logo

Snowflake ends service-account passwords. Now comes the hard part

ID: 05b7fb64-370c-583c-b3b2-e816ac1eeb32

STIX ID: report--05b7fb64-370c-583c-b3b2-e816ac1eeb32

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-08-26

Date Updated: 2026-08-26

Author: Sponsored by Token Security

...
...

The report details a large credential-based compromise in which Connor Moucka and co-conspirators used valid, often years-old credentials to access over 165 Snowflake customer accounts and exfiltrate billions of records (including AT&T call/text logs). It reviews Snowflake’s phased deprecation of passworded legacy service accounts, outlines operational remediation steps—inventorying service accounts, assigning named owners, selecting per-account passwordless methods, and treating replaced passwords as compromised—and highlights governance failures that enable such large-scale breaches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.