TechNewsReel
Live

Stolen Credentials and Missing MFA Fueled Massive Snowflake Data Theft

A 2024 campaign exposed hundreds of millions of records after attackers exploited customer accounts lacking multi-factor authentication.

TechNewsReel Newsroom · August 6, 2026

A widespread cyber campaign in mid-2024 targeted customers of the Snowflake cloud data platform, resulting in the theft of massive datasets from several high-profile global organizations. The intrusions highlight a critical failure in identity management across the enterprise SaaS ecosystem.

According to reports from Hedgehog Security and Rescana, the attackers did not breach Snowflake's own core systems. Instead, they utilized stolen credentials—likely harvested via infostealer malware—to gain unauthorized access to customer accounts. The primary vulnerability was the absence of multi-factor authentication (MFA) on these accounts, allowing threat actors to enter the environment using only a username and password.

The Scale of Exposure

The impact of the campaign was vast, with approximately 165 organizations confirmed to have had their Snowflake tenants accessed without authorization. The resulting data loss affected some of the world's largest companies. Ticketmaster saw the data of approximately 560 million customers compromised, while AT&T lost roughly 110 million call and text records. Additionally, Santander reported the exposure of approximately 30 million customers.

The SaaS Security Gap

This incident reflects a broader trend in cybersecurity where threat actors target the "connective tissue" of the cloud—integrations and platform access—rather than attempting to break the core infrastructure of the service provider. By focusing on the weakest link in the chain, attackers can bypass sophisticated platform security by simply impersonating a legitimate user. The reliance on single-factor authentication for high-privilege administrative accounts created a systemic vulnerability that automated tools could easily exploit once credentials were leaked.

The Shared Responsibility Model

The Snowflake intrusions underscore the "shared responsibility model" of cloud security. While a provider like Snowflake may maintain a secure environment, the ultimate security of the data depends on the customer's implementation of identity controls. The catastrophic loss of hundreds of millions of records across diverse sectors demonstrates that the failure to mandate MFA in enterprise environments is no longer a minor oversight, but a critical business risk.

The Path Forward

Industry analysts continue to monitor the full extent of the fallout as affected organizations work to notify users and secure their environments. While the primary vector—stolen credentials—is understood, the long-term implications for data privacy litigation and the push for mandatory MFA across all SaaS platforms remain the primary focus for security professionals. This campaign serves as a stark reminder that the most advanced cloud infrastructure is only as secure as the credentials used to access it.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.