[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fOPV7t0QwIIrvwGsGLda7l2wIg10EWN8nMYW8GigCfsE":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":25,"created_at":26,"published_at":27,"article":28,"tags":32,"podcasts":51},"2e38b43b-1c62-4bbe-8f8c-c2602899c3d0","snowflake-breaches-stolen-credentials-no-mfa-100m-records-exposed","b94230bb-dd9a-4ec9-85cb-944ca7b7c5ff","Snowflake Breaches: Stolen Credentials + No MFA = 100M Records Exposed","The root cause of the Snowflake breaches was a compounding failure: infostealer malware harvested credentials that were never rotated, and MFA was not enforced on the compromised accounts, giving attackers unfettered access. This demonstrates that credential hygiene and authentication hardening are not optional controls — they are foundational defenses. The scale of impact (165 organizations, 100+ million individuals) illustrates how a single control gap in a cloud platform can create a massive blast radius across an entire supply chain of customers. Organizations that assume cloud providers handle authentication security on their behalf are dangerously mistaken — shared responsibility models require customers to enforce their own MFA and credential policies.","**Immediate actions:**\n- Audit all cloud service accounts (especially Snowflake, AWS, Azure, GCP) and enforce MFA on every account without exception.\n- Scan your environment for credentials exposed via infostealer malware using threat intelligence feeds or services like Have I Been Pwned for corporate domains.\n- Rotate all service account passwords and API tokens immediately, prioritizing accounts with access to sensitive data.\n\n**Long-term improvements:**\n- Implement a password rotation policy with automated enforcement, ensuring credentials are cycled on a defined schedule (e.g., every 90 days for privileged accounts).\n- Adopt phishing-resistant MFA (e.g., FIDO2\u002Fpasskeys) rather than SMS-based MFA for all critical cloud platform accounts.\n- Establish a cloud security posture management (CSPM) tool to continuously detect misconfigured authentication settings across SaaS and cloud environments.\n\n**Detection measures:**\n- Deploy user and entity behavior analytics (UEBA) to detect anomalous login patterns, such as logins from new geographies or unusual query volumes in Snowflake.\n- Subscribe to threat intelligence services that monitor for corporate credentials appearing in infostealer malware logs (e.g., Flare, Hudson Rock).\n- Enable and centralize authentication logs from all cloud platforms into your SIEM for real-time alerting on suspicious access.",[12,13,14,15,16,17,18,19,20,21,22,23,24],"CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 5: Account Management","CIS Control 6: Access Control Management","CIS Control 12: Network Infrastructure Management","NIST SP 800-53 AC-2: Account Management","NIST SP 800-53 AC-17: Remote Access","NIST SP 800-53 IA-5: Authenticator Management","NIST SP 800-53 IA-2(1): MFA for Privileged Accounts","NIST CSF ID.AM-3: Organizational communication and data flows are mapped","NIST CSF PR.AC-1: Identities and credentials are managed","GDPR Article 32: Security of Processing (technical measures to ensure ongoing confidentiality)","ISO 27001 A.9.4: System and application access control","ITIL: Service Configuration Management (tracking and enforcing secure baseline configurations)","published","2026-08-06T08:20:59.621966+00:00","2026-08-06T08:20:59.269+00:00",{"id":7,"url":29,"slug":30,"title":31},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fsnowflake-hacker-pleads-guilty-over.html","snowflake-hacker-pleads-guilty-over-breaches-affecting-at-least-100-million-peop-b41d69","Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People",[33,39,45],{"id":34,"name":35,"slug":36,"description":37,"color":38},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":40,"name":41,"slug":42,"description":43,"color":44},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":46,"name":47,"slug":48,"description":49,"color":50},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[]]