Breach Reference
Scan your email →
Data breach reference · April 2024

Were you affected by the Snowflake customer credential-stuffing — AT&T 73M records breach?

Disclosed
Apr 19, 2024
Records affected
73,000,000
Type
Credential theft (UNC5537 / ShinyHunters)
Sector
General SMB

Check if your email appears in this breach.

One-click check against public breach records. No account required.

Takes 60 seconds. We never store your email address.

What happened

Snowflake customer accounts compromised via credential-stuffing with previously-stolen credentials. The attackers (UNC5537 / Scattered Spider / ShinyHunters) did NOT exploit a vulnerability in Snowflake's platform — they used stolen credentials against Snowflake customer accounts that lacked MFA. AT&T was one victim: personally identifiable information including SSNs, dates of birth, account passcodes, names, emails, mailing addresses, and account numbers for ~73 million people (7.6M current customers + 65.4M former). Multiple other Snowflake-customer breaches followed.

Reported impact: AT&T $370K ransom paid; broader customer-cohort impact ongoing

Source: Security.org / CNBC

Common questions about the Snowflake customer credential-stuffing — AT&T 73M records breach

When did the Snowflake customer credential-stuffing — AT&T 73M records breach happen?
The breach was disclosed in April 2024. Public reporting was carried by Security.org / CNBC. The incident is categorized as: Credential theft (UNC5537 / ShinyHunters).
How many people were affected?
Approximately 73000000 records were reported affected. Whether your specific data was among them depends on your relationship with Snowflake customer credential-stuffing — AT&T 73M records during the exposure window.
How do I check if my email was in this breach?
Enter your email in the scan form above. LeakTrace runs a check against known breach records and returns the result in under a minute. No account required.
Is my data still at risk years later?
Yes. Breach data from years past continues to circulate on active infostealer channels and credential-stuffing marketplaces. The passage of time does not neutralize the exposure. Ongoing monitoring catches new exposures as they land instead of only the ones already disclosed publicly.

Other general smb sector breaches