Mandiant is currently assisting Snowflake in responding to a data theft incident [2], known as UNC5537 [1] [4], which has affected 165 of Snowflake’s customers globally.


Snowflake customers, such as Santander, Ticketmaster, and LendingTree, have confirmed data breaches, with ongoing investigations. Mandiant researchers have identified UNC5537 as the cybercriminal group suspected of stealing a significant volume of data from over 100 organizations, including Snowflake customers. The attacks targeted organizations lacking multifactor authentication, allowing unauthorized access using stolen credentials. Mandiant confirmed that Snowflake's environment was not breached, and incidents were traced back to compromised customer credentials. Mandiant began notifying potentially exposed organizations in May and collaborated with Snowflake on a joint investigation and victim notification program. Approximately 100 organizations have been notified of potential exposure, and Mandiant has warned of future similar attacks targeting SaaS solutions. A significant volume of data has been stolen from hundreds of Snowflake cloud storage customers via compromised login credentials, with the incident linked to data breaches at Ticketmaster and Santander Bank. Mandiant, investigating the data theft alongside Snowflake, identified the financially motivated threat actor UNC5537. At least 165 Snowflake customer organizations have been notified of potential compromises, with no evidence suggesting Snowflake's enterprise environment was breached. The UNC5537 group systematically compromised Snowflake customers using stolen login credentials, dating back to 2020, to steal and sell data on cybercriminal forums. The group's successful compromises were due to poor security practices on impacted accounts, with Mandiant expecting the list of victims to grow as UNC5537 targets additional platforms in the near future. The incident underscores the importance of implementing robust security measures, such as multi-factor authentication [1] [3] [7] [8] [9] [10] [12], to protect against cyber threats. Snowflake and Mandiant’s collaborative efforts in investigating and mitigating the data theft incident demonstrate the need for proactive monitoring and response to potential security breaches. The ongoing threat campaign by UNC5537 highlights the evolving tactics of cybercriminals and the necessity for organizations to stay vigilant and continuously improve their security practices to safeguard sensitive data.