Keypoints
- Connor Moucka used valid Snowflake customer credentials, not a vulnerability, to access over 165 organizations.
- The attack exposed weak identity controls, including old credentials, no second factor, and missing network restrictions.
- Snowflake is migrating legacy service users to the SERVICE type to block password authentication.
- Organizations must inventory service accounts, assign named owners, and determine what breaks before migration.
- Snowflake recommends passwordless methods such as workload identity federation, External OAuth, key-pair authentication, or programmatic access tokens.