Snowflake announced MFA-by-default policy for new accounts following 2024 breach disclosures
Oct 8, 2024In October 2024, following sustained criticism over the UNC5537 mass breach chain, Snowflake announced it would require multi-factor authentication by default for newly-created accounts and would deprecate password-only logins for new admin accounts by 2025. CISO Brad Jones acknowledged the company's product defaults had been a contributing factor to the breach and the company committed to additional secure-by-default investments. The change took effect for new accounts in early 2025.