>

Snowflake-Related Arrests: UNC5537’s Kitchener Pinch

On October 30, 2024, Canadian authorities arrested a 26-year-old Kitchener, Ontario man on a US warrant connecting him to the Snowflake-account intrusions tracked by Mandiant as UNC5537 — the crew behind the Ticketmaster, Santander, and AT&T disclosures that dominated 2024's data-theft calendar. The arrest, first reported in early November by Bloomberg identifying the suspect as Connor Riley Moucka, illuminated the infostealer-credential-to-cloud kill chain and the market for stolen data. This account reconstructs the campaign, the arrest, and the MFA lessons that outlast it.

Continue ReadingSnowflake-Related Arrests: UNC5537’s Kitchener Pinch

AT&T’s Snowflake Ransom Payment: The $370K Precedent

On July 31, 2024, AT&T confirmed its customer data — including call and text metadata of nearly all subscribers and some SSNs — had been stolen off Snowflake's cloud via compromised service-account credentials, and that it had paid roughly $370,000 to the SQlMap-scanning crew known as ShinyHunters to delete it. This account reconstructs the credential theft, the infostealer-to-Snowflake kill chain, the economics of a mid-six-figure ransom, and the quarterly-burial of accountability between carrier, and its data-warehouse vendor.

Continue ReadingAT&T’s Snowflake Ransom Payment: The $370K Precedent

The Snowflake Extortion Campaign at Its Peak: 165+ Customers, One Credential Wave

On June 19, 2024, Mandiant's public advisory named UNC5537 as the crew behind the Snowflake extortion wave — 165+ victim organizations entered with infostealer credentials against MFA-less tenants, datasets extorted through listings and a dedicated leak market researchers dubbed Snow:Bay. This piece condenses the TTP catalogue, the backyard economics of stolen logs, the aftermarket that changed notification obligations forever, and the single control that would have prevented every confirmed intrusion.

Continue ReadingThe Snowflake Extortion Campaign at Its Peak: 165+ Customers, One Credential Wave

Snowflake-Ticketmaster: The Credential Wave That Broke the Cloud-Secure Myth

Live Nation's May 2024 SEC filing confirmed criminal access to roughly 560 million Ticketmaster customer records — taken not by exploiting Snowflake but by logging into it with infostealer-derived credentials on a tenant without MFA. This account explains the UNC5537 tradecraft that chained $20 stealer logs into Fortune-500 data lakes, why the 'no Snowflake breach' defense only half-worked, what the ~560M-record dataset contained, and the mandatory-MFA wave that reshaped SaaS identity through 2024.

Continue ReadingSnowflake-Ticketmaster: The Credential Wave That Broke the Cloud-Secure Myth
>