Snowflake confirms that the data breach at AT&T is connected to the hack that has affected other customers, including Ticketmaster and LendingTree
- Fallout from attack disclosed in May is still spreading — Ticketmaster, LendingTree among recent victims in crime spree
Context & Ripple Effects
The incident evolved from early claims involving Ticketmaster and Santander, which Snowflake initially countered alongside CrowdStrike and Mandiant by saying they had found no evidence of a platform breach. The subsequent appearance of hundreds of allegedly stolen customer credentials made customer-environment access the central issue.
This confirmation connects AT&T to an episode already associated with Ticketmaster and LendingTree, turning what had appeared to be separate disclosures into a shared security event. AT&T’s planned customer notification over stolen phone records underscores the scale of the downstream exposure.
First-order effects
- AT&T, Ticketmaster and LendingTree now face the immediate operational and reputational consequences of being tied to the same intrusion campaign, rather than isolated incidents.
- Snowflake must manage customer assurance around access controls and incident attribution after its earlier statement that found no evidence of a platform breach.
Second-order effects
- Other Snowflake customers have a clearer reason to review credentials, access paths and unusual activity in their own environments, even where no compromise has been disclosed.
- Security providers and enterprise buyers will put greater weight on the boundary between a cloud platform compromise and misuse of customer credentials, because that distinction determines who owns remediation and liability.
Third-order effects
- The episode points to cloud-data risk becoming more concentrated around identity and credential security: one compromised access path can create a multi-company incident without establishing that the shared platform itself was breached.
- If similar cases persist, large cloud customers may demand more demonstrable identity controls and incident transparency from both platform vendors and their own security teams.
The trend: Enterprise cloud breaches are increasingly being assessed as identity-driven, cross-customer blast-radius events rather than solely as failures of a shared platform.