Snowflake Forces Migration Away from Service‑Account Passwords After Credential‑Compromise Breach Affects Hundreds of Customers
What Happened — Attackers leveraged long‑standing, password‑based service accounts in Snowflake to infiltrate more than 165 customer environments, exfiltrating billions of records—including AT&T wireless call and text logs. Snowflake is now deprecating the LEGACY_SERVICE user type and blocking password authentication for all service accounts.
Why It Matters for Compliance & Audit Readiness
- Credential‑stale accounts violate SOC 2 CC6.1 (Logical Access) and CC6.2 (User Access Management) requirements for timely de‑provisioning and MFA.
- The migration forces organizations to inventory non‑human identities, assign owners, and document access—key evidence for continuous‑compliance audits.
- Demonstrating that all service accounts are MFA‑protected or password‑less provides defensible audit trails and reduces the risk of future credential‑based breaches.
Who Is Affected – Cloud data‑platform providers, SaaS vendors, and any organization that integrates Snowflake for analytics or data warehousing (e.g., telecom, finance, health).
Recommended Actions
- Run an immediate inventory of all Snowflake service accounts via the ACCOUNT_USAGE schema.
- Map each account to an owner and document its business purpose.
- Enforce MFA or migrate to password‑less SERVICE type before the October 2026 deadline.
- Capture the inventory and migration evidence in your SOC 2 control logs for audit readiness.
Technical Notes – The breach stemmed from stolen, never‑rotated passwords and lack of MFA on service accounts. No software vulnerability was exploited; the attack vector was stolen credentials. Source: BleepingComputer