We have not identified evidence to suggest that this activity was caused by a vulnerability, misconfiguration, or breach of the Snowflake platform;
We have not identified evidence to suggest that this activity was caused by compromised credentials of current or former Snowflake employees;
This appears to be a campaign targeting users with single-factor authentication;
As part of this campaign, threat actors leveraged credentials previously acquired or obtained through malware to steal information; It is
We found evidence that a threat actor obtained personal credentials and accessed demo accounts belonging to a former Snowflake employee. It did not contain confidential data. Demo accounts are not connected to Snowflake corporate or production systems. Access was possible because the demo account was not behind Okta or Multi-Factor Authentication (MFA), unlike Snowflake’s corporate and production systems.