Christensen Group Insurance Article

Connect with us
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Search
August 24, 2026

Cyber case study: What the Snowflake data breach teaches your business about data security

In 2024, threat actors stole information from more than 160 organizations by using harvested usernames and passwords to gain unauthorized access to customers’ Snowflake environments. Snowflake—a cloud-based data warehousing and analytics service—was not breached, nor was its software exploited. Instead, the attackers relied on compromised credentials to access customer accounts and exfiltrate sensitive data. The campaign exposed hundreds of millions of records, triggered regulatory scrutiny and, in some cases, prompted litigation. High-profile victims included AT&T, Ticketmaster and Santander Bank.

The incident demonstrated how a single point of failure (e.g., stolen credentials) can have significant and far-reaching consequences. Organizations can learn valuable cybersecurity lessons by reviewing the details of this incident, its impact, and the contributing factors.

The details

In April 2024, cybersecurity firm Mandiant identified a threat campaign targeting Snowflake customer database instances after receiving intelligence relating to exposed database records. Subsequent investigations revealed that attackers had gained access to customer environments using legitimate usernames and passwords that had previously been stolen from users’ devices by credential- stealing malware, known as infostealers.

According to Mandiant, many of the credentials used in the attack had been exposed months or even years earlier, with some dating back to 2020. These exposed credentials were already circulating within cybercriminal marketplaces and were subsequently acquired and used at scale to gain direct access to accounts.

After gaining access, the attackers responsible for the campaign, referred to by Mandiant as UNC5537, used a custom tool called FROSTBITE to conduct reconnaissance, gathering information such as user accounts, IP addresses, session IDs, and organization names. Next, they moved laterally within individual Snowflake environments to exfiltrate data, which they later used in extortion attempts. According to reports, proceeds from extortion exceeded $2 million across the campaign.

Approximately 165 organizations were breached, including several high-profile victims. AT&T disclosed that call and text message metadata associated with approximately 109 million customer accounts had been exfiltrated, while Ticketmaster confirmed the theft of data relating to approximately 560 million customers. Additional confirmed victims included Santander Bank, Advance Auto Parts, Neiman Marcus, and Bausch Health.

Many of the breaches succeeded because individual Snowflake environments lacked multifactor authentication (MFA), while others lacked network allow lists that restrict access to trusted corporate networks or approved VPN addresses. Some organizations believed they were secure because they had implemented single sign-on (SSO). However, locally created username and password credentials remained active after SSO adoption, allowing the threat actors to bypass centrally enforced MFA controls and gain access through unmonitored entry points.

Following an investigation, U.S. authorities identified Canadian national Connor Riley Moucka, who used the online alias “Judische,” as the primary operator behind the campaign. He was arrested in Canada in October 2024, while alleged co-conspirator John Binns was arrested in Turkey.

According to cybersecurity firm Mandiant, the vast majority of credentials used in the campaign had already been circulating in infostealer logs prior to the attack. Rather than exploiting a software vulnerability or breaching Snowflake’s infrastructure, the attackers simply logged in using valid usernames and passwords, demonstrating how comparatively unsophisticated tactics can enable large-scale data theft.

The impact

The Snowflake data breach had significant and far-reaching consequences. Ramifications included the following:

Operational disruption

Impacted organizations experienced considerable operational disruption as they undertook work to identify stolen records, notify affected customers, and coordinate with regulators. Some organizations engaged specialized incident response teams to investigate the breach and strengthen security controls, and the response and remediation efforts required significant time and resources.

Financial losses

Organizations faced direct costs related to breach investigations, incident response services, and customer notification efforts. In some cases, they also faced extortion demands as attackers threatened to release stolen data unless a ransom was paid. AT&T, for example, reportedly paid approximately $370,000 in Bitcoin to secure the deletion of stolen data. Class-action lawsuits were filed against several affected organizations. In AT&T’s case, litigation related to the Snowflake breach and a separate 2024 data incident led to a $177 million settlement.

Reputational damage

The cyber group advertised victim data for sale on cybercrime forums, damaging consumer trust in affected organizations, particularly where the stolen information included sensitive personal details. The scale of the exposed data, including data linked to approximately 109 million AT&T customers and approximately 560 million Ticketmaster users, kept affected businesses under intense public scrutiny, further amplifying reputational damage.

Regulatory scrutiny

The breach attracted regulatory scrutiny across multiple jurisdictions, requiring affected organizations to assess their notification obligations and, where necessary, report the incident to regulators and affected individuals. The incident also prompted renewed attention to the vast quantities of sensitive data stored in cloud environments and the identity and access controls used to protect it. Snowflake itself faced questions about whether stronger security measures (e.g., mandatory MFA) could have reduced the scale of the campaign, even though its platform wasn’t breached.

Lessons learned

There are several key takeaways from the Snowflake breach regarding cybersecurity and access control. The incident emphasized these important lessons:

1. MFA

The breach underscored the importance of MFA in protecting access to sensitive systems and data. Since many of the compromised accounts lacked MFA, attackers gained access using only a username and password. Organizations should consider enforcing MFA across all cloud services, including administrative accounts and older accounts that may not be subject to the same security controls as newer systems.

{{richtext-cta-general-1="/components/rich-text-cta"}}

2. Credential management

The attack demonstrated the risks associated with poor credential hygiene. Many of the credentials used in the attack had been exposed long before the breach occurred, but they remained valid because organizations had not changed the associated passwords, decommissioned unused accounts, or implemented other mitigation controls.

Organizations should consider implementing strong credential lifecycle management practices, including regular password rotation, timely removal of inactive accounts, and monitoring for compromised credentials. When adopting SSO, organizations should also audit and disable legacy authentication methods that could allow users to bypass centralized security controls.

3. Third-party and supply chain risk management

The breach highlighted the risks associated with third-party access. In several Snowflake- related investigations, the credentials used by attackers were traced back to contractor devices that had previously been infected with infostealer malware. Organizations should ensure that all third-party accounts with access to business systems are protected by strong authentication controls, including MFA where possible.

4. Monitoring and access controls

The breach underscored the importance of detecting unusual account behavior. By logging in with legitimate credentials that had been compromised, the attackers appeared to be authorized users, so their access and subsequent data exfiltration didn’t immediately raise suspicion.

Organizations should monitor unusual data export volumes and timing patterns, set alerts for large or unexpected exports, and implement approval requirements for bulk data movements. They should also consider restricting access to sensitive platforms through network access policies (e.g., limiting logins to trusted IP addresses, approved locations, or managed devices), which can help prevent stolen credentials from being used to gain unauthorized access.

5. Insurance considerations

The breach highlighted the significant financial consequences of large-scale data loss and, therefore, the importance of cyber insurance. Organizations should review both their first- and third-party cyber coverage to ensure the limits are sufficient to cover potential notification, remediation, extortion, and litigation costs. Some cyber insurers require MFA or other minimum security controls as a condition of coverage, and failure to maintain these controls could limit or void coverage.

For more risk management guidance and insurance solutions, contact us today.

Provided by Christensen Group Insurance. © 2026 Zywave, Inc. All rights reserved.

Get the latest insurance articles sent to your inbox

Stay up-to-date with our latest insurance news and information.

Speak with an insurance expert.

Talk with us today