Mandiant, a leading cybersecurity firm, investigated the Snowflake breaches alongside Snowflake. They identified the threat actor as UNC5537 and traced the attacks to infostealer-harvested credentials. Mandiant's analysis highlighted the lack of sophisticated techniques, emphasizing the role of credential hygiene.