Hackers Exploit Weak MFA on Snowflake Accounts, Steal Data from 165 Organizations and Extort Millions
What Happened — Between February and October 2024, a Canadian cyber‑criminal group used stolen login credentials to access Snowflake customer accounts that lacked multi‑factor authentication. The attackers exfiltrated data from at least 165 SaaS customers—including call‑detail records, financial information, and government IDs—and demanded ransom, collecting over $2.5 million.
Why It Matters for Trust & Control Assurance
- The incident demonstrates how a missing MFA control can become the single point of failure that a continuous control‑assurance program is built to detect and remediate.
- Evidence of MFA enforcement, password‑complexity policies, and regular access‑review logs provides a defensible audit trail across frameworks.
- Verisq’s Access Controls capability helps organizations capture, monitor, and report on these controls in real time, turning a reactive fix into proactive assurance.
Who Is Affected – SaaS providers, financial‑services firms, retail merchants, telecommunications carriers, and any organization that stores data in Snowflake.
Recommended Actions –
- Enforce MFA on all privileged and service‑account logins immediately.
- Harden password policies to meet industry‑recommended complexity and rotation standards.
- Implement continuous monitoring of credential usage and generate immutable evidence for audit readiness.
Technical Notes – Attack vector: stolen credentials (phishing or credential‑dump purchases). No public vulnerability disclosed; the weakness was the lack of MFA enforcement on Snowflake accounts. Source: Krebs on Security