Skip to main content
company

Snowflake

Cloud-based data warehousing and analytics platform; NYSE-listed (SNOW). Central to the 2024 mass-breach incident chain that compromised Ticketmaster, Santander, AT&T and others via stolen Snowflake customer credentials.

Track Record

reactive

In October 2024, following sustained criticism over the UNC5537 mass breach chain, Snowflake announced it would require multi-factor authentication by default for newly-created accounts and would deprecate password-only logins for new admin accounts by 2025. CISO Brad Jones acknowledged the company's product defaults had been a contributing factor to the breach and the company committed to additional secure-by-default investments. The change took effect for new accounts in early 2025.

negligent

Beginning in April 2024, threat actor UNC5537 used credentials stolen via prior infostealer malware to access approximately 165 Snowflake customer tenants that lacked multi-factor authentication, exfiltrating hundreds of millions of records belonging to downstream customers including Ticketmaster (560M records), Santander, AT&T (~110M wireless customers), Advance Auto Parts, LendingTree, Neiman Marcus, and others. Snowflake initially attributed responsibility to customer credential management while critics noted Snowflake's product defaults did not require MFA. Snowflake later enabled MFA-by-default policies for new accounts.