Snowflake ends service-account passwords. Now comes the hard part

Snowflake ends service-account passwords. Now comes the hard part

Keypoints

  • Connor Moucka used valid Snowflake customer credentials, not a vulnerability, to access over 165 organizations.
  • The attack exposed weak identity controls, including old credentials, no second factor, and missing network restrictions.
  • Snowflake is migrating legacy service users to the SERVICE type to block password authentication.
  • Organizations must inventory service accounts, assign named owners, and determine what breaks before migration.
  • Snowflake recommends passwordless methods such as workload identity federation, External OAuth, key-pair authentication, or programmatic access tokens.

Read More: https://www.bleepingcomputer.com/news/security/snowflake-ends-service-account-passwords-now-comes-the-hard-part/