The Snowflake data breach has exposed over 100 million records by exploiting stolen credentials to access cloud data platforms. This large-scale intrusion, affecting global and UK-relevant organisations, highlights new risks in cloud credential security.
Snowflake Data Breach: Timeline and Methodology
In May and June 2024, multiple organisations using the Snowflake cloud data platform reported unauthorised access to their data repositories. Security researchers and threat intelligence teams identified a coordinated campaign targeting Snowflake tenants, with attackers leveraging stolen credentials to bypass security controls.
The breach was first detected in early May 2024, when several companies noticed suspicious activity in their Snowflake environments. By late June, analysis revealed that over 100 million individual records had been accessed or exfiltrated. The affected organisations span a variety of sectors, including finance, retail and technology, and several prominent UK brands were among those impacted.
Initial investigation suggests the attackers used credentials obtained from previous data breaches or phishing campaigns. These credentials, often lacking multi-factor authentication (MFA) protection, enabled direct access to Snowflake accounts. The method did not involve exploitation of a software vulnerability in Snowflake itself, but instead relied on credential stuffing and brute-force attacks against login endpoints.
- Event start: Early May 2024
- Discovery: Mid-May 2024 by internal security teams
- Public disclosure: June 2024
- Current status: Ongoing investigation and remediation
The attackers systematically targeted organisations with weak password policies or no enforcement of MFA. Once inside, they used native Snowflake features to enumerate databases, exfiltrate sensitive customer data and cover their tracks.
Attack Impact: Who Is Affected and What Data Was Exposed?
The breach has impacted a significant number of Snowflake customers. Estimates place the number of exposed records at over 100 million, affecting customer information, transaction histories and in some cases, internal business data. The attack is considered one of the largest cloud credential-based intrusions to date.
UK-relevant brands and multinational organisations are among those affected, although the full list of impacted entities remains confidential. The exposed data varies by organisation, but commonly includes:
- Customer names and contact details
- Transaction records
- Account identifiers and hashed passwords
- Internal business documents
The breach demonstrates how attackers can leverage a single set of stolen credentials to compromise multiple Snowflake tenants. Notably, the attackers did not exploit a zero-day vulnerability in Snowflake. Instead, they relied on the absence of strong authentication controls, targeting accounts where MFA was not enforced or where passwords had been reused across multiple services.
Security teams have also noted that, in several cases, the attackers established persistence by creating new user accounts and assigning them elevated privileges, making detection more difficult.
How the Snowflake Credential Attack Worked
The method of attack was straightforward but effective. By collecting usernames and passwords from previous breaches or phishing campaigns, the attackers launched credential stuffing attacks against Snowflake login portals. Where accounts lacked MFA, these credentials provided immediate access.
Once authenticated, the attackers:
- Enumerated available databases and tables
- Exported large volumes of data using standard Snowflake export features
- In some cases, set up automated scripts to maintain access and exfiltrate data over time
- Created new privileged accounts to retain control
The attack did not require advanced malware or exploitation of Snowflake software flaws. Instead, it exploited common weaknesses in access management and user authentication. The attackers also took steps to minimise detection by blending their activity with legitimate traffic patterns.
The breach has prompted Snowflake and affected organisations to launch internal investigations, rotate credentials and enforce stronger authentication requirements. Incident response teams are reviewing access logs for evidence of unauthorised activity dating back several months, as some intrusions may have gone undetected for extended periods.
Current Mitigation Efforts and Exploitation Status
As of July 2024, the incident remains under active investigation. Snowflake has issued guidance to all customers, urging them to enable MFA, review user accounts for suspicious activity and update passwords for all users. Affected organisations have begun notifying regulators and potentially impacted customers, as required by data protection laws.
Security researchers believe the group responsible may attempt further intrusions using the same tactics, targeting other cloud-based data platforms and software-as-a-service (SaaS) providers. The incident has accelerated efforts across the industry to mandate MFA and strengthen credential hygiene for cloud platforms.
Why This Breach Matters
This breach is significant due to the sheer scale of data exposed and the ease with which attackers bypassed security controls using weak or reused credentials. The incident highlights the critical importance of enforcing MFA and monitoring cloud platform access for signs of compromise.
What Organisations Should Do Now
- Immediately enable MFA on all Snowflake and other cloud data accounts
- Audit user accounts and permissions for suspicious changes
- Monitor access logs for unusual activity, especially new account creation
Organisations should also review their password policies and consider additional authentication measures to reduce the risk of similar attacks in future.
Originally reported by Unknown.






