logo

Hundreds of Snowflake customer passwords found online are linked to info-stealing malware

ID: 271e849f-2b75-5bef-bbdb-af3976fd0ff8

STIX ID: report--271e849f-2b75-5bef-bbdb-af3976fd0ff8

Feed Name: TechCrunch Security News

Threat Score
78/100

Date Published: 2024-06-05

Date Updated: 2026-04-23

Author: Zack Whittaker

...
...

A TechCrunch investigation details alleged compromises of multiple Snowflake customer accounts where infostealer malware reportedly stole employee Snowflake credentials (username/password and custom login URLs). Attackers published hundreds of credentials tied to organizations including Ticketmaster and Santander; lack of enforced MFA on customer accounts is presented as the primary enabler. Snowflake acknowledges potential unauthorized access to a limited number of accounts, urges customers to enable MFA, and says it has found no evidence of a direct breach of Snowflake infrastructure, while investigators did not test credentials directly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.