Skip to main content

SnowflakeSnowflake announced MFA-by-default policy for new accounts following 2024 breach disclosures

In October 2024, following sustained criticism over the UNC5537 mass breach chain, Snowflake announced it would require multi-factor authentication by default for newly-created accounts and would deprecate password-only logins for new admin accounts by 2025. CISO Brad Jones acknowledged the company's product defaults had been a contributing factor to the breach and the company committed to additional secure-by-default investments. The change took effect for new accounts in early 2025.

Scoring Impact

TopicDirectionRelevanceContribution
Corporate Transparency+towardsecondary+0.50
Data Security+towardprimary+1.00
Infrastructure Accountability+towardprimary+1.00
Overall incident score =+0.357

Score = avg(topic contributions) × significance (medium ×1) × confidence (0.57)× agency (reactive ×0.75)

Evidence (1 signal)

Confirms Policy Change Oct 8, 2024 documented

Snowflake CISO Brad Jones announced MFA-by-default for new accounts after 2024 breach disclosures

Snowflake's October 8, 2024 security blog from CISO Brad Jones announced MFA-by-default for new accounts and deprecation of password-only admin logins by 2025, acknowledging product-default contributions to the UNC5537 breach.

Related: Same Topics