CYBERSECURITY

The AT&T and Snowflake breach

Credential stuffing at Snowflake in July 2024, including data held for AT&T, and what a business can change.

In July 2024, attackers went after Snowflake, a cloud data-warehouse company, and AT&T was among the organizations affected. Further reporting is at BankInfoSecurity, TechRadar, and Security Week.

What happened

The attackers used credential stuffing: login names and passwords stolen in earlier breaches, tried again on Snowflake. The breach affected hundreds of organizations, including AT&T. The attackers are identified as UNC5537. They stole large amounts of sensitive data and used it to demand ransoms.

Snowflake’s core infrastructure was not compromised. Access came through accounts with weak practices, including demo accounts that did not use multi-factor authentication. The stolen data included personal information and business-sensitive details from several well-known customers.

What about AT&T

Attackers reached sensitive customer information stored in Snowflake’s environment. The specifics of what was taken from AT&T had not been fully disclosed at the time of writing. The attackers demanded ransoms and threatened to leak the data.

What to change

  • Use multi-factor authentication on every account, including accounts that are not production. A stolen password is then much harder to use on its own.
  • Have people change passwords and avoid reusing them. A password manager keeps long, unique passwords, and watching for suspicious logins shows credential stuffing early.
  • Train people on current threats, phishing, safer browsing, and unique passwords.
  • Use tools that watch for unusual activity as it happens. Snowflake worked with Mandiant on threat-hunting guides and recommended mitigations for its users.
  • Write an incident response plan that covers containment, removal, recovery, and how you will talk with the people affected, including customers.

The same class of incident can reach other businesses that rely on cloud services. Geekland IT’s work includes helping businesses stay secure.

Company names

Snowflake, AT&T, and the other company names here are trademarks of their owners. Geekland IT does not claim them. They are named so the incident can be described. That is not an endorsement, and this page does not use their logos.

Back to the blog