/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A website for cybercriminals lists 500+ allegedly stolen Snowflake customer credentials, including for environments belonging to Santander and Ticketmaster

Cloud data analysis company Snowflake is at the center of a recent spate of alleged data thefts, as its corporate customers scramble …

TechCrunch Zack Whittaker

Context & Ripple Effects

Earlier reporting tied alleged compromises at Ticketmaster and Santander to stolen Snowflake credentials, a claim Snowflake disputed. The new listing broadens the issue from a small set of alleged victim incidents to a potentially wider customer-access exposure.

That matters because credentials can provide a path into multiple customer environments without requiring a separate intrusion at each company. The story therefore centers identity controls and customer-environment access, not just the security of a single dataset.

First-order effects

  • Snowflake customers whose environments may appear in the listing face an immediate need to validate access, rotate exposed credentials, and review account activity; Santander and Ticketmaster are among the named organizations.
  • Snowflake faces heightened pressure to investigate the alleged credential source and help customers determine whether listed access was valid or already used.

Second-order effects

  • Enterprise customers using shared cloud data platforms are likely to scrutinize authentication, credential rotation, and monitoring responsibilities more closely, increasing demand for incident-response work and identity-security controls.
  • The risk shifts from a reputational problem for one provider to a customer-containment problem; later extortion reports involving Snowflake customers show how alleged access can translate into commercial and operational pressure.

Third-order effects

  • If similar campaigns persist, cloud-data customers will treat identity compromise as a platform-level concentration risk, pushing providers and buyers toward stronger access segmentation and more explicit shared-security accountability.
  • The episode suggests that attackers can monetize access across many customer environments, making credential hygiene and detection a more durable competitive requirement for cloud data platforms.

The trend: Cloud-security risk is increasingly concentrating around identity access, where one compromised credential can expose multiple organizations that share a platform.

Discussion

  • @tomgorup Tom Gorup on threads
    Single-Factor Auth is Dead.  Long Live MFA/Passkeys.  Snowflake Inc. has been in the news for a major data breach reported by Ticketmaster, Santander bank, and several others.  This event is being called the “world's largest data breach” by some, but is it “a” breach? …
  • @zackwhittaker@mastodon.social Zack Whittaker on mastodon
    We've seen over 500 stolen credentials containing Snowflake customer usernames, passwords, and the login pages for the corresponding Snowflake environments.  —  The credentials relate to employees at Ticketmaster and Santander, and others One set of exposed credentials appear to …
  • @h4ckmanac @h4ckmanac on x
    🚨 #BREAKING 🚨 🇺🇸#USA: Hundreds of millions of Advance Auto Parts records allegedly exfiltrated: The threat actor claims to be selling for $1.5 million 3 terabytes stolen from AAP Snowflake. According to the post, the data includes: - 380 million customer profiles (name, [image]
  • @laurenbalik Lauren Balik on x
    Update on Snowflake $SNOW cybersecurity situation. — I've now spoken directly with 5 founders/execs at 5 different orgs who had their Snowflake accounts breached in the past month or two. 1) In each case there was an extreme and quick uptick in Snowflake credit burn as the
  • @gossithedog Kevin Beaumont on x
    [video]
  • @ejcx_ Evan J on x
    This is spicy but very good takes If you're the security team for a SaaS company, your customer's accounts are assets you have to protect whether you think that's fair or not. Big platforms (okta last year, snow, and everything similar) need to step up D&R / account security
  • @troyhunt Troy Hunt on x
    Another breach claimed to have been sourced from Snowflake:
  • @gossithedog Kevin Beaumont on x
    The Snowflake fallout continues - TechCrunch report over 500 orgs have credentials readily available https://techcrunch.com/... [image]
  • @lorenzofb Lorenzo Franceschi-Bicchierai on x
    NEW: Cloud giant Snowflake is at the center of a recent spate of alleged data thefts, including Ticketmaster. TechCrunch has seen hundreds of alleged Snowflake customer passwords available online for hackers to use, suggesting there's more to come https://techcrunch.com/...
  • r/technology r on reddit
    The Snowflake Attack May Be Turning Into One of the Largest Data Breaches Ever