Don’t do SECURITY. Do business SECURELY.

Snowflake customer accounts raided in wave of data thefts

Attackers use stolen passwords to access Snowflake cloud accounts at Ticketmaster, AT&T, Santander, and others, stealing data on many millions of people.

A wave of data thefts targeting customers of cloud data platform Snowflake came to light when Live Nation disclosed in a regulatory filing that its Ticketmaster subsidiary had been breached, with the stolen database later confirmed as hosted on Snowflake. Victims also included AT&T, Santander, and around 165 organisations in all.

What happened

  • Mandiant said the group it tracks as UNC5537 logged into customer accounts using stolen credentials, mostly exposed by infostealer malware, on accounts without multi-factor authentication.
  • Snowflake and Mandiant said they had found no evidence that Snowflake’s own enterprise environment had been breached.
  • AT&T said call and text records for nearly all its mobile customers had been taken, and was reported to have paid a hacker about US$370,000 to delete the data.
  • A Canadian, Connor Moucka, was arrested on 30 October 2024 and a US man, John Binns, already detained in Turkey, was charged in connection with the thefts; Moucka pleaded guilty in August 2026.

Why it mattered

The campaign showed that a single missing control, MFA, across cloud tenants could expose huge volumes of data, and it pushed Snowflake to make MFA the default and let administrators enforce it.

Lessons for organisations

Enforce MFA and network restrictions on all cloud and SaaS accounts, rotate old credentials, and protect endpoints against infostealers. Cloud security remains a shared responsibility, whatever the provider’s own controls.

Sources: Google Cloud (Mandiant), TechCrunch

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights