A broad intrusion campaign compromised Snowflake customer environments including Ticketmaster, Santander and AT&T after attackers used credentials stolen by infostealer malware or bought on criminal forums, rather than exploiting a flaw in Snowflake itself. Reporting tied the activity to ShinyHunters, which advertised allegedly stolen data from Ticketmaster and Santander, while Mandiant said many affected accounts lacked multifactor authentication and that more than 100 customer environments were targeted. AT&T said the attackers accessed its Snowflake environment in April and stole call and text metadata for nearly 110 million customers, including numbers contacted, interaction counts and aggregate call durations, but not message content.
The campaign evolved from data theft into extortion, with victims receiving ransom demands and law enforcement pursuing suspects tied to the operation. Canadian authorities arrested a man from Kitchener, Ontario, in connection with the Snowflake hacking and extortion scheme, and reporting later indicated another suspected participant may have been a U.S. soldier. Government agencies including Australia’s Signals Directorate and U.S. investigators were drawn into the response, and AT&T said disclosure of its breach was temporarily delayed at the request of the FBI and DOJ because of national security and public safety concerns.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
17 events from the most recent confirmed update back to the earliest known activity.
BlackFog's account of the Snowflake campaign lists Neiman Marcus among the publicly identified organizations affected by the customer-environment compromises. This adds a new named victim beyond those already captured in the existing timeline.
CBC reported that the Kitchener, Ontario man arrested over the Snowflake hacking scheme could face extradition to the United States. The development showed the case progressing beyond arrest toward potential prosecution.
Further reporting identified another alleged participant in the Snowflake extortion activity and said the suspect may be a U.S. soldier. This expanded public attribution around the people allegedly involved in the campaign.
A Canadian man was arrested in connection with the Snowflake data extortion campaign. The arrest represented a significant law enforcement action in the investigation into the breaches and related extortion attempts.
Reporting indicated that a hacker tied to the Snowflake customer data breaches was still active months after the initial disclosures. This marked a continuing operational threat beyond the first wave of victim notifications.
WIRED reported that AT&T paid a hacker about $370,000 in cryptocurrency in an effort to secure deletion of data stolen from its Snowflake environment. The payment marked a specific post-breach extortion response by AT&T beyond its earlier public disclosure of the incident.
AT&T disclosed that a cyberattack against its Snowflake environment exposed call and text metadata for roughly 110 million customers. The stolen records covered a six-month period ending October 31, 2022, plus records from January 2, 2023, but not message contents or customer names.
Mandiant reported that the Snowflake intrusions were driven by stolen credentials harvested from non-Snowflake systems and that affected accounts generally lacked multifactor authentication. Reporting said more than 165 Snowflake customers did not use MFA, underscoring the campaign's scale and cause.
Pure Storage confirmed that attackers accessed data through a compromised Snowflake account, making it another publicly identified victim in the broader Snowflake customer compromise campaign. The disclosure added a new affected organization beyond those already named publicly.
Reporting said victims of the Snowflake data breach campaign were receiving ransom demands. This reflected a later-stage monetization and extortion phase affecting organizations compromised in the earlier intrusions.
WIRED reported that Advanced Auto Parts and LendingTree were among the organizations affected in the Snowflake customer compromise campaign. The report expanded the known victim list beyond Santander and Ticketmaster, indicating the breach wave was broader than initially disclosed.
Australia's Signals Directorate said it was aware of successful compromises involving several companies using Snowflake environments. This added government confirmation that the activity extended beyond the initially named victims.
Snowflake disclosed that accounts belonging to multiple customers were compromised after threat actors used credentials obtained via infostealer malware or bought on cybercrime forums. The company said the activity was not due to a vulnerability in Snowflake's platform itself.
Ticketmaster parent Live Nation confirmed a recently disclosed breach and identified Snowflake as the third-party cloud provider involved. The incident was publicly linked to the same campaign affecting other Snowflake customers.
Santander disclosed that data belonging to millions of customers and all current and some former employees had been hacked. Reporting linked the incident to compromises of Snowflake customer environments.
AT&T said it discovered the theft on April 19, 2024, and began incident response with third-party cybersecurity experts. Subsequent public disclosure was delayed after FBI and DOJ requests tied to national security and public safety concerns.
AT&T said attackers accessed its Snowflake environment between April 14 and April 25, 2024, as part of the broader Snowflake customer compromise campaign. The intrusion led to theft of call and text metadata affecting nearly all of AT&T's wireless customers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
22 references tracked. Mallory keeps watching after this page renders.
blackfog.com
Open sourcebankinfosecurity.com
Open sourcecbc.ca
Open sourcekrebsonsecurity.com
Open sourcebbc.com
Open sourcetheverge.com
Open sourcetechcrunch.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.