Snowflakes
– Wiki Commons

Snowflake has refuted claims that hackers breached its system, which was alleged to be the origin of the high-profile data breaches at Ticketmaster and Santander Bank.

“We have not identified evidence suggesting this activity was caused by a vulnerability, misconfiguration or breach of Snowflake’s platform,” said a joint statement from Snowflake, CrowdStrike and Google Cloud Mandiant regarding their ongoing investigation involving a targeted threat campaign against some Snowflake customer accounts.

In addition, “we have not identified evidence suggesting this activity was caused by compromised credentials of current or former Snowflake personnel,” according to the statement.

However, the investigation did find evidence that “a threat actor obtained personal credentials to and accessed demo accounts belonging to a former Snowflake employee,” which did not contain sensitive data.

“Demo accounts are not connected to Snowflake’s production or corporate systems. The access was possible because the demo account was not behind Okta or multifactor authentication (MFA), unlike Snowflake’s corporate and production systems,” the companies wrote.

Hacks targeting Santander and Ticketmaster In an SEC filing last week, Live Nation Entertainment, Ticketmaster's parent company, confirmed unauthorized activity within a third-party cloud database environment containing company data, but did not name the involved service provider.

Meanwhile, the notorious threat group ShinyHunters recently claimed responsibility for both the Santander and Ticketmaster data breaches.

Researchers at cybersecurity firm Hudson Rock last week published a report linking these breaches to a hack involving Snowflake.

According to Hudson Rock, the threat actor told the firm that “all of these breaches stem from the hack of a single vendor — Snowflake.” The hackers allegedly gained access by using the stolen credentials of a Snowflake employee to bypass Okta and compromised about 400 companies.

Snowflake finds a targeted campaign, offers recommendations In response to these allegations, Snowflake and third-party cybersecurity experts from CrowdStrike and Mandiant investigated potential threat activity within Snowflake customer accounts.

They found that the incident appeared to be a targeted campaign directed at accounts with single-factor authentication. “As part of this campaign, threat actors have leveraged credentials previously purchased or obtained through infostealing malware,” the statement said.

“Snowflake has promptly informed the limited number of Snowflake customers who it believes may have been affected. Mandiant has also engaged in outreach to potentially affected organizations,” it added.

Snowflake recommended customers immediately enforce multifactor authentication (MFA) on all accounts and set up Network Policy Rules to only allow authorized users or only allow traffic from trusted locations like VPN and cloud workload network address translation (NAT), while impacted organizations should reset and rotate Snowflake credentials.

Toby Lewis, global head of threat analysis at Darktrace, highlighted that these breaches underscore a critical issue of the reliance on single-factor authentication. “This isn't a supply chain hack but a reminder: if users can access your SaaS with just a password, so can attackers.”

“In this case, it appears that the security of cloud-hosted data is only as strong as the users' passwords. Credential phishing, keyloggers and weak passwords make accounts vulnerable. Cloud providers should encourage better security practices, such as mandatory MFA, even without explicit requirements on them to do so under the shared responsibility model. In essence, it becomes a differentiator when weighing up different cloud providers—pick the one that has secure-by-default practices to enhance overall security,” Lewis said in a statement.