The aftermath of a series of data thefts from Snowflake customers is causing growing concern about the company’s security measures.
Following similar issues faced by Ticketmaster, LendingTree has now also linked a data theft incident from its QuoteWizard subsidiary to issues with Snowflake’s services.
“We can confirm that we use Snowflake for our business operations, and that we were notified by them that our subsidiary, QuoteWizard, may have had data impacted by this incident,” explained Megan Greuling, a spokesperson from LendingTree, in discussion with TechCrunch.
LendingTree has commenced an in-depth internal investigation following the revelation from Snowflake and has mentioned that sensitive finance-related consumer data does not seem to be affected.
Snowflake, on its part, has remained mostly quiet about the incidents, beyond affirming that their own systems weren’t breached directly. Instead, they point to the absence of multi-factor authentication (MFA) among their clientele as the key issue, a security feature that Snowflake does not mandate. An incident involving a compromised ex-employee “demo” account without MFA has also come to light.
Despite incidents appearing to stem from stolen credentials and lack of MFA, Snowflake has retained its stance, with their Information Security Officer Brad Jones emphasizing the attacks were directed at users with single-factor authentication.
TechCrunch’s investigation into the matter has uncovered an extensive list of stolen Snowflake customer credentials online. Snowflake customers’ risk exposure remains a concern, especially for those who haven’t yet implemented MFA or changed their passwords.
As we continue to delve deeper into the situation, our queries to Snowflake about the scope and details of the situation remain unanswered.
The extent of the customer impact within Snowflake remains uncertain.
A “limited number” of Snowflake customers have been notified about potential impacts; however, the specific number of affected users out of their reported 9,800+ customers is not disclosed.
It is still unclear how much internal data Snowflake can rely on to determine the reach of the problem or how quickly they became aware of the intrusions.
The contents of the compromised “demo” account of a former Snowflake employee remain undisclosed.
The specifics of what data the account contained or its relevance to the breached customer data is not known, with Snowflake refusing to clarify.
Snowflake’s reasons for not resetting passwords or mandating MFA proactively remain unknown.
Despite the link between the lack of MFA and the thefts, Snowflake hasn’t forced a reset or mandated MFA protections for its users, an action that isn’t without precedent in the industry.
Steps toward making MFA a default setting are being hinted at by Snowflake, but no specific timeline has been confirmed.
If you have further insights regarding Snowflake’s account intrusions, please reach out. You can contact the reporter using various secure communication methods provided or via SecureDrop for document submissions.
FAQ Section
What is Snowflake?
Snowflake is a cloud-based data warehousing company that provides a platform for data storage, processing, and analytics.
What happened with Snowflake’s customer data?
Several Snowflake customers, including Ticketmaster and LendingTree’s QuoteWizard, have experienced data theft incidents which they have linked to security issues within Snowflake’s systems, particularly the lack of enforced multi-factor authentication (MFA).
Has Snowflake’s own infrastructure been breached?
Snowflake maintains that their systems have not been directly breached. The issues are tied to customers not using MFA, and Snowflake does not enforce or require MFA by default for its customers.
What is multi-factor authentication (MFA)?
MFA is a security measure that requires users to provide two or more verification factors to gain access to a resource such as an application, online account, or a VPN. It is designed to protect against unauthorized access resulting from compromised credentials.
Is sensitive customer data at risk?
Although LendingTree has indicated that sensitive consumer financial data does not appear to be impacted, the scope of the stolen data and the potential risk to sensitive information remain a concern for Snowflake customers not employing MFA.
What has been the response from Snowflake regarding these data theft incidents?
Snowflake has been relatively quiet on the incidents, reiterating their stance that affected customers were not using MFA. The company has also signaled future steps towards implementing MFA by default but has not taken proactive measures such as a widespread password reset.










































