RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The incident desk · 100 retrospective records ↗

The incident desk / Incident

Incident / From the archive · 22 May 2024 event · prepared 16 September 2026

Old infostealer logins opened Snowflake accounts that lacked MFA

Mandiant's investigation and Live Nation's own filing trace the 2024 campaign to credentials, not a platform breach.

Visual for this record: Old infostealer logins opened Snowflake accounts that lacked MFA
Visual published by raw.githubusercontent.com, shown for identification of the record. Credit: raw.githubusercontent.com · source page ↗ Rights: owner-review-pending.

What happened

Beginning in April 2024, Mandiant, part of Google Cloud, identified a pattern of unauthorized access to customer accounts on the Snowflake cloud data platform. Its published analysis attributes the activity to a financially motivated cluster it tracks as UNC5537 and states that the access relied on customer credentials previously stolen by infostealer malware, including several well-known families, some of which had been circulating since November 2020 and remained valid, unrotated, for as long as four years. Mandiant reports that none of the affected accounts had multi-factor authentication enabled and that Snowflake had, by design, allowed customers to configure network access controls that in these cases were not applied. By 22 May 2024, Mandiant had notified Snowflake of the broader pattern and began notifying roughly 165 potentially affected organizations.

One of those organizations was Live Nation Entertainment. Its own filing with the Securities and Exchange Commission states that on 20 May 2024 it identified unauthorized activity within a third-party cloud database environment, primarily affecting its Ticketmaster subsidiary, and that a threat actor later offered the data for sale. The filing describes the company notifying law enforcement and beginning regulatory and user notifications.

Confidence and limits

Mandiant's report and Live Nation's own securities disclosure are independent primary accounts that describe the same underlying pattern: credential theft unrelated to Snowflake's own systems, compounded by the absence of multi-factor authentication on the affected accounts. Mandiant's cluster attribution to UNC5537 is the firm's own analytic judgment, not a criminal court finding, and the documents reviewed here do not name or describe the outcome for any individual alleged to be responsible.

Why it mattered

The campaign showed that a cloud platform can be functionally sound while remaining exposed through customer-side authentication gaps, since Snowflake's own controls, including MFA and network policies, existed but were not required by default at the time. Because credentials can remain valid for years after an initial infostealer infection with no reuse by the account owner, a security posture that relies on the assumption that old, unused credentials are harmless is not supported by this case.

Defensive takeaway

Enforce multi-factor authentication and network allow-listing on every account with access to shared cloud data platforms as a default, not an opt-in, and periodically rotate or revoke credentials tied to accounts that have not authenticated recently.

  • Can we confirm that multi-factor authentication is enforced, not merely enabled, for every account with access to our cloud data platforms?
  • Do we have a process to detect and rotate credentials that appear in infostealer or credential-dump intelligence feeds, even years after they were reported?
  • Have we reviewed our cloud vendor's default security posture against what it recommends as a best practice, since the two are not always the same?

Snowflake's own documentation, current as retrieved 16 September 2026, records that accounts created after a 2024 policy change require multi-factor enrollment by default for password-based sign-in, a shift that, whatever its stated rationale, addresses precisely the gap this campaign exploited.

Defensive takeaway

Confirm multi-factor authentication and network allow-listing are enforced, not merely available, on every account with access to a cloud data platform, including accounts your own team rarely uses.

Mandiant's investigation and Live Nation's own securities filing independently describe the credential-based access pattern; Mandiant's attribution of the activity to a single cluster, tracked as UNC5537, is the investigating firm's assessment rather than a court finding, and no criminal charges are described in the primary documents reviewed here.

Sources & reading trail

UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion ↗

Documents that infostealer-sourced credentials, some unrotated for years, were used to access Snowflake accounts lacking MFA and network allow-lists, affecting roughly 165 organizations.

vendor-primary · Source published: 10 June 2024 · Retrieved: 16 September 2026

Live Nation Entertainment, Inc. Form 8-K (Item 8.01, filed 23 May 2024) ↗

States Live Nation identified unauthorized activity in a third-party cloud database environment affecting its Ticketmaster subsidiary on 20 May 2024 and notified law enforcement and regulators.

company-primary · Source published: 23 May 2024 · Retrieved: 16 September 2026

Multi-Factor Authentication (MFA) documentation ↗

Records, as retrieved 16 September 2026, that accounts created after the 2024_08 behavior change bundle require MFA enrollment by default for password sign-in.

vendor-primary · Source published: Not established · Retrieved: 16 September 2026

Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.