A Google threat analyst says the hacker behind the Snowflake breach recently broke into a “handful” of new orgs and is likely a male based in Canada in his 20s
Cyber investigators are tracking alleged scammer in connection with a string of compromises
Context & Ripple Effects
The reported follow-on compromises extend a Snowflake-linked incident that had already drawn scrutiny after researchers described claims involving Ticketmaster and Santander and allegedly stolen Snowflake credentials, claims Snowflake disputed.
The story matters because investigators are treating the activity as an ongoing campaign rather than a closed breach. Subsequent coverage tied the case to a Canadian arrest and alleged compromises of as many as 165 Snowflake users, but those later developments were not known at the time of this report.
First-order effects
- The newly affected organizations face an immediate need to investigate possible compromise and contain any active access associated with the tracked actor.
- Google’s public attribution narrows the investigative focus to a suspected Canada-based individual, potentially aiding coordination among victims and authorities without establishing guilt.
Second-order effects
- Organizations that may share credentials, identity providers, or other access paths with affected environments are likely to review authentication logs and privileged access more urgently.
- The expanded activity raises the operational stakes for Snowflake and its customers: incident-response teams must distinguish a continuing actor campaign from isolated customer breaches.
Third-order effects
- If repeated intrusions continue to be linked to a small set of financially motivated actors, cloud-data platforms will face sustained pressure to make identity security and customer-side access monitoring central to their security posture.
- The case also illustrates how threat attribution can turn from a technical containment exercise into cross-border law-enforcement coordination, while public claims remain provisional until independently substantiated.
The trend: Cloud-data breaches are increasingly being treated as identity- and access-driven campaigns that can persist across multiple victim organizations rather than as single, self-contained incidents.