Multi-CloudCIO BriefingsRetrospectives

CIO Brief: SaaS Shared Responsibility — Snowflake Wasn't Hacked, Its Customers Were

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from June 2024, written in 2026 with the benefit of hindsight.

The short version: In 2024, attackers stole data from about 165 companies' accounts on Snowflake, a cloud data platform — including Ticketmaster and AT&T. Snowflake itself wasn't hacked. The customers' accounts used passwords stolen by malware and didn't require multi-factor authentication.

Shared responsibility in plain language

SaaS providers secure their platform. Customers are responsible for who can log in and how. If the provider offers MFA and you don't turn it on, a breach through stolen passwords is your responsibility — legally and reputationally.

The business impact

  • Massive data theft and extortion.
  • Customer and regulatory fallout that lands on you, not the provider.
  • Hidden risk from passwords stolen from personal or contractor devices years ago.

Questions to ask your team

  • Which SaaS platforms hold our sensitive data?
  • Does every one require sign-in through our company identity system with MFA?
  • Are there service accounts or old accounts with passwords that never change?
  • Can we see who exported large amounts of data from our SaaS platforms?

What good looks like

Every SaaS platform tied to company sign-in with MFA, no standalone passwords for people, tightly controlled service accounts, and monitoring for large data exports.

The decision

Ask for a list of SaaS platforms that still allow password-only sign-in. Close those gaps this quarter — starting with the ones holding customer data.

snowflake breach impactSnowflake customer breaches2024

More on this story