CASE DOSSIER alleged

Snowflake Customer Multi-Tenant Credential Stuffing Campaign

Docket: SEC CIK 0001640147 Court: U.S. District Court for the Northern District of California Opened: 2024-05-31 Sector: Telecommunications, Entertainment, Banking, Cloud Services

Key Facts

Status
ALLEGED
Legal disposition
Loss Amount
$150.0 million
Stole records of 110 million AT&T phone accounts and 560 million Ticketmaster users, leading to extensive class-action lawsuits and regulatory filings.
Techniques
2
Verified mappings
Defendants
0
Named in charges
  • Legal Status: ALLEGED in U.S. District Court for the Northern District of California.
  • Primary Target Sector: Telecommunications, Entertainment, Banking, Cloud Services.
  • Documented Financial Loss: $150.0 million.
  • 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Coordinated cybercrime campaign targeting over 165 corporate customer tenants of cloud database provider Snowflake using credentials harvested by infostealer malware, exfiltrating billions of consumer records from Ticketmaster, Santander, and AT&T.

Procedural & Incident Timeline

2024-06-05 advisory

CISA issues alert warning organizations with Snowflake tenants to enforce multi-factor authentication and review network allowlists.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1078 Valid Accounts
Defense Evasion
"Threat actors authenticated to victim Snowflake tenants using valid usernames and passwords that had been stolen by info-stealers (Lumma, RedLine) months earlier." Mandiant Joint Advisory ¶ 2 reviewed
T1041 Exfiltration Over C2 Channel
Exfiltration
"Adversaries executed native SQL commands in Snowflake command-line clients (snowsql) to stage and export customer database tables." CISA Advisory Alert reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, Snowflake Customer Multi-Tenant Credential Stuffing Campaign, No. SEC CIK 0001640147 (U.S. District Court for the Northern District of California 2024), https://cyberattackcaselibrary.pages.dev/cases/snowflake-multi-tenant-credential-attacks/
Embeddable Incident Card (HTML):
<iframe src="https://cyberattackcaselibrary.pages.dev/embed/case/snowflake-multi-tenant-credential-attacks" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>