A wave of data thefts targeting customers of cloud data platform Snowflake came to light when Live Nation disclosed in a regulatory filing that its Ticketmaster subsidiary had been breached, with the stolen database later confirmed as hosted on Snowflake. Victims also included AT&T, Santander, and around 165 organisations in all.
What happened
- Mandiant said the group it tracks as UNC5537 logged into customer accounts using stolen credentials, mostly exposed by infostealer malware, on accounts without multi-factor authentication.
- Snowflake and Mandiant said they had found no evidence that Snowflake’s own enterprise environment had been breached.
- AT&T said call and text records for nearly all its mobile customers had been taken, and was reported to have paid a hacker about US$370,000 to delete the data.
- A Canadian, Connor Moucka, was arrested on 30 October 2024 and a US man, John Binns, already detained in Turkey, was charged in connection with the thefts; Moucka pleaded guilty in August 2026.
Why it mattered
The campaign showed that a single missing control, MFA, across cloud tenants could expose huge volumes of data, and it pushed Snowflake to make MFA the default and let administrators enforce it.
Lessons for organisations
Enforce MFA and network restrictions on all cloud and SaaS accounts, rotate old credentials, and protect endpoints against infostealers. Cloud security remains a shared responsibility, whatever the provider’s own controls.
Sources: Google Cloud (Mandiant), TechCrunch
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.