Confidence
1- Public role
- Profile subject linked to reviewed BTW article evidence.
- Information type
- This record preserves Snowflake's organization identity while leaving legal entity, network resources, service scope, leadership, and related public sources open for enrichment.
Related details
- The Snowflake customer thefts reach a guilty plea, not a platform-breach finding
authorized human evidence
Last updated: 2026-08-27
Related research
8- Snowflake's AI Budgets Follow Entry Points, Not Just Agents
A budget attached to a Cortex Agent does not necessarily follow every request that reaches it. Snowflake's treatment of CoWork-originated activity exposes a wider question for enterprise AI: where spending is counted, whose access can be stopped, and how long the stop takes to arrive.
Primary articlePublished 2026-09-03 - Snowflake Put Annual Floors Inside a US$6bn Cloud Commitment
Snowflake's new AWS commitment is usually presented as one large five-year number. The contract is tighter than that headline. It combines a US$6 billion cumulative minimum with a minimum for every contract year, while allowing some shortfall payments to fund qualifying use later in the term. The economics will turn on the sequence of consumption, not the total alone.
Primary articlePublished 2026-08-28 - The Snowflake customer thefts reach a guilty plea, not a platform-breach finding
Connor Riley Moucka’s guilty plea turns part of the 2024 mass data-theft campaign from allegation into admitted criminal conduct. It also sharpens a distinction that enterprises cannot afford to blur. The Justice Department did not name Snowflake, while Mandiant’s contemporaneous investigation connected a campaign of the same scale to Snowflake customer instances and found stolen customer credentials—not a breach of Snowflake’s enterprise environment—behind every case it handled. The legal milestone is real; so is the tenant-side identity failure it leaves exposed.
Primary articlePublished 2026-08-06 - Snowflake made customer MFA defaults a data-cloud accountability test
Snowflake is a risk and accountability case because the accountability issue is not only whether Snowflake itself was breached; it is whether provider-side defaults, customer controls, and investigation evidence made credential misuse harder to sustain and easier to prove. The public record matters for customers, data subjects, security teams, cloud buyers, litigants, regulators, and boards needed evidence that identity defaults and telemetry were strong enough for the amount of sensitive data concentrated in customer instances.
Primary articlePublished 2026-07-12 - Snowflake made verifiable repair the test of shared cloud responsibility
The 2024 Snowflake customer credential-theft campaign did not require a demonstrated breach of Snowflake's production platform. That boundary matters, but it is not the end of accountability. The durable question is whether shared responsibility became measurable repair: stronger default MFA, leaked-password blocking, usable customer telemetry, network-policy adoption, and evidence that a provider-led campaign response changed the baseline rather than only the public explanation.
Primary articlePublished 2026-07-12 - Snowflake's AI Data Cloud Is Tested by the Accepted Governed Data Result
Snowflake's production test is not whether a demo can answer a natural-language question, but whether a governed data question, transformation or AI-assisted application can become an accepted result with permissions, lineage, freshness, cost and audit evidence still intact.
Primary articlePublished 2026-07-11 - Snowflake's credential-theft campaign and the limits of shared responsibility
The 2024 Snowflake campaign did not require a demonstrated break in Snowflake's production platform. Attackers used customer credentials, entered customer instances through supported interfaces, and issued ordinary data commands with extraordinary consequences. That distinction is essential, but it does not finish the accountability analysis. This is a shared-responsibility stress test: what happens when multi-factor authentication and network restrictions are customer settings, while the provider operates the authentication service, defaults, telemetry, data plane, security warnings, and product roadmap on which those customers depend?
Primary articlePublished 2026-07-10 - Snowflake acquires TruEra to bolster data cloud capabilities
TruEra brings AI model monitoring and observability to enhance Snowflake’s data cloud capabilities and ensure data accuracy.
Primary articlePublished 2026-05-26
