LIVE
UTC --:--:--
OT SECURITY HUB
by zuckergates
// INCIDENT · 2024

Snowflake Credential Attacks (UNC5537)

Kampanye besar penyalahgunaan kredensial Snowflake tanpa MFA — memicu wajib MFA platform.

criticalGlobalMultiUNC5537
Impact
~165 pelanggan terdampak: Ticketmaster (560 jt), Santander, AT&T (109 jt), LendingTree, Advance Auto.
Initial vector
Stolen credentials infostealer → Snowflake tenants
Lessons learned
  • MFA wajib SaaS data warehouse
  • Rotasi kredensial pasca-infostealer
  • Network policy IP allowlist