Attacks on Snowflake accounts affect clients such as Ticketmaster and Santander
SANS gathered research on unauthorised access to Snowflake customer environments.

News summary
SANS gathered research on unauthorised access to Snowflake customer environments. Evidence pointed to the use of compromised credentials and accounts without MFA, impacting organisations such as Ticketmaster and Santander.
Migrating data to the cloud does not eliminate the need to protect identities. MFA, credential rotation, access restrictions, logs, and alerts remain essential controls.
Source: SANS Internet Storm Center — 4 June 2024
What happened
On 4 June 2024 the SANS Internet Storm Center gathered research on unauthorised access to customer environments at Snowflake, a cloud data platform. The evidence pointed to the use of compromised credentials on accounts that did not have multi-factor authentication enabled.
The impact reached organisations including Ticketmaster and Santander, among others, whose data hosted on Snowflake was accessed without authorisation using credentials stolen previously in other incidents, not through a vulnerability in the platform itself.
What it means for a mid-sized business
Migrating data to the cloud doesn't remove the need to protect identities: in this case, the problem wasn't the cloud platform but access accounts protected only by a password, with no additional layer of verification.
Using credentials stolen from other services to access cloud systems, known as credential stuffing, remains one of the most effective techniques against organisations that don't systematically require multi-factor authentication for every access to sensitive data.
What to review
Essential controls for protecting data hosted on cloud platforms:
- Mandatory multi-factor authentication on all accounts with access to sensitive data.
- Regular rotation of credentials and passwords for service accounts.
- Access restrictions by network address or location where possible.
- Logging and alerts for unusual access patterns to the data.
Frequently Asked Questions
- Was it a Snowflake vulnerability?
- Not according to the research gathered by SANS. Access came through compromised credentials on accounts without multi-factor authentication, not a technical flaw in the platform.
- What is credential stuffing?
- Using credentials stolen from one service to try to access others where the user reused the same password.
- How can a mid-sized business protect itself from this risk?
- By requiring multi-factor authentication for all access to sensitive data and avoiding password reuse across services.
Concepts mentioned in this article: Cloud · Ticket
Moving from news to prevention requires concrete measures. Seintec can help you prioritise them based on your company's size, activity, and budget. Contact our technical team.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.