Back to all lessons
Awareness Lessons
2 months ago

Stolen Credentials Enabled Mass Snowflake Account Compromise

The UNC5537 campaign succeeded because 165 organizations failed to adequately protect their Snowflake cloud accounts against credential-based attacks, with no multi-factor authentication (MFA) standing between attackers and billions of sensitive records. Stolen credentials — likely harvested through infostealer malware or prior breaches — were used directly to authenticate into cloud environments without triggering sufficient alerts. This case illustrates that cloud data platforms are high-value targets, and that weak authentication hygiene combined with poor monitoring creates catastrophic exposure. The $9.5 million in organizational losses and massive reputational damage could have been significantly mitigated by basic access control enforcement. It is a stark reminder that perimeter defenses mean little when attackers can simply log in with valid credentials.

Tactical Insight

Immediate Actions

  • Enforce multi-factor authentication (MFA) on all cloud platform accounts, including Snowflake and similar SaaS/data warehouse services.
  • Audit all active credentials and revoke or rotate any that may have been exposed in prior breaches using tools like HaveIBeenPwned or threat intelligence feeds.
  • Review Snowflake (and cloud platform) login audit logs immediately for anomalous access patterns such as unusual geolocations or off-hours logins.

Long-term Improvements

  • Implement a Zero Trust access model requiring continuous verification of identity, device posture, and context before granting access to sensitive data platforms.
  • Establish a formal credential hygiene program that includes regular password rotation, infostealer monitoring, and privileged access management (PAM) tooling.
  • Apply the principle of least privilege to all cloud service accounts, ensuring users and service principals only have access to the data they require.

Detection Measures

  • Deploy a SIEM or cloud-native monitoring solution to alert on suspicious authentication events such as impossible travel, new device logins, or bulk data exports.
  • Integrate threat intelligence feeds to detect when employee or service account credentials appear on dark web marketplaces or paste sites.
  • Conduct regular tabletop exercises simulating credential compromise scenarios to validate detection and response playbooks.