What happened?
On 30 October 2024, Canadian authorities in Ontario arrested a 26-year-old man wanted by the United States in connection with one of the year’s biggest data-theft campaigns: the compromise of cloud accounts belonging to more than 160 organizations using Snowflake’s data warehousing service. The arrest, made on a US warrant and first reported publicly in early November, put a face and a name to the actor cluster Mandiant tracks as UNC5537 – the crew behind the intrusions that cascaded through the spring and summer as the Ticketmaster, Santander, Advance Auto Parts, and ultimately AT&T disclosures. When this post publishes on 1 November 2024, the suspect is in custody with extradition proceedings ahead, his alleged associates still at large, and the security industry holding up the case as the year’s cleanest lesson in what happens when infostealer logs meet single-factor authentication on cloud data platforms.
Quick Answer: UNC5537 is Mandiant’s tracking label for the financially motivated actor cluster behind the 2024 Snowflake customer-account intrusions. The group did not breach Snowflake itself: it used credentials stolen by infostealer malware from customers’ own machines – passwords not protected by multi-factor authentication – to log into individual Snowflake tenant environments legally, and then stole and extorted the data inside. At least 165 organizations were compromised between April and October 2024; the campaign surfaced publicly with May’s Ticketmaster and Santander disclosures, crested with AT&T’s June admission that call and text metadata for nearly all of a year’s wireless traffic had been taken, and closed October with the arrest in Ontario, Canada of a 26-year-old man on a US warrant – reported by Bloomberg to be Connor Riley Moucka, alleged to operate under the aliases Judische and Waifu. The case became the canonical example of credential-driven cloud compromise: no zero-days, no malware wizardry – just recycled passwords, missing MFA, and unlimited data exfiltration once inside.
The campaign’s anatomy is studied now precisely because of its simplicity. The initial access came from infostealer logs – credentials siphoned from infected endpoints, sold or shared in criminal markets – that happened to include Snowflake customer logins without MFA. Logging in as a valid user leaves no breach signature for the platform to detect, because nothing about the login is anomalous to the tenant: the user is legitimate, the password is correct, and the session behaves like analytics work. From there, the attackers enumerated data, staged exfiltration, and pivoted to extortion – contacting victims directly or publishing on criminal forums when payment talks failed. Every subsequent control failure was downstream of that first one: no MFA, no credential-rotation discipline against infostealer exposure, and resource-scoped trust that let one tenant’s identity become that tenant’s entire warehouse.
The paper trail
| Date | Event |
|---|---|
| 2024-04→05 | UNC5537 activity against Snowflake customer tenants scales; initial access via infostealer-harvested credentials lacking MFA |
| 2024-05-30 | Snowflake acknowledges customer-account compromises after extortion attempts; the first victim disclosures (Ticketmaster, Santander) hit the press |
| 2024-06 | AT&T confirms paying a reported ~$370,000 and discloses call/text metadata theft for nearly all customers covering May-October 2022 and January 2024; Advance Auto Parts data leaks |
| 2024-08→09 | Mandiant and Snowflake publish joint guidance on the campaign; hunting continues as additional tenants surface; the actor cluster is publicly tracked as UNC5537 |
| 2024-10-30 | Ontario authorities arrest a 26-year-old man on a US warrant in connection with the campaign; Bloomberg later reports the name and aliases Judische and Waifu |
| 2024-11-01 | This post publishes with the suspect in custody, extradition pending, and the campaign’s lessons already institutionalized |
No zero-days required
What unsettled the industry about UNC5537 was the absence of sophistication in the traditional sense. No memory corruption, no supply-chain implant, no novel evasion – the most technically advanced artifact in the chain was off-the-shelf infostealer malware running on random employees’ laptops. The sophistication was operational: recognizing that cloud data platforms aggregate enormous value behind single passwords, building a pipeline to match stolen credential lists against tenant logins, and converting access into extortion revenue at industrial scale. For a decade the industry priced cloud risk as adversary-versus-platform; 2024’s Snowflake campaign repriced it as adversary-versus-average-password-hygiene, and the average lost. Google Cloud’s own threat data for 2024 recorded infostealer infections in the hundreds of millions – meaning credential supply for attacks of this shape is effectively unlimited, and the differentiating variable is whether the destination requires a second factor.
The extortion economy’s quarter
The campaign also matured the year’s extortion economics. UNC5537 monetized through direct extortion attempts against victims, forum sales of stolen datasets, and – in the pattern that defined 2024 – silent broker median information warfare, where stolen data first surfaces as samples on criminal forums to pressure payment. AT&T’s June disclosure, with its reported ~$370,000 payment and its account of metadata covering most of a year of wireless traffic, demonstrated both the ceiling of exposure and the floor of clearance pricing: unique datasets with national-security resonance priced in the six figures, commodity customer tables in the low thousands. The arrest answers the demand side of that market with a custodial example, but the market itself – logs for sale, access for rent, data for extortion – operated unbothered through the entire campaign and continues to. Enforcement removes operators; it does not remove the incentive structure that recruits their replacements.
MFA as the year’s unofficial standard
The policy aftermath was the fastest-moving part of the story. Within weeks of the May disclosures, Snowflake shipped mandatory MFA requirements and policy-capabilities for tenant administrators – an implicit acknowledgment that voluntary adoption had failed – while Mandiant’s campaign guidance and CISA’s subsequent Secure by Design alerts converged on the same prescriptions: phishing-resistant MFA on all administrative and data-plane access, continuous checking of credential exposure against infostealer dumps, and conditioned access policies that treat an impossible-travel login as an incident rather than a curiosity. enterprises lighting out after their own exposure discovered the hard math of 2024: every credential ever typed on an infected endpoint is presumed stolen, and every SaaS tenant holding consequential data is presumed to be in someone’s credential list. The organizations that treated the Snowflake campaign as their wake-up call spent the summer rotating credentials, enforcing MFA, and inventorying which tenants held what data – discovering, in the process, how many shadow warehouses their analytics teams had spun up outside formal governance.
- Infostealer logs are the new breach: hundreds of millions of infections mean credential supply is unlimited; any login not defended by a second factor is perimeter, waiting for its match.
- Platform security is not tenant security: UNC5537 broke nothing at Snowflake – customer identity was the perimeter, and customer identity was recycling passwords.
- Extortion prices data by uniqueness: the campaign’s payments scaled with irreplaceability – metadata troves priced highest, commodity tables lowest; data inventory discipline is now pricing discipline.
- Arrests cap campaigns, not categories: one operator in custody closes the 2024 chapter while the logs-and-extortion economy recruiting the next crew runs uninterrupted.
FAQ
Did UNC5537 actually hack Snowflake the company?
No – and the distinction is the entire case study. Snowflake’s platform was not breached; its customers’ accounts were accessed with their own valid, stolen credentials. The attackers logged in the front door using passwords harvested by infostealer malware from customer-side machines, defeating nothing but the absence of MFA. That is why the response played out as customer-side remediation (MFA mandates, credential rotation, exposure monitoring) rather than platform-side patching: the vulnerability was in the identity layer customers own, not the service layer Snowflake operates.
Who is the arrested suspect?
Per Bloomberg’s reporting and the Canadian justice process: Connor Riley Moucka, 26, of Kitchener, Ontario, arrested 30 October 2024 on a US warrant and identified as operating under the aliases Judische and Waifu. US court documents accuse him of conspiracy and extortion connected to the campaign against at least 165 organizations. The attribution chain runs Mandiant’s telemetry to the cluster, the cluster’s operational errors to identities, and the identities to a name and address – a reminder that financially motivated crews lag state actors in operational security precisely because scale demands sloppy reuse of personas and infrastructure.
Was the AT&T data part of this campaign?
Yes – AT&T’s June 2024 disclosure, covering call and text metadata for nearly all mobile customers across defined 2022 and 2024 windows, came from its Snowflake tenant compromise, with a reported payment of roughly $370,000 to keep the data contained. It was the campaign’s ceiling event: not because the technique differed, but because the dataset demonstrated what a warehouse compromise means when the tenant is national infrastructure-adjacent. The AT&T episode converted UNC5537 from an enterprise-security story into a national-policy one – Congress asked questions, regulators opened files, and MFA-on-analytics-platforms became a board-level agenda item rather than a hardening checklist footnote.
Legacy: the password era’s last big win
The Snowflake campaign and its October arrest will be remembered as the breach story that was never about a breach. A crew with commodity malware and patience walked into 165 organizations through the front door of recycled passwords, took what they found, and sold silence to the highest bidder – until one of them answered his door in Kitchener. The durable lessons institutionalized themselves almost immediately: MFA stopped being optional on platforms holding consequential data, infostealer exposure monitoring became a purchased service, and data executives learned to answer the question the campaign made famous – what is in your warehouse, and who else can log into it? The arrest puts a person in a cell, but the case’s real legacy is architectural: the assumption that valid credentials equal legitimate users died in the summer of 2024, and every identity system designed since carries its obituary in the design docs. For the password era, UNC5537 was the last big win – and the first chapter of the mandatory-second-factor age it forced into existence.
