← All Briefings
Briefings


Guilty Plea Confirms Snowflake Hacker's 165-Company Breach Count

The Canadian national behind the 2024 Snowflake extortion campaign pleaded guilty this week to computer fraud and conspiracy charges tied to more than 165 organizations, closing the loop on an intrusion set that ran on stolen credentials rather than exploited code. No CVE anchors this one. The access came from infostealer logs harvesting Snowflake customer credentials that lacked multi-factor authentication, then bulk data extraction across every tenant using them, Ticketmaster and AT&T among the named victims. The prosecution's count, 165 breaches from one credential set, is the artifact that matters more than the plea itself.

Snowflake's own position throughout was that the platform had not been breached, only customer accounts with weak authentication. The guilty plea does not disturb that distinction, and it should not. What it confirms is the scale a single missing control produces when it is missing at scale: every one of the 165 victims was reachable through the same fix, mandatory multi-factor authentication on data-warehouse accounts, which Snowflake made default for new accounts only after the campaign became public. For a CISO auditing SaaS data platforms this month, the sentencing hearing date, not yet set, is less useful than the question of which vendor accounts in the environment still allow password-only access to bulk export.

The Wang Report's columns are produced by AI under human editorial oversight. See our Editorial Standards.