The back door of the cloud old credentials and MFA disabled triggers the failure in Snowflake

Author: Published 5 min de lectura 164 reading

The images in this article were generated with artificial intelligence. How we publish

The criminal repentance of Connor Riley Moulka in Seattle for his role in intrusions on Snowflake's client accounts is, in criminal terms, a partial closure: an accused pleaded guilty to computer fraud, electronic fraud, aggravated identity theft and related conspiracy, and faces severe penalties that include mandatory minimum and up to decades of imprisonment. But at the technical and risk management level, the case leaves a much harder lesson: there was no sophisticated explosion or intrinsic failure of the platform; what allowed access were old credentials stolen by infostealer type and never rotated, with multi-factor authentication (MFA) disabled. Mandiant's investigation (actor traced as UNC5537) and public confirmations show that many of these credentials were captured years ago and remained valid, allowing for commitments in at least 165 organizations and data exposure of more than 100 million people.

That the vector was so prosaic doesn't make it less serious. On the contrary: it reveals a systemic failure of digital hygiene and governance in the management of identities and access. When a large proportion of accounts used as pivot had a history of exposure and no lists of allowed on the network were applied, the attacker needed only to buy or use filtered credentials in an infostealers market to move. The result was economic and human: direct losses over $9.5 million for the companies concerned, leaks of call and text records, payroll data, DEA registration numbers, passports and social security numbers, as well as reextortion attempts directed at individuals identified in the stolen data.

The back door of the cloud old credentials and MFA disabled triggers the failure in Snowflake
Image generated with IA.

This incident clarifies two frequent discussions on cloud safety. First, shared responsibility is not a mantra: it is practical. Cloud service providers may be technically safe, but if customers do not manage credentials, do not rotate secrets and do not force MFA, the risk persists. Second, safety is not improved only with new tools: basic credentials management, periodic rotation, closure of obsolete access and universal application of MFA are high-impact measures. Snowflake has begun to tighten its policies, requiring MFA by default in human accounts created since October 2024 and planning to block the exclusive use of passwords gradually until 2026, but the exceptions and long deadlines leave risk windows that the attackers exploit.

For organizations and technical officials who want to turn this warning into concrete actions, the immediate priority is to reduce the area that allowed the case. Implement and force MFA without exception for all human accounts and, where possible, for service accounts; prohibit single password login and migrate to more resistant factors such as FIDO keys or passwords; rotate passwords and secrets automatically and frequently, especially after incidents or signs of exposure; detect and block committed credentials using filter feeds and account intelligence services. In addition, close access to critical instances by applying network-allowed and segmentation lists, minimize the volume of sensitive data stored in shared environments and use field tokenization or encryption when feasible.

Recommendations for technical controls should be complemented by governance. Inventory accounts and privileges, conduct risk analysis and tabletop exercises on extortion or data leakage, implement abnormal use monitoring and response to playbooks incidents that include reporting to affected and cooperation with authorities. It is also relevant to review contracts with suppliers and to require transparency in security controls and response plans, because trust in a supplier does not replace the customer's operational responsibility.

The back door of the cloud old credentials and MFA disabled triggers the failure in Snowflake
Image generated with IA.

This case also has a human and regulatory dimension: the sale and resale of credentials in illicit markets and the reextortion of individual victims underline the need for protection for people whose lives are exposed. The companies concerned should provide mitigation support to those who see personal data being compromised, and regulators are increasingly attentive to organizations demonstrating proactive measures. Criminal action against operators such as Moulka may have a deterrent impact, but it does not prevent the constant emergence of new collections of credentials if practices are not fixed at an operational level.

To read the Department of Justice's statement on guilt and charges, please refer to the official note by the DOJ on https: / / www.justice.gov / opa / pr /..., and to understand MFA's implementation recommendations and its nuances in Snowflake, official documentation is a direct resource in https: / / docs.snowflake.com / en / user-guide / security-mfa.html. It is also appropriate to review the technical analysis and warning of response to incidents published by threat response firms to learn how these accesses were detected and mitigated.

In short, the story is not that the cloud was insecure by default, but that the stolen credentials and the lack of basic practices remained the preferred back door by economically motivated attackers. The priority for any organization that uses cloud services should be to treat that door as the most critical vulnerability: to close it through strict identity policies, access control and continuous monitoring before the next wave of old credentials reappears in an illicit market.

Coverage

Related

More news on the same subject.