Executive Summary

In 2024, threat actor Connor Moucka and accomplices exploited valid but compromised Snowflake customer credentials to breach over 165 organizations, stealing billions of records including AT&T's wireless customer data. The attackers used years-old, unrotated passwords without multi-factor authentication to access Snowflake environments. Moucka pleaded guilty in August 2024 to computer fraud, wire fraud, and conspiracy charges. In response, Snowflake implemented a phased authentication rollout through 2026, culminating in the complete deprecation of password-based service accounts by October 2026.

This incident highlights the growing threat landscape around identity-based attacks and the critical need for robust non-human identity management as organizations increasingly deploy AI agents and automated systems that require programmatic access to cloud platforms.

Why This Matters Now

Organizations face mounting pressure to secure non-human identities as AI agents and automated systems proliferate, making legacy service account management a critical attack vector that demands immediate attention and systematic remediation.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Attackers used valid but compromised customer credentials, many years old without multi-factor authentication, to access over 165 Snowflake customer organizations and steal billions of records.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have constrained the Snowflake breach by implementing segmentation controls and east-west traffic enforcement that could have limited lateral movement across customer organizations. The controlled egress policies would likely have reduced the scope of data exfiltration from compromised Snowflake environments.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: CNSF visibility controls would likely have detected abnormal authentication patterns and credential usage from unexpected geographical locations or network segments accessing Snowflake infrastructure.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero Trust segmentation policies would likely have constrained service account access scope and limited privilege escalation by enforcing identity-based access controls around sensitive Snowflake data repositories.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic enforcement would likely have constrained lateral movement between customer organizations by blocking unauthorized inter-tenant communications and restricting cross-organizational data access paths.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Centralized visibility controls would likely have detected persistent session anomalies and provided security teams with comprehensive monitoring of attacker activities across multiple customer environments simultaneously.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress security policies would likely have constrained large-scale data extraction by enforcing data loss prevention rules and limiting outbound transfer volumes from Snowflake environments to external destinations.

Impact (Mitigations)

While customer data exposure would still have occurred, the overall business impact would likely have been reduced through constrained lateral movement and limited data exfiltration scope across fewer customer organizations.

Impact at a Glance

Affected Business Functions

  • Data Analytics and Business Intelligence
  • Customer Data Management
  • Cloud Data Warehousing
  • Enterprise Reporting Systems
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Billions of records stolen from 165+ Snowflake customer organizations including call and text records of nearly all AT&T wireless customers, customer PII, business intelligence data, and enterprise analytics datasets. At least 79.7% of compromised accounts had prior credential exposure dating back to November 2020.

Recommended Actions

  • Implement Zero Trust Segmentation with identity-based policies to prevent lateral movement between customer environments and enforce least privilege access controls
  • Deploy Egress Security & Policy Enforcement to monitor and control data exfiltration attempts, blocking unauthorized data exports to external destinations
  • Establish Multicloud Visibility & Control with centralized policy management to detect anomalous authentication patterns and suspicious data access behaviors across all Snowflake instances
  • Enforce Threat Detection & Anomaly Response capabilities to baseline normal service account behavior and alert on credential reuse or access from unexpected locations
  • Mandate service account lifecycle management with automated rotation, owner assignment, and network policy restrictions to prevent long-lived credential exposure

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image