Snowflake ends service-account passwords. Now comes the hard part

A Wake-Up Call for Snowflake Customers: The Perils of Service-Account Passwords and What’s Next

In a shocking case that exposed the vulnerabilities of service-account passwords, Connor Moucka and his co-conspirators used valid customer credentials to log in to over 165 Snowflake customer organizations, stealing billions of records, including the call and text records of nearly all of AT&T’s wireless customers. The consequences were severe, with Moucka pleading guilty to multiple charges related to computer fraud, wire fraud, aggravated identity theft, and conspiracy.

Snowflake’s response has been swift and decisive. In a bid to prevent similar breaches in the future, the company is migrating legacy service users to the SERVICE type, which will block password-based authentication entirely. This move marks a significant shift in Snowflake’s approach to security, one that recognizes the limitations of traditional passwords and the need for more robust identity management.

As part of this effort, Snowflake is forcing customers to confront their own identity debt – a backlog of credentials that have been exposed, abandoned, or left unrotated. This process is not just about replacing passwords; it’s about discovering what uses each account has, assigning an owner, and deciding how much access it still needs.

The challenge ahead is significant. Legacy service accounts, which have had more time for credentials to leak and go unrotated, are the most difficult to address. These accounts often lack clear ownership or documentation, making it hard to determine who should be responsible for their migration. Moreover, as these accounts transition from password-based authentication to new methods, dependencies may break, causing unforeseen consequences.

To overcome this hurdle, Snowflake customers must take a more proactive approach to identity management. This involves building an inventory of service accounts, assigning named owners to each account, and choosing the most suitable method for authentication without passwords. The good news is that Snowflake provides several options for passwordless authentication, including workload identity federation, which is its recommended choice.

For customers looking to future-proof their security posture, it’s essential to start building this inventory now, not in October when the deadline looms. This involves answering three crucial questions: which accounts still authenticate with passwords, who owns each account, and what breaks when password-based authentication stops working? By addressing these issues proactively, Snowflake customers can avoid the chaos that follows a sudden transition to new security protocols.

Ultimately, this case serves as a reminder of the importance of identity management in securing modern systems. It’s not just about replacing passwords; it’s about taking ownership of our digital assets and ensuring they are properly secured. As Snowflake continues its rollout of passwordless authentication, customers must be prepared to tackle their own identity debt head-on – before it’s too late.


Source: Bleeping Computer — 2026-08-26