Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

Hackers Exploit Weak MFA on Snowflake Accounts, Steal Data from 165 Organizations and Extort Millions

Between February and October 2024, a Canadian cyber‑criminal group accessed Snowflake customer accounts without MFA, exfiltrated data from at least 165 organizations, and extorted over $2.5 million. The breach underscores the need for enforceable access‑control policies and continuous evidence collection for audit readiness.

LiveThreat™ Intelligence · 📅 September 17, 2026· 📰 krebsonsecurity.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
4 sector(s)
✅
Actions
3 recommended
📰
Source
krebsonsecurity.com

Hackers Exploit Weak MFA on Snowflake Accounts, Steal Data from 165 Organizations and Extort Millions

What Happened — Between February and October 2024, a Canadian cyber‑criminal group used stolen login credentials to access Snowflake customer accounts that lacked multi‑factor authentication. The attackers exfiltrated data from at least 165 SaaS customers—including call‑detail records, financial information, and government IDs—and demanded ransom, collecting over $2.5 million.

Why It Matters for Trust & Control Assurance

  • The incident demonstrates how a missing MFA control can become the single point of failure that a continuous control‑assurance program is built to detect and remediate.
  • Evidence of MFA enforcement, password‑complexity policies, and regular access‑review logs provides a defensible audit trail across frameworks.
  • Verisq’s Access Controls capability helps organizations capture, monitor, and report on these controls in real time, turning a reactive fix into proactive assurance.

Who Is Affected – SaaS providers, financial‑services firms, retail merchants, telecommunications carriers, and any organization that stores data in Snowflake.

Recommended Actions –

  • Enforce MFA on all privileged and service‑account logins immediately.
  • Harden password policies to meet industry‑recommended complexity and rotation standards.
  • Implement continuous monitoring of credential usage and generate immutable evidence for audit readiness.

Technical Notes – Attack vector: stolen credentials (phishing or credential‑dump purchases). No public vulnerability disclosed; the weakness was the lack of MFA enforcement on Snowflake accounts. Source: Krebs on Security

📰 Original Source
https://krebsonsecurity.com/2026/08/canadian-man-pleads-guilty-in-snowflake-extortions/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Could you prove your access controls held up here?

Credential and access failures map directly to identity and access-control requirements in every major framework. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →