{
  "id": "case-snowflake-credential-stuffing",
  "slug": "snowflake-multi-tenant-credential-attacks",
  "title": "Snowflake Customer Multi-Tenant Credential Stuffing Campaign",
  "summary": "Coordinated cybercrime campaign targeting over 165 corporate customer tenants of cloud database provider Snowflake using credentials harvested by infostealer malware, exfiltrating billions of consumer records from Ticketmaster, Santander, and AT&T.",
  "case_number": "SEC CIK 0001640147",
  "court": "U.S. District Court for the Northern District of California",
  "district": "N.D. Cal.",
  "country": "United States",
  "opened_at": "2024-05-31",
  "status": "alleged",
  "victim_sector": "Telecommunications, Entertainment, Banking, Cloud Services",
  "victim_country": "United States, Spain, Worldwide",
  "loss_amount_usd": 150000000,
  "loss_amount_note": "Stole records of 110 million AT&T phone accounts and 560 million Ticketmaster users, leading to extensive class-action lawsuits and regulatory filings.",
  "first_seen_at": "2024-04-14T00:00:00Z",
  "last_updated_at": "2026-06-25T14:00:00Z",
  "actor_slug": "unc5537",
  "defendant_slugs": [],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1078",
      "evidence_excerpt": "Threat actors authenticated to victim Snowflake tenants using valid usernames and passwords that had been stolen by info-stealers (Lumma, RedLine) months earlier.",
      "evidence_locator": "Mandiant Joint Advisory \u00b6 2",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Mandiant & Snowflake Joint Security Bulletin",
      "source_url": "https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1041",
      "evidence_excerpt": "Adversaries executed native SQL commands in Snowflake command-line clients (snowsql) to stage and export customer database tables.",
      "evidence_locator": "CISA Advisory Alert",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Alert",
      "source_url": "https://www.cisa.gov/news-events/alerts",
      "technique_name": "Exfiltration Over C2 Channel",
      "tactic": "Exfiltration"
    }
  ],
  "events": [
    {
      "event_type": "advisory",
      "event_date": "2024-06-05",
      "description": "CISA issues alert warning organizations with Snowflake tenants to enforce multi-factor authentication and review network allowlists."
    }
  ]
}