In a joint statement, Snowflake, CrowdStrike, and Mandiant say they have not found evidence suggesting Snowflake's platform was breached to hack Ticketmaster
CrowdStrike and Mandiant joined in a statement saying data breaches for Ticketmaster and Santander appear to be ‘targeted attacks.’
Context & Ripple Effects
The statement answers earlier reporting that a threat actor claimed to have accessed Ticketmaster and Santander through stolen Snowflake employee credentials. Its significance is attribution: the companies are separating a possible customer-account compromise from a compromise of Snowflake’s underlying service.
The targeted-attack characterization narrows the immediate investigation toward identity controls and affected customer environments rather than a platform-wide technical failure. That distinction matters to Snowflake customers, whose risk assessments depend on which layer was exposed.
First-order effects
- Snowflake can tell customers and markets that investigators have found no evidence of a platform breach, while Ticketmaster and Santander still face incident response tied to the reported data exposure.
- CrowdStrike and Mandiant’s assessment directs remediation toward compromised credentials and targeted access paths rather than an emergency platform-wide vulnerability fix.
Second-order effects
- Snowflake customers are likely to scrutinize credential management, access monitoring, and account-level protections; later reporting of allegedly stolen Snowflake customer credentials makes that distinction operationally important.
- Security vendors gain a more central role in incident attribution: their findings determine whether customers treat an event as a cloud-provider failure or as a tenant-specific identity breach.
Third-order effects
- If similar incidents continue to originate in customer identities rather than cloud infrastructure, shared-cloud security accountability will increasingly be divided between provider platform controls and each customer’s access governance.
- The episode points toward security assessments that emphasize evidence-based attribution and coordinated disclosure, though the eventual scope of exposure remains dependent on the ongoing investigation.
The trend: Cloud-security incidents are increasingly being framed around the boundary between resilient shared infrastructure and vulnerable customer identities.