GoFirm
Back to Blog
Case Studies·3 min read

The Snowflake Credential Campaign and the Authentication Gap That Exposed Half a Billion Records

By GoFirm

In mid-2024, a financially motivated threat group designated UNC5537 by Mandiant conducted one of the most damaging data theft campaigns in history. They targeted organisations using Snowflake, the cloud data platform, and they did it without exploiting a single vulnerability in Snowflake's infrastructure.

The method was straightforward. The attackers obtained credentials stolen by infostealer malware from employee devices - credentials available for purchase on criminal marketplaces, some harvested as far back as 2020. They used those credentials to authenticate directly into Snowflake customer tenants. Because a large number of affected accounts did not have MFA enforced, a valid username and password was sufficient to gain full access. From there, they exfiltrated data at scale.

Approximately 165 organisations were targeted across the campaign. Ticketmaster confirmed that 560 million customer records had been stolen, including names, addresses, and partial payment card data. AT&T confirmed that call and text metadata covering approximately 110 million customers had been exfiltrated - effectively a record of who every AT&T customer had called or messaged, and when. Santander, LendingTree, Advance Auto Parts, and Neiman Marcus were among the other confirmed victims.

The primary actor, Alexander Moucka, was arrested in Canada in October 2024. That did not recover the data.

There was no breach of Snowflake's platform. No zero-day. No sophisticated intrusion. The attackers authenticated as legitimate users, because they had legitimate credentials, and the systems they accessed had no additional confirmation requirement before data left.

This is the credential theft problem at industrial scale. The industry's answer - enforce MFA - is correct and necessary. Snowflake subsequently moved to require advanced security controls across customer accounts. But MFA alone addresses the authentication layer. It does not address the execution boundary. An attacker who obtains credentials and passes MFA, whether through phishing, SIM swapping, or MFA fatigue, still faces no confirmed authority requirement before bulk data export executes.

GoFirm closes that gap. Bulk data exports from sensitive environments are configured as high-consequence actions requiring a named authority confirmation before execution. The authority receives the full context - what data, how much, to where - and confirms with their biometric on their registered device through a channel separate from the platform being accessed. A threat actor who has successfully authenticated, with or without MFA, cannot produce that confirmation.

Across 165 organisations, the data exfiltration that followed successful authentication executed without a single confirmed authority decision. That is the gap that produced half a billion stolen records. MFA would have made entry harder. GoFirm would have made the exfiltration impossible.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto’s AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in minutes, not months.

References

1. Huntress, Snowflake Data Breach: What Happened, Impact, and Lessons, 2024

2. BlackFog, Snowflake Data Breach Explained: Timeline, Impact, and Key Lessons, 2025

3. Wikipedia, Snowflake Data Breach, citing AT&T and Live Nation SEC filings, 2024.

Share this article