- • Utilize network segmentation and microsegmentation to restrict lateral movement within the cloud environment.
- • Deploy data loss prevention (DLP) solutions to monitor and control data exfiltration activities.



