Back to all incidents

Snowflake

snowflake.com
CONFIRMED

A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provide...

Observable Status CONFIRMED
Industry / Sector Technology
Incident Classification Credential Stuffing / Cloud Account Takeover
Attributed Threat Actor UNC5537
Affected Population 165,000,000 records
First Seen 2026-08-06
Last Updated 2026-10-06
Corporate Customer Data Warehouses Authentication Credentials Client Database Backups Customer Data Warehouses
OPEN WEIGHTS TELEMETRY • DETERMINISTIC CONFIDENCE

Confidence & Source Corroboration

85% CONFIDENCE
1. Primary Authority CONFIRMED BY TARGET Base weight: 50%
2. Evidence Specificity +23% Statutory Filing Verified
3. Corroboration Curve +12% 2 independent domains
4. Timeline & Staleness +0% 2 milestones logged
Corroborated Source Domains:
krebsonsecurity.com bleepingcomputer.com
STATUTORY REGULATORY DISCLOSURES

Official Regulatory Filings & Legal Compliance Records

1 Verified Statutory Filing
Regulatory Ground Truth Standard: The disclosures below represent formal statutory filings and enforcement records submitted to government regulatory authorities (SEC, State Attorneys General, HHS OCR, CISA). In accordance with repository principles, this data is captured exactly as filed by the reporting entity and is never modified, overridden, or synthesized by AI models.
U.S. Securities and Exchange Commission (SEC)

Form 8-K (Item 8.01 Other Events - Customer Cybersecurity Disclosures)

CONFIRMED BY REGULATOR
Docket / Accession ID 0001640147-24-000042
Statutory Filing Date 2024-06-03
Disclosed Impact 165,000,000 records
Evidence Standard Regulatory Ground Truth
Statutory Filing Details & Summary (Preserved As Filed):

Form 8-K filing regarding customer account security disclosures detailing threat actor credential stuffing against customer demo environments lacking multi-factor authentication.

View Official Regulatory Filing Document https://www.sec.gov/Archives/edgar/data/1640147/000164014724000042/0001640147-24-000042-index.htm

Technical Forensic Briefing

Incident Overview

The Snowflake cybersecurity event represents a confirmed Credential Stuffing / Cloud Account Takeover within the Technology sector, attributed to the UNC5537 cyber threat collective. Discovered through technical indicators and regulatory breach filings, the event resulted in unauthorized access to sensitive internal IT environments, impacting approximately 165,000,000 individuals and records.

Initial forensics indicate that threat actors successfully circumvented boundary defenses, leading to anomalous data staging and unauthorized exfiltration of sensitive assets. Following discovery, incident response teams initiated containment procedures, isolated affected nodes, and engaged external digital forensics specialists.

Compromised Assets & Data Scope

Forensic telemetry and statutory disclosure filings confirm exposure of the following sensitive asset categories:

  • Primary Data Classes: Corporate Customer Data Warehouses, Authentication Credentials, Client Database Backups.
  • Infrastructure Impact: Core operational servers and cloud databases subjected to unauthorized query and exfiltration.
  • Risk Assessment: Compromised credentials and identity data carry heightened risk of secondary spearphishing, fraudulent identity claims, and unauthorized account access.

Statutory Disclosures & Compliance

  • U.S. Securities and Exchange Commission (SEC) (Form 8-K (Item 8.01 Other Events - Customer Cybersecurity Disclosures)): Official regulatory filing under accession/tracking ID 0001640147-24-000042 (Filed: 2024-06-03). Form 8-K filing regarding customer account security disclosures detailing threat actor credential stuffing against customer demo environments lacking multi-factor authentication. Direct Document Link: Form 8-K (Item 8.01 Other Events - Customer Cybersecurity Disclosures)

Milestone Timeline (2 events logged)

2026-08-06 17:00 UTC
INDEPENDENT VERIFICATION

Canadian Man Pleads Guilty in Snowflake Extortions

2026-10-06 16:33 UTC
CONFIRMED BY TARGET

ASOS confirms data breach after “HACKED” in-app notifications

Have updated information or a new verifiable source?

This incident record is a flat Markdown file tracked in Git. Propose an update or add a milestone via Pull Request.

Propose Update via GitHub