Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Snowflake Account Hacks Linked to Santander and Ticketmaster Breaches: What Happened

The 2024 Snowflake campaign targeted customer accounts with infostealer-stolen credentials—not a confirmed breach of Snowflake’s underlying platform. Here is what the Santander and Ticketmaster links establish and what customers should do.
From TheFinanceBase Team8 min to read

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Snowflake was not shown to have suffered a confirmed breach of its underlying production platform. The 2024 campaign targeted individual Snowflake customer accounts with usernames and passwords previously stolen by infostealer malware. According to Mandiant, the affected accounts generally lacked multifactor authentication (MFA), retained old credentials, and had no network allowlists.

The campaign, attributed by Mandiant to the financially motivated threat cluster UNC5537, was linked through company disclosures, reporting, and attacker claims to the Santander and Ticketmaster incidents. However, the large numbers advertised by the attackers—including claims involving 560 million Ticketmaster records and 30 million Santander records—were not independently verified totals in the cited material.

The short version: was Snowflake hacked?

Confirmed: Attackers accessed multiple Snowflake customer environments using stolen credentials, searched the accounts, and extracted data for extortion or resale.

Not established: Mandiant found no evidence that the access originated from a breach of Snowflake’s enterprise environment or a vulnerability in the Snowflake platform.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Norton 360 Deluxe 2027 Antivirus, 5 Devices, Auto-Renews [Download]
  • ONGOING PROTECTION Download instantly & install protection for 5 PCs, Macs, iOS or Android devices in minutes!
  • TOP-PERFORMING VPN Faster speeds, more server locations, and greater connection control to protect your privacy across all your devices, including Smart TVs.
  • ADVANCED SCAM PROTECTION Help spot hidden scams online. With the built-in Genie AI assistant, you’ll never wonder if a message or email is suspicious again.
  • REAL-TIME PROTECTION Advanced security protects against existing and emerging malware threats, including ransomware and viruses, and it won’t slow down your device performance.
  • DARK WEB MONITORING Identity thieves can buy or sell your information on websites and forums. We search the dark web and notify you should your information be found.

Still disputed or unverified: The precise size of the Ticketmaster and Santander data sets, the identity of every person involved, and whether all public claims came from the same group.

That distinction matters. “Snowflake breach” is understandable shorthand, but the evidence more precisely describes customer-account compromises on Snowflake. The platform hosted the affected data, while the initial credentials were stolen from endpoints outside Snowflake.

What happened?

The campaign followed a relatively direct path:

  1. An infostealer infected a computer and harvested credentials from browsers or other local stores.
  2. The stolen Snowflake username and password remained valid—some credentials dated to 2020 or earlier.
  3. The customer account did not require MFA, allowing password-only access.
  4. The attacker logged in through tools such as Snowsight, SnowSQL, Snowflake drivers, or DBeaver Ultimate.
  5. After reconnaissance, the attacker queried and exported valuable data, then pursued extortion or resale.
Infostealer infection
        ↓
Snowflake credentials harvested
        ↓
Old credentials remain valid
        ↓
No MFA blocks password-only login
        ↓
Customer account accessed
        ↓
Reconnaissance and data export
        ↓
Extortion or resale

Mandiant identified malware families including VIDAR, RISEPRO, REDLINE, RACOON STEALER, LUMMA, and METASTEALER. The problem was therefore not credential theft alone. It was the combination of endpoint compromise, long-lived credentials, absent MFA, broad access, and insufficient network restrictions.

Timeline

  • April 2024: Mandiant identified unauthorized access to a Snowflake customer environment.
  • May 20, 2024: Ticketmaster identified its incident, according to contemporaneous reporting.
  • May 22, 2024: Mandiant notified Snowflake of the broader campaign.
  • May 30–31, 2024: Snowflake customer guidance and public reporting emerged.
  • June 10, 2024: Mandiant publicly described UNC5537 and approximately 165 potentially exposed organizations.

The figure of approximately 165 described organizations notified or potentially exposed at that point. It does not mean that 165 organizations were confirmed to have identical data theft, nor does it represent all Snowflake customers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Was there a Snowflake platform vulnerability?

Snowflake said it found no evidence of a vulnerability, misconfiguration, or breach of its platform. Mandiant’s investigation likewise found that every incident it handled in the campaign traced back to compromised customer credentials, with no evidence that the access began with a breach of Snowflake’s enterprise environment.

An early alternative theory from Hudson Rock suggested that an infostealer-compromised Snowflake employee account might have helped attackers obtain access or tokens. That report was withdrawn and should be treated as historical, unverified context—not as an explanation established by the investigation.

This does not mean Snowflake customers had no security responsibility, or that questions about defaults, detection, notification, and shared responsibility are legally settled. It means the cited technical evidence supports customer-account compromise rather than a confirmed compromise of Snowflake’s production infrastructure.

How attackers explored the accounts

Mandiant observed attackers using web and command-line access, drivers, database tools, and a reconnaissance utility it tracks as FROSTBITE. Some reporting used a different attacker-associated name for the tool. The name is an indicator of attacker activity, not evidence that Snowflake itself contained malware.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Observed reconnaissance included listing users and roles, checking current IP addresses and session IDs, and identifying organization names. Attackers then searched for valuable tables and performed bulk queries and exports. A successful login did not automatically prove that every table was accessed; the relevant evidence is in account activity, query history, export records, and downstream victim investigation.

Ticketmaster: what is known?

Live Nation confirmed unauthorized access to Ticketmaster data stored by a third-party cloud database provider. Contemporaneous reporting identified that provider as Snowflake.

A threat actor claimed to possess information on approximately 560 million Ticketmaster customers and demanded $500,000. Reports at the time described fields including names, addresses, phone numbers, and partial payment-card information. The 560-million figure was an attacker claim, not an independently verified total in the cited sources. It should not automatically be translated into 560 million confirmed affected people or payment-card victims.

Santander: what is known?

Santander disclosed a breach affecting customers in Chile, Spain, and Uruguay. Researchers, contemporaneous reporting, and a threat actor later connected the incident to the Snowflake-linked campaign.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Webroot Internet Security Plus | Antivirus Software 2026 | 3 Device | 1 Year Keycard for PC/Mac/Chromebook/Android/IOS + Password Manager | Packaged Version
  • STAY PROTECTED EVERYWHERE you go, at home, in a café, at the airport—everywhere—on ALL YOUR DEVICES, with cloud-based protection against viruses & other online threats
  • Webroot PASSWORD MANAGER by Last Pass creates, encrypts, and saves all your passwords, so you only have to remember one.
  • As the #1 TRUSTED PROVIDER OF THREAT INTELLIGENCE, you know you’re in good hands. Stay safe from viruses, ransomware, phishing, and more.
  • Webroot SOFTWARE UPDATES ITSELF AUTOMATICALLY, so you always have the most current protection without lifting a finger—and updates happen in the background so they won’t slow you down.
  • PREMIUM FEATURES: Encrypts & protects passwords and account information for all your devices so you can stay protected wherever you are.

The attacker advertised a data set said to contain approximately 30 million Santander records. That figure, like the Ticketmaster number, was a claim connected to a data-sale listing—not a confirmed impact total. Advertised records can contain duplicates, stale information, unrelated material, or fabricated samples. A number of records is also not the same as a number of unique individuals or regulated records requiring notification.

Who was responsible?

Mandiant tracks the campaign as UNC5537 and describes it as financially motivated, with data theft, extortion, and attempted resale as objectives.

The name ShinyHunters appeared in reporting and threat-actor claims involving Santander and Ticketmaster. The cited evidence does not establish that ShinyHunters and UNC5537 were the same operational group, that every public claim came from one group, or that every advertised data set was genuine. Those identities should therefore be attributed rather than stated as settled fact.

What Snowflake customers should do

1. Treat exposed credentials as unsafe

Reset passwords for users who accessed Snowflake from infected or unmanaged devices. Rotate credentials found in infostealer logs, and revoke active sessions, tokens, and other programmatic credentials where appropriate.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Changing one Snowflake password is not enough if the endpoint remains infected. Reimage or thoroughly remediate the device, then rotate other credentials used or stored there, including browser passwords, password-manager entries, cloud keys, SSH keys, and developer tokens.

2. Enforce MFA for human users

Mandiant said the compromised accounts did not have MFA enabled. MFA would likely have blocked the password-only access path described in the investigation, although it is not a universal defense against stolen sessions, compromised identity providers, token theft, phishing-resistant-authentication bypasses, or service-account abuse.

Rank #4
Sale
Webroot Internet Security Complete | Antivirus Software 2026 | 5 Device | 1 Year Download for PC/Mac/Chromebook/Android/IOS + Password Manager, Performance Optimizer
  • POWERFUL, LIGHTNING-FAST ANTIVIRUS: Protects your computer from viruses and malware through the cloud; Webroot scans faster, uses fewer system resources and safeguards your devices in real-time by identifying and blocking new threats
  • IDENTITY THEFT PROTECTION AND ANTI-PHISHING: Webroot protects your personal information against keyloggers, spyware, and other online threats and warns you of potential danger before you click
  • SUPPORTS ALL DEVICES: Compatible with PC, MAC, Chromebook, Mobile Smartphones and Tablets including Windows, macOS, Apple iOS and Android
  • NEW SECURITY DESIGNED FOR CHROMEBOOKS: Chromebooks are susceptible to fake applications, bad browser extensions and malicious web content; close these security gaps with extra protection specifically designed to safeguard your Chromebook
  • PASSWORD MANAGER: Secure password management from LastPass saves your passwords and encrypts all usernames, passwords, and credit card information to help protect you online

Snowflake’s documentation describes authentication policies that can require MFA. For an account configuration where this policy is appropriate, an administrator might use:

CREATE AUTHENTICATION POLICY require_mfa_authentication_policy
  MFA_ENROLLMENT = 'REQUIRED'
  MFA_POLICY = (
    ENFORCE_MFA_ON_EXTERNAL_AUTHENTICATION = 'ALL'
  );

ALTER ACCOUNT SET AUTHENTICATION POLICY
  require_mfa_authentication_policy;

Check the current Snowflake authentication-policy documentation before deploying this in production. The effect depends on user type, client, account configuration, and SSO design.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. Separate people from workloads

Unattended ETL jobs, BI tools, scripts, and integrations cannot depend on a person approving an MFA prompt. Do not exempt service identities by giving them reusable human passwords. Inventory service users and migrate them, where supported, to key-pair authentication, OAuth, workload identity federation, or another non-interactive method.

Test the migration against every connector before enforcing a new policy. A rushed MFA rollout can break automated workloads even when the security objective is sound.

4. Restrict network access

Use Snowflake network policies to limit access to trusted corporate egress points, VPNs, private connectivity, or approved tooling. Network restrictions reduce the value of a stolen password used from unfamiliar infrastructure.

Allowlist design has trade-offs. Remote employees, cloud workloads, contractors, disaster-recovery systems, and third-party integrations may use different addresses. Maintain tested break-glass access, document approved ranges, and avoid both ineffective broad allowlists and dangerously narrow policies that create outages.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Webroot Internet Security Complete | Antivirus Software 2026 | 5 Device | 1 Year Keycard for PC/Mac/Chromebook/Android/IOS + Password Manager, Performance Optimizer and Cloud Backup | Packaged Version
  • NEVER WORRY about losing important files and photos again! With 25GB of secure online storage, you know your files are safe and sound.
  • KEEP YOUR COMPUTER RUNNING FAST with our system optimizer. By removing unnecessary files, it works like a PC tune-up, so you can keep working smoothly.
  • Our PASSWORD MANAGER by Last Pass creates, encrypts, and saves all your passwords, so you only have to remember one.
  • As the #1 TRUSTED PROVIDER OF THREAT INTELLIGENCE, Webroot protection is quick and easy to download, install, and run, so you don’t have to wait around to be fully protected.
  • STAY PROTECTED EVERYWHERE you go, at home, in a café, at the airport—everywhere—on ALL YOUR DEVICES with cloud-based protection against viruses and other online threats.

5. Hunt historical activity

Preserve available evidence before deleting users, changing roles, or altering integrations. Review:

  • Login history, source IP addresses, geographies, and unusual authentication times;
  • Client application names and unexpected use of command-line or database tools;
  • New sessions, role enumeration, privilege changes, and unusual administrative activity;
  • Query history involving sensitive tables;
  • Bulk extraction, copying, staging, or export activity; and
  • Access by users or service identities that normally operate from a different environment.

Mandiant’s guidance at the time discussed hunting across the prior 365 days, but retention and visibility depend on the customer’s Snowflake edition, configuration, enabled features, and any logs exported to another system. Missing suspicious records is not proof that no access occurred.

6. Reduce the blast radius

Review privileged roles and excessive grants. Apply least privilege, masking policies, row-access policies, and appropriate controls to sensitive tables. Alert on bulk data extraction and abnormal administrative behavior. A stolen account should not automatically provide access to an entire data estate.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What this incident teaches security teams

  • MFA must be the default for people: Password-only access leaves cloud data vulnerable when credentials leak.
  • Credential age matters: A password stolen years earlier can still work if it was never rotated or invalidated.
  • Endpoint security is part of cloud security: An infected workstation can expose SaaS, database, and cloud credentials simultaneously.
  • Service accounts need a separate plan: Human MFA policies cannot replace secure workload authentication.
  • Network controls add a second barrier: They can limit where a valid credential works, but only if maintained accurately.
  • Logs need preparation: Retention, centralized export, and alerting should be configured before an incident.
  • Data monitoring matters: A valid login may look ordinary until unusual queries, role discovery, or large exports reveal the intrusion.

What the incident does—and does not—prove

The evidence supports a campaign against Snowflake customer accounts using credentials stolen by infostealers. It does not establish that all Snowflake customers were affected, that every public data-sale claim was genuine, or that the advertised record counts equal unique victims.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Nor does it justify saying that changing a password alone resolves the risk. If the original endpoint remains compromised, the replacement password can be stolen again. The practical response must combine identity controls, endpoint remediation, session and credential rotation, network restrictions, least privilege, and historical hunting.

Snowflake’s subsequent documentation describes MFA enforcement, leaked-password protection, network policies, and a staged move away from single-factor password sign-ins. Customers should confirm which controls are available and appropriately configured for their account, region, edition, clients, and workloads.

Frequently Asked Questions

Were all Snowflake customers affected?

No. Mandiant identified approximately 165 potentially exposed organizations as of June 10, 2024; that was not a confirmed-victim count for every organization and not a count of all Snowflake customers.

Can MFA prevent this kind of attack?

MFA would likely have blocked the password-only access path described by Mandiant, but it does not eliminate risks such as stolen sessions, compromised identity providers, token theft, or service-account abuse.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does changing a Snowflake password remove the risk?

Not by itself. The affected endpoint may still be infected, and other credentials from that device may also be compromised. Remediate the endpoint, revoke sessions and tokens, and rotate related credentials.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.