Skip to content

ScopeMantle is SOC 2 Type II in progress, read our trust commitments →

Breach Pattern

The Snowflake Customer Breakdown: When the credential layer isn't yours

165+ enterprises breached through one third-party connector. The mechanics, the missing controls, and the lessons that still aren't applied.

The warehouse was fine. The connector layer was not.

The 2024 Snowflake customer wave is the year a lot of boards heard "Snowflake breach" and pictured a cloud misconfiguration. Public reporting and vendor guidance pointed at a uglier mix: stolen customer credentials, missing MFA, and third-party analytics connectors holding long-lived tokens or keys. 165+ enterprises showed up in that reporting. Ticketmaster and Santander were among brands that confirmed tenant impact. Precise wording matters: customer-tenant access via stolen credentials, not "Snowflake the product was owned end to end."

OAuth and API keys are different protocols. Operationally both are persistent delegate credentials stored outside your IAM. ScopeMantle covers the OAuth slice: which employees granted which integration tools access to identity-linked SaaS that sits next to warehouse workflows. We do not pretend to be a Snowflake CASB.

Snowflake published hardening: MFA, network policies, credential rotation. Plenty of customers rotated passwords and left connector grants alone, because those grants were born in a browser and never hit procurement.

Timeline

Early 2024. Actors scan for tenants without MFA and for leaked contractor passwords. In parallel, connector platforms that hold API keys and OAuth tokens with warehouse access become attractive vaults.

April to May 2024. Mandiant and Snowflake coordinate as victim count climbs. Press shorthand says Snowflake breach. IR teams that only reset human passwords leave the connector path open.

June 2024. Snowflake pushes advanced security controls and IOCs. Connector vendors issue advisories. Emergency rotation without a map of who still holds delegate access is the common failure.

Second half of 2024. Lawsuits and regulators talk MFA. Less airtime goes to BI and ELT tools data engineers authorized themselves. Same structural blind spot as Drift, different API.

2025 to 2026. MFA and network policies land. AI analytics tools create a second wave of connector sprawl. Auditors ask for CC9.2 evidence of third-party data access. Spreadsheets are still last year's.

Mechanics, without the mythology

Three paths showed up in public analysis: credential stuffing and infostealer logs against humans, absent MFA, and connector-platform compromise. Where MFA was off, a password was enough. Where a connector held a long-lived token, the password was optional. That is the OAuth-refresh rhyme.

Exfil used legitimate JDBC and REST. No malware on a laptop. DLP on endpoints is a miss. Detection needs a list of third parties that can authenticate as your users or as service principals. Shared-responsibility arguments waste the first 48 hours. Snowflake secures the platform. You secure credentials, MFA, and vendor grants. Connector vendors sit in the gap and often never made the RoPA.

Scale is a script: iterate tenant URLs, test stolen creds, dump stages. One connector vault key is many enterprises.

What warehouse telemetry misses

Account usage views show login patterns. They do not give you an IdP OAuth inventory. A DBA looking at Snowflake users will not see the ELT SaaS an engineer authorized with Google. Those are different RACIs. Data platform owns connector approval. DBAs own warehouse RBAC. If those meetings never happen, you will rotate the wrong secret.

LayerControlTypical miss
Human loginMFA, network policyContractors with long-lived passwords (a primary 2024 vector in public write-ups)
Service principalsKey rotation, secret storesKeys copied into a connector SaaS
OAuth to adjacent SaaSIdP grant inventory and revokeBI tool authorized via Google, never in Snowflake user list

Procedure you can run this quarter

  1. List every connector, ELT, reverse-ETL, and AI-analytics tool that can reach the warehouse. Include POCs.
  2. For each, record: credential type (password, key, OAuth), where it lives, owner, last rotation, MFA or network policy on the warehouse side.
  3. Export Google Workspace and Okta grants. Highlight data-integration categories and warehouse-adjacent scopes.
  4. Join the two lists on owner email. Orphans on either side are the conversation.
  5. Revoke dead POCs. Rotate anything that survived 2024 without a recorded rotation.
  6. Add "OAuth revoke at IdP" to the Snowflake security review checklist, next to password rotation.
  7. Tabletop: connector vendor discloses Friday. You need client IDs and warehouse creds in one war-room doc.

ScopeMantle signals (OAuth slice only)

Unattested BI / ELT tools in the IdP grant list score on Scope Sanity. Warehouse-adjacent scopes on a general productivity app trigger review. Infra and data-platform titles raise severity. Stale POC grants age out in the ninety-day report. Breach-feed match on a connector vendor is the same bulk-revoke motion as Drift. Board trend is high-risk grant count, not a fake "Snowflake secure score" we do not sell.

Lessons

  • MFA on Snowflake is necessary and not sufficient. Delegate credentials skip the login UI.
  • Put connectors in CC9.2, not only native warehouse users.
  • Emergency rotation includes IdP OAuth revoke.
  • Do not claim HIPAA via ScopeMantle. We are not attested. No BAA. Educational write-up only.
  • Network plus session policy plus OAuth inventory is the defense-in-depth sentence for the board. Not one of those alone.

What to tell an auditor

"Here is the warehouse user list and MFA evidence (CC6.7-ish / platform hardening). Here is the connector inventory and IdP OAuth export (CC9.2). Here is a revoke from a dead POC." If they want a victim-count comparison, stick to public 165+ reporting. Do not estimate your industry's share.

A joint checklist for data platform and security

Put this in the quarterly Snowflake (or warehouse) review. It is boring on purpose.

  • MFA enforced for humans. Break-glass accounts listed and short-lived.
  • Network policy: expected CIDRs. Connector SaaS IPs documented, not "0.0.0.0 plus hope."
  • Service user list with owner and rotation date.
  • Connector SaaS list with credential type and vault location.
  • IdP OAuth export attached, filtered to BI / ELT / AI analytics.
  • Dead POC revoked this quarter (name one).
  • Last disclosure tabletop date and hours-to-revoke.

If data platform refuses to share the connector list, that is the finding. Security cannot inventory a vault it cannot see. ScopeMantle will not invent warehouse keys. We will show you the Google and Okta grants those engineers also created while they were standing up the POC.

Class-action and press hygiene

Public reporting named large brands. Your board will ask if you are "like Ticketmaster." Answer with your MFA status, your connector list, and your last rotation dates. Do not answer with a vibe. Do not claim ScopeMantle would have prevented password stuffing. We would have helped on the OAuth-shaped connector path and on the identity grants around it. Stay in that lane.

What to do this week

  1. Pull connector list from data-platform, not from procurement. They will differ.
  2. Export IdP grants. Mark ELT and BI.
  3. Kill one POC that is still live.
  4. Read Drift, Context.ai, the playbook, CC9.2 mapping.
  5. Demo if you want continuous IdP inventory. $5 / $6, no seat min, custom 500+. Entra is Beta.

What a POC week should look like

A data engineer wants to try a new reverse-ETL tool. Today the path is often: corporate Google login, OAuth, warehouse service user created in a hurry, Slack thumbs-up. A better path: ticket, named owner, credential type recorded, IdP grant visible in the next sync, 30-day expiry unless attested. If the POC dies, revoke the warehouse user and the OAuth grant. Half of leftover risk is POCs that became furniture.

Do not let the tool request mail scopes "for support notifications." Notifications can use SMTP or a bot account you control. Mail read on an ELT vendor is how a warehouse project becomes a privacy incident.

If the vendor only supports long-lived personal access tokens, treat that as a higher bar than OAuth with a revoke button. You can still use the tool. You cannot pretend it is equivalent. Write the exception with a rotation date.

Contractor passwords vs connector tokens

Public write-ups on this wave spent a lot of ink on contractors and infostealers. That path is MFA, short-lived creds, and not sharing passwords in tickets. The parallel path is the connector vault. Your tabletop should run both injects: "contractor laptop dumped" and "ELT vendor disclosed." Different owners, different revoke buttons, same Friday night. If you only drill the first, you will look prepared and still lose the tenant on the second.

TruConnector-class tools (the public Snowflake story used third-party connectors as the shorthand) should be named in the CC9.2 vendor list even when the contract sits with a reseller. Resellers do not revoke tokens for you. Client IDs and service users do. Account usage views show login patterns. They do not replace an IdP grant export. Pair them. Post-incident rotation without OAuth revoke leaves the connector path open. Put both on the quarterly warehouse review, with a named dead POC each quarter so the checklist cannot go stale.

Field guide: the warehouse review that includes identity

Invite data platform, security, and a DBA. Bring three artifacts: warehouse user list with MFA, connector list with credential types, IdP OAuth export filtered to BI and ELT. If any artifact is missing, that is the meeting. Kill one POC before you leave. Write the next tabletop date. Do not adjourn on a vibe about Ticketmaster.

Stay in lane on ScopeMantle: OAuth slice and adjacent IdP grants. We do not prevent password stuffing. MFA on Snowflake is still your job. 165+ is public reporting, not our customer set. $5 / $6, no seat min, Entra Beta, HIPAA not attested. Playbook.

Run both tabletops: contractor laptop dumped, and ELT vendor disclosed. Different owners, different buttons, same Friday. Pair warehouse usage views with the IdP export. Kill a named POC every quarter so the checklist cannot go stale. 165+ stays a public figure, not our customer metric.

If you only remember one operational sentence: MFA plus connector inventory plus IdP OAuth export, reviewed in the same meeting, with a named dead POC each quarter. Password rotation without revoke is a half fix. 165+ is press, not our pipeline.

Write the connector RACI on a wiki page: who approves a new ELT OAuth, who rotates the warehouse user, who revokes the IdP grant. If those are the same hero, you have an availability risk. Split them before the next POC.

Bring the three artifacts to one meeting: MFA user list, connector credential types, IdP OAuth export. Missing artifact is the agenda. Named dead POC is the proof the checklist still lives. Stay in the OAuth lane when you mention ScopeMantle.

Related reading stays on the internal paths already linked above: platform, integrations, demo, and the companion resources or blog posts for this topic. Use those links when you brief a colleague so they get the same product truth: public $5 / $6 pricing, no seat minimum, custom at 500+, Entra labelled Beta, DSAR templates operator-reviewed, no HIPAA attestation, no invented logos. That is the briefing. Everything else is the procedure you can run this week.

Start the trial from /demo when the manual export starts to rot. That is usually week six, not week one.

FAQ

Common questions

About ScopeMantle

ScopeMantle is an OAuth-grant audit and DSAR-automation platform for mid-market SaaS companies, sold primarily through an open MSSP partner program (70/30 wholesale split, deal registration, no direct-sale conflict in partner territories) and secondarily direct. Built in 2026.

Explore the partner program →

70 / 30 wholesale · deal registration honoured · no direct-sale conflict

Find the Context.ai in your org before the attacker does.

15-minute connection. First inventory in an hour. Vendor risk scores for every third party by tomorrow.

Book a demo to see the inventory on your own tenant.