Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsThe 2024 Snowflake-related data theft campaign targeted customer accounts, not a demonstrated breach of Snowflake’s own enterprise environment. Mandiant said the incidents it investigated traced to stolen customer credentials; by June 10, 2024, Mandiant and Snowflake had notified about 165 organizations that they might have been exposed. A later U.S. Department of Justice announcement, on August 5, 2026, said a defendant pleaded guilty in a conspiracy involving more than 165 victim organizations.
Was Snowflake itself breached?
Mandiant’s June 10, 2024 analysis of the incidents it handled found no evidence that unauthorized access resulted from a breach of Snowflake’s enterprise environment. Instead, the attackers used credentials exposed through infostealer malware on systems outside Snowflake, then signed in to customer Snowflake instances. The distinction matters: the campaign involved customer accounts hosted on Snowflake, but Mandiant did not attribute the access it investigated to a compromise of Snowflake’s corporate systems. Mandiant’s campaign analysis describes its findings and their scope.
How many organizations were affected?
The published counts use different wording and dates, and should not be treated as interchangeable:
| Source and date | What the figure describes |
|---|---|
| Mandiant and Snowflake, June 10, 2024 | Approximately 165 organizations notified as potentially exposed. |
| U.S. Department of Justice, August 5, 2026 | More than 165 victim organizations in the criminal conspiracy described in the guilty-plea announcement. |
“Potentially exposed” does not mean that every notified organization had confirmed data theft, nor does either count establish an identical impact for each company. The cited official sources do not provide a single reconciled list of all affected organizations or a complete account of each victim’s losses.
#1 Best Overall
How did the attackers get into customer accounts?
Mandiant tracked the financially motivated group as UNC5537. Its investigation found that the group used credentials collected by infostealer malware from systems not owned by Snowflake. Once authenticated, the attackers accessed customer accounts and exported data. The accounts in the investigated incidents did not have multifactor authentication (MFA) enabled.
Mandiant and Snowflake’s 2024 analysis found that 79.7% of accounts leveraged by the threat actor had prior credential exposure. Mandiant also said most credentials used were available from historical infostealer infections, with some dating to 2020. It identified three recurring weaknesses:
- MFA was not required for the affected accounts.
- Some stolen credentials had remained valid without rotation for years.
- The affected instances lacked network allow lists restricting access to trusted locations.
These findings describe the accounts in Mandiant’s investigated incidents; they are not a claim that every Snowflake customer account had the same weaknesses.
What data was stolen, and how was the campaign monetized?
Mandiant reported data theft, attempted data sales and extortion in its 2024 campaign analysis. The later DOJ announcement says that, between February and October 2024, Connor Riley Moucka and co-conspirators used stolen login credentials to compromise cloud-hosted data belonging to at least 165 customers of a U.S.-based SaaS company. According to DOJ’s account of court documents, they stole billions of sensitive records—including call and text history, financial and payroll information, and identity data—and threatened to publish stolen data online. DOJ reported that the conspirators received more than $2.5 million in ransom payments and that at least one victim was extorted again.
Those broader scope and payment figures come from DOJ’s August 5, 2026 guilty-plea announcement, not Mandiant’s 2024 report. DOJ described Moucka’s plea in a statement on the case. Assistant Attorney General A. Tysen Duva said, “Today’s guilty plea serves as a reminder to all cybercriminals, regardless of where they live, that they cannot hide behind a wall of anonymity.”
Which companies disclosed related data access?
In a July 16, 2024 letter, Senators Richard Blumenthal and Josh Hawley summarized AT&T’s disclosure that six months of customer call and text records, including location information, had been illicitly accessed from a third-party cloud platform. The letter also named Ticketmaster, Advance Auto Parts and Santander Bank as companies that had announced related disclosures by that date. It is a dated congressional summary, not a complete victim list or a substitute for each company’s own disclosure. Read the senators’ July 16 letter to AT&T.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How should organizations reduce the risk?
Mandiant’s recommendations address the weaknesses it observed in the campaign. Organizations should apply them across relevant accounts and pair them with response procedures that account for stolen data, not just encrypted systems.
Quick Recap
Best Value
Harden account access
- Enforce MFA for every account, and use secure authentication methods.
- Monitor credentials for signs of exposure; invalidate or rotate credentials when exposure is suspected rather than leaving them active.
- Restrict access to critical data and accounts to trusted network locations using allow lists where appropriate.
Improve detection and response
- Alert on abnormal access attempts and investigate unexpected data access or export activity.
- Ensure incident-response plans address data exfiltration and extortion threats, including threats to publish stolen information even when no files have been encrypted.
- Use CISA’s StopRansomware Guide for broader prevention practices and a response checklist; its guidance covers data extortion as well as ransomware that encrypts files.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Recommended Free Tools

