The Snowflake Extortion Campaign at Its Peak: 165+ Customers, One Credential Wave

📋 Key Takeaways
  • What happened?
  • Snow:Bay and the industrialization of extortion
  • The two failures, again and again
  • Why this entry matters in the timeline
  • The Mandiant TTP catalogue, condensed
5 min read · 935 words
Educational & Ethical Use Only — This article is provided for educational and ethical cybersecurity research purposes only. The techniques described should only be used on systems you own or have explicit permission to test. Always follow responsible disclosure and the laws applicable to you. Mitigations are included so engineers can harden real systems.

What happened?

By mid-June 2024, the credential-driven campaign against Snowflake customer tenants had peaked: Mandiant attributed the operation to UNC5537, counted 165-plus victim organizations, and the crew’s data-leak habits had graduated from individual shakedown listings to a dedicated market. On June 19, when this post publishes, Mandiant’s public advisory and Snowflake’s customer report had just dropped, turning what each victim thought was a private extortion note into a named, tracked campaign.

Quick Answer: Mandiant’s June 19, 2024 advisory branded the Snowflake extortion wave UNC5537 — 165+ victims entered with infostealer credentials against MFA-less tenants, data extorted via listings and the “Snow:Bay” leak market; the campaign proved stolen-password economics scale to cloud data platforms.

Everything about UNC5537’s tradecraft was commodity. No zero-day, no sophisticated implant — infostealer logs bought or accumulated, credential-stuffing discipline against Snowflake login endpoints, and patience. Inside, the crew enumerated with standard SQL, staged exfil through cloud storage, and monetized through extortion. Mandiant’s profile emphasized their youth and financial motivation over state ties — a reminder that the barrier to a Fortune-500-scale breach in 2024 is a laptop, a wallet for logs, and tenants without MFA.

Snow:Bay and the industrialization of extortion

The campaign’s trademark was infrastructure discipline unusual for criminal crews: a dedicated leak marketplace researchers dubbed “Snow:Bay,” styled innocuously and hosted for buyers to browse and re-purchase datasets. It converted one-time extortion into an aftermarket. For defenders, that changes the assumption set: data does not resolve to “stolen once” but circulates with a price curve; notification obligations and monitoring must therefore be durable, not a single mail-merge apology.

Date Event
2024-04→05 Early intrusions accumulate; Santander and Ticketmaster disclosures (late May) made the campaign’s existence
2024-06 Peak volume: Advance Auto Parts, LendingTree/QuoteWizard and dozens more confirmed or listed
2024-06-19 Mandiant public advisory attributes campaign to UNC5537; Snowflake customer report details TTPs and countermeasures — this post publishes the same day
2024-06→07 Snow:Bay leak market observed; arrests follow later (a 2025 Canadian bust charged an alleged participant)
2024-H2 Snowflake mandates MFA rollout; industry-wide SaaS identity hardening wave
data-hmmnm-seam="2">

The two failures, again and again

Mandiant’s victim sampling found the same two factors in every confirmed intrusion: credentials already present in infostealer logs, and no MFA on the tenant. Auxiliary factors appeared — demo accounts with production mirrors, service accounts with long-lived keys, absent network policies — but the headline statistic was brutal in its simplicity. The campaign was preventable by a single control, executed consistently across every identity, human or machine.

  • Identity hygiene is the perimeter: MFA on every tenant, phish-resistant where feasible; no exceptions for “internal only” or service identities.
  • Credential-exposure monitoring: ingest stealer-log feeds; auto-burn any credential observed; treat exposure dates as rotation SLAs.
  • Kill legacy surfaces: demo tenants, unused integrations, and 2024-era default-password policies are the entry points campaigns like this are made of.
  • Extortion playbook: pre-determine legal, comms and law-enforcement paths; delay tactics and leak-market realities belong in the plan, not in improv.

FAQ

Was Snowflake itself compromised?

No — every confirmed intrusion used valid customer credentials against customer tenants. The platform’s contribution to the story was architectural (password-only access possible from anywhere) and later corrective: mandatory MFA, network policies, and customer guidance. But “not breached” and “blameless” diverged in the court of customer opinion, which is its own lesson for SaaS vendors.

Who exactly is UNC5537?

Mandiant’s profiling painted a financially motivated crew — young, North America- and Turkey-linked individuals by later reporting, opportunistic rather than state-directed. The 2025 arrest of a Turkish-Canadian suspect (linked to Ticketmaster/Santander claims) added faces to the label. The significance is less the names than the model: low-skill actors industrializing high-yield credential abuse.

What is “Snow:Bay”?

A leak marketplace the crew stood up to sell stolen Snowflake-tenant datasets — some fresh, some recycled from earlier victims, some honestly repackaged, some padded. Its existence signals extortion economics maturing: resale infrastructure, customer segmentation (in the criminal sense), and pricing that decays with data age. Defenders monitoring such markets gain early warning of second-hand exposure.

data-hmmnm-seam="3">

Why this entry matters in the timeline

Placed after Ticketmaster (p05) and before CDK (p11), this entry captures the campaign at its named, quantified peak — the moment the industry stopped calling these “incidents” and started calling it a wave. The 165+ count, the attribution, the leak market: the full lifecycle of a modern cloud-extortion operation, executed without a single zero-day. For every security leader asked “are we doing enough about cloud,” June 19, 2024 supplied the year’s clearest answer metric: count your MFA-less identities. That number is your exposure.

data-hmmnm-seam="4">

The Mandiant TTP catalogue, condensed

The June 19 advisory is worth keeping on the bookshelf. Operationally: valid credentials, no MFA, broad network access; documented abuse of Snowflake’s SQL interfaces to enumerate and stage; exfil via cloud storage buckets and fronting services; extortion through leak-site listings and direct contact. Device trail: infostealer families years back, RDP and VPN footprints fading in and out. Countermeasure mapping is one-to-one: credential monitoring kills stage one, MFA kills stage two, network allow-listing kills stage three, and money-laundering friction (the crew cashed out crypto through standard rails) is where law enforcement eventually caught up.

data-hmmnm-seam="5">

Aftermath and aftershocks

The wave rewrote SaaS security baselines within months: Snowflake’s mandatory MFA (enforced in stages through late 2024), customer-facing security guides, and a wave of tenant audits across every data-platform vendor. Litigation and regulator interest followed the big names. And the UNC5537 playbook — stealer logs plus MFA-less tenants — remains the check-your-org exercise it always was; the crews copying it in 2025 merely changed the vendor logos. The campaign’s final lesson is the oldest one in the book, now priced at 560 million records: identity is the perimeter, and it is only as strong as its laziest non-MFA login.

data-hmmnm-seam="end">

Prabhu Kalyan Samal

Application Security Consultant at TCS. Certifications: CompTIA SecurityX, Burp Suite Certified Practitioner, Azure Security Engineer, Azure AI Engineer, Certified Red Team Operator, eWPTX v3, LPT, CompTIA PenTest+, Professional Cloud Security Engineer, SC-900, SC-200, PSPO I, CEH, Oracle Java SE 8, ISP, Six Sigma Green Belt, DELF, AutoCAD. Writing about ethical hacking, security tutorials, and tech education at Hmmnm.