CASE DOSSIER
alleged
Snowflake Customer Multi-Tenant Credential Stuffing Campaign
Docket: SEC CIK 0001640147 Court: U.S. District Court for the Northern District of California Opened: 2024-05-31 Sector: Telecommunications, Entertainment, Banking, Cloud Services
Key Facts
Status
ALLEGED
Legal disposition
Loss Amount
$150.0 million
Stole records of 110 million AT&T phone accounts and 560 million Ticketmaster users, leading to extensive class-action lawsuits and regulatory filings.
Techniques
2
Verified mappings
Defendants
0
Named in charges
- Legal Status: ALLEGED in U.S. District Court for the Northern District of California.
- Primary Target Sector: Telecommunications, Entertainment, Banking, Cloud Services.
- Documented Financial Loss: $150.0 million.
- 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:
Case Summary
Coordinated cybercrime campaign targeting over 165 corporate customer tenants of cloud database provider Snowflake using credentials harvested by infostealer malware, exfiltrating billions of consumer records from Ticketmaster, Santander, and AT&T.
Procedural & Incident Timeline
2024-06-05 advisory
CISA issues alert warning organizations with Snowflake tenants to enforce multi-factor authentication and review network allowlists.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1078 | Valid Accounts Defense Evasion | "Threat actors authenticated to victim Snowflake tenants using valid usernames and passwords that had been stolen by info-stealers (Lumma, RedLine) months earlier." | Mandiant Joint Advisory ¶ 2 | reviewed |
| T1041 | Exfiltration Over C2 Channel Exfiltration | "Adversaries executed native SQL commands in Snowflake command-line clients (snowsql) to stage and export customer database tables." | CISA Advisory Alert | reviewed |
Cite & Embed This Case Record
Public Domain / CC0 Bluebook Legal Citation:
Cyberattack Case Library, Snowflake Customer Multi-Tenant Credential Stuffing Campaign, No. SEC CIK 0001640147 (U.S. District Court for the Northern District of California 2024), https://cyberattackcaselibrary.pages.dev/cases/snowflake-multi-tenant-credential-attacks/
Embeddable Incident Card (HTML):
<iframe src="https://cyberattackcaselibrary.pages.dev/embed/case/snowflake-multi-tenant-credential-attacks" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>