Executive Summary
In 2024, threat actor Connor Moucka and accomplices exploited valid but compromised Snowflake customer credentials to breach over 165 organizations, stealing billions of records including AT&T's wireless customer data. The attackers used years-old, unrotated passwords without multi-factor authentication to access Snowflake environments. Moucka pleaded guilty in August 2024 to computer fraud, wire fraud, and conspiracy charges. In response, Snowflake implemented a phased authentication rollout through 2026, culminating in the complete deprecation of password-based service accounts by October 2026.
This incident highlights the growing threat landscape around identity-based attacks and the critical need for robust non-human identity management as organizations increasingly deploy AI agents and automated systems that require programmatic access to cloud platforms.
Why This Matters Now
Organizations face mounting pressure to secure non-human identities as AI agents and automated systems proliferate, making legacy service account management a critical attack vector that demands immediate attention and systematic remediation.
Attack Path Analysis
Attackers obtained valid but exposed Snowflake service account credentials through infostealers, some dating back years. They used these credentials without MFA to authenticate directly to Snowflake instances, escalated privileges within the platform, moved laterally across 165+ customer organizations, established persistent access, and exfiltrated billions of records including AT&T customer data before causing significant business impact through data theft and extortion.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers acquired valid Snowflake service account credentials through infostealer malware, with some passwords exposed as early as November 2020 but remaining valid for years without rotation
MITRE ATT&CK® Techniques
Valid Accounts
Valid Accounts: Cloud Accounts
Unsecured Credentials: Credentials In Files
Brute Force
Data from Cloud Storage
Exfiltration Over Web Service: Exfiltration to Cloud Storage
Domain Policy Modification
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Multi-Factor Authentication for All Access
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – ICT Risk Management Framework
Control ID: Article 8
CISA ZTMM 2.0 – Asset Management for Identities
Control ID: Identity.AM-1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21.2(a)
ISO 27001:2022 – User Registration and Deregistration
Control ID: A.9.2.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Snowflake credential theft exposes massive IT infrastructure vulnerabilities requiring immediate service account migration, multi-factor authentication, and zero trust segmentation implementation.
Telecommunications
AT&T breach demonstrates telecommunications sector's critical exposure to credential theft attacks targeting customer communication records through cloud data platforms like Snowflake.
Financial Services
Legacy service accounts in financial institutions face severe compliance violations under PCI and regulatory frameworks, requiring immediate passwordless authentication migration.
Health Care / Life Sciences
Healthcare organizations using Snowflake face HIPAA compliance breaches from credential theft, necessitating encrypted traffic controls and identity-based access policies.
Sources
- Snowflake ends service-account passwords. Now comes the hard parthttps://www.bleepingcomputer.com/news/security/snowflake-ends-service-account-passwords-now-comes-the-hard-part/Verified
- Canadian pleads guilty to Snowflake cloud data theft attackshttps://www.bleepingcomputer.com/news/security/canadian-pleads-guilty-to-snowflake-cloud-data-theft-attacks/Verified
- UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortionhttps://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortionVerified
- Snowflake MFA Rollout Documentationhttps://docs.snowflake.com/en/user-guide/security-mfa-rolloutVerified
- Snowflake Authentication Security Updateshttps://community.snowflake.com/s/article/Snowflake-Authentication-Security-UpdatesVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have constrained the Snowflake breach by implementing segmentation controls and east-west traffic enforcement that could have limited lateral movement across customer organizations. The controlled egress policies would likely have reduced the scope of data exfiltration from compromised Snowflake environments.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: CNSF visibility controls would likely have detected abnormal authentication patterns and credential usage from unexpected geographical locations or network segments accessing Snowflake infrastructure.
Control: Zero Trust Segmentation
Mitigation: Zero Trust segmentation policies would likely have constrained service account access scope and limited privilege escalation by enforcing identity-based access controls around sensitive Snowflake data repositories.
Control: East-West Traffic Security
Mitigation: East-west traffic enforcement would likely have constrained lateral movement between customer organizations by blocking unauthorized inter-tenant communications and restricting cross-organizational data access paths.
Control: Multicloud Visibility & Control
Mitigation: Centralized visibility controls would likely have detected persistent session anomalies and provided security teams with comprehensive monitoring of attacker activities across multiple customer environments simultaneously.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security policies would likely have constrained large-scale data extraction by enforcing data loss prevention rules and limiting outbound transfer volumes from Snowflake environments to external destinations.
While customer data exposure would still have occurred, the overall business impact would likely have been reduced through constrained lateral movement and limited data exfiltration scope across fewer customer organizations.
Impact at a Glance
Affected Business Functions
- Data Analytics and Business Intelligence
- Customer Data Management
- Cloud Data Warehousing
- Enterprise Reporting Systems
Estimated downtime: N/A
Estimated loss: N/A
Billions of records stolen from 165+ Snowflake customer organizations including call and text records of nearly all AT&T wireless customers, customer PII, business intelligence data, and enterprise analytics datasets. At least 79.7% of compromised accounts had prior credential exposure dating back to November 2020.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies to prevent lateral movement between customer environments and enforce least privilege access controls
- • Deploy Egress Security & Policy Enforcement to monitor and control data exfiltration attempts, blocking unauthorized data exports to external destinations
- • Establish Multicloud Visibility & Control with centralized policy management to detect anomalous authentication patterns and suspicious data access behaviors across all Snowflake instances
- • Enforce Threat Detection & Anomaly Response capabilities to baseline normal service account behavior and alert on credential reuse or access from unexpected locations
- • Mandate service account lifecycle management with automated rotation, owner assignment, and network policy restrictions to prevent long-lived credential exposure



