A website for cybercriminals lists 500+ allegedly stolen Snowflake customer credentials, including for environments belonging to Santander and Ticketmaster
The credentials relate to employees at Ticketmaster and Santander, and others One set of exposed credentials appear to belong to a former Snowflake employee. … X: @h4ckmanac : 🚨 #BREAKING 🚨 🇺🇸#USA: Hundreds of millions of Advance Auto Parts records allegedly exfiltrated: The threat actor claims to be selling for $1.5 million 3 terabytes stolen from AAP Snowflake. According to the post, the data includes: - 380 million customer profiles (name, [image] Evan J / @ejcx_ : This is spicy but very good takes If you're the security team for a SaaS company, your customer's accounts are assets you have to protect whether you think that's fair or not. Big platforms (okta last year, snow, and everything similar) need to step up D&R / account security Lauren Balik / @laurenbalik : Update on Snowflake $SNOW cybersecurity situation. — I've now spoken directly with 5 founders/execs at 5 different orgs who had their Snowflake accounts breached in the past month or two. 1) In each case there was an extreme and quick uptick in Snowflake credit burn as the Troy Hunt / @troyhunt : Another breach claimed to have been sourced from Snowflake: Kevin Beaumont / @gossithedog : [video] Lorenzo Franceschi-Bicchierai / @lorenzofb : NEW: Cloud giant Snowflake is at the center of a recent spate of alleged data thefts, including Ticketmaster. TechCrunch has seen hundreds of alleged Snowflake customer passwords available online for hackers to use, suggesting there's more to come https://techcrunch.com/... Kevin Beaumont / @gossithedog : The Snowflake fallout continues - TechCrunch report over 500 orgs have credentials readily available https://techcrunch.com/... [image] LinkedIn: Ronan Murphy : This current spate of cyber attacks targeting major companies such as, LendingTree, Santander, and Ticketmaster have highlighted the critical vulnerabilities in current data security practices. … Matthew Venne : This Snowflake breach is once again proof that 99% of hacks are NOT due to some clever tactic. It's because organizations the world over STILL do not employ the MOST basic security principles. … Stanley Tsang : A recent data breach has targeted customers of cloud storage company Snowflake. Hackers are using stolen login credentials to access customer accounts, and the scale of the breach is still unknown. … Robert Fernandes : A hack against customers of the cloud storage company Snowflake looks like it may turn into one of the biggest-ever data breaches. … Scott Jarkoff : 日本語は英語の後に.きます ... There is no justification for not enabling MFA/2FA/2SV beyond sheer negligence. … Forums: r/technology : The Snowflake Attack May Be Turning Into One of the Largest Data Breaches Ever
Context & Ripple Effects
Earlier reporting tied the alleged Ticketmaster and Santander intrusions to stolen Snowflake employee credentials; this report makes the exposure more concrete by describing a broad set of purported customer logins available to criminals. The key issue is not merely a single customer breach, but whether credentials can be reused across multiple cloud data environments.
The incident’s significance grew as later coverage connected additional affected customers to the same campaign and described ransom demands against breached Snowflake customers. That arc turns identity and access controls into a central test of platform trust.
First-order effects
- Organizations whose credentials appear in the listing face an immediate need to validate exposure, revoke or rotate affected access, and review activity in their Snowflake environments.
- Snowflake must coordinate investigation and customer notification around a campaign that includes accounts apparently associated with a former employee, while named customers face potential data-access and incident-response costs.
Second-order effects
- A publicly available credential set gives attackers a target list for follow-on account access and data-theft attempts, raising the urgency for customers beyond those already associated with the earlier claims of Ticketmaster and Santander intrusions.
- The campaign increases pressure on SaaS customers to scrutinize identity controls and anomalous consumption; the reported extreme spikes in Snowflake credit use show that account misuse can create operational as well as data-loss exposure.
Third-order effects
- If credential-led compromises continue to span many tenants, cloud-data platforms will be judged less on infrastructure security alone and more on how effectively they make identity, monitoring, and customer response a shared operational boundary.
- The episode points toward platform trust becoming a commercial and governance issue: customers may demand clearer responsibility for credential protection, detection, and breach coordination, though the scope of the alleged credential set remains unverified.
The trend: Cloud-data security is shifting from perimeter protection toward identity resilience and shared accountability across SaaS platforms and their customers.