A website for cybercriminals lists 500+ allegedly stolen Snowflake customer credentials, including for environments belonging to Santander and Ticketmaster
Cloud data analysis company Snowflake is at the center of a recent spate of alleged data thefts, as its corporate customers scramble …
TechCrunchZack Whittaker
Context & Ripple Effects
Earlier reporting tied alleged compromises at Ticketmaster and Santander to stolen Snowflake credentials, a claim Snowflake disputed. The new listing broadens the issue from a small set of alleged victim incidents to a potentially wider customer-access exposure.
That matters because credentials can provide a path into multiple customer environments without requiring a separate intrusion at each company. The story therefore centers identity controls and customer-environment access, not just the security of a single dataset.
First-order effects
Snowflake customers whose environments may appear in the listing face an immediate need to validate access, rotate exposed credentials, and review account activity; Santander and Ticketmaster are among the named organizations.
Snowflake faces heightened pressure to investigate the alleged credential source and help customers determine whether listed access was valid or already used.
Second-order effects
Enterprise customers using shared cloud data platforms are likely to scrutinize authentication, credential rotation, and monitoring responsibilities more closely, increasing demand for incident-response work and identity-security controls.
The risk shifts from a reputational problem for one provider to a customer-containment problem; later extortion reports involving Snowflake customers show how alleged access can translate into commercial and operational pressure.
Third-order effects
If similar campaigns persist, cloud-data customers will treat identity compromise as a platform-level concentration risk, pushing providers and buyers toward stronger access segmentation and more explicit shared-security accountability.
The episode suggests that attackers can monetize access across many customer environments, making credential hygiene and detection a more durable competitive requirement for cloud data platforms.
The trend: Cloud-security risk is increasingly concentrating around identity access, where one compromised credential can expose multiple organizations that share a platform.
Single-Factor Auth is Dead. Long Live MFA/Passkeys. Snowflake Inc. has been in the news for a major data breach reported by Ticketmaster, Santander bank, and several others. This event is being called the “world's largest data breach” by some, but is it “a” breach? …
We've seen over 500 stolen credentials containing Snowflake customer usernames, passwords, and the login pages for the corresponding Snowflake environments. — The credentials relate to employees at Ticketmaster and Santander, and others One set of exposed credentials appear to …
🚨 #BREAKING 🚨 🇺🇸#USA: Hundreds of millions of Advance Auto Parts records allegedly exfiltrated: The threat actor claims to be selling for $1.5 million 3 terabytes stolen from AAP Snowflake. According to the post, the data includes: - 380 million customer profiles (name, [image]
Update on Snowflake $SNOW cybersecurity situation. — I've now spoken directly with 5 founders/execs at 5 different orgs who had their Snowflake accounts breached in the past month or two. 1) In each case there was an extreme and quick uptick in Snowflake credit burn as the
This is spicy but very good takes If you're the security team for a SaaS company, your customer's accounts are assets you have to protect whether you think that's fair or not. Big platforms (okta last year, snow, and everything similar) need to step up D&R / account security
NEW: Cloud giant Snowflake is at the center of a recent spate of alleged data thefts, including Ticketmaster. TechCrunch has seen hundreds of alleged Snowflake customer passwords available online for hackers to use, suggesting there's more to come https://techcrunch.com/...