Technology
What Snowflake isn’t saying about its customers’ data breaches

Snowflake’s security problems are, for lack of a greater word, growing after a recent wave of customer data theft.
After Ticketmaster became the primary company to link its recent data breach to cloud computing company Snowflake, loan comparison site LendingTree confirmed that its QuoteWizard subsidiary had data stolen from Snowflake.
“We can confirm that we use Snowflake for our business operations and have been notified by Snowflake that this incident may have impacted data from our QuoteWizard subsidiary,” Megan Greuling, a spokeswoman for LendingTree, told TechCrunch.
“We take these matters seriously and initiated an internal investigation immediately after receiving information from (Snowflake),” the spokesman said. “At this time, there does not appear to be an impact on consumer financial account information or LendingTree’s parent information,” the spokesperson added, declining to comment further, citing the continuing investigation.
As increasingly affected customers come forward, Snowflake has said little other than a brief statement on its website reiterating that there was no data breach on its own systems, but somewhat that customers weren’t using multi-factor authentication, or MFA, a security measure that Snowflake doesn’t implement or require its customers to enable by default. Snowflake itself caught wind of the incident, claiming that a former worker’s “demo” account was compromised since it was only protected by a username and password.
In an announcement Friday, Snowflake firmly stood by its response thus far, saying its position “remains unchanged.” Referring to his earlier statement on Sunday, Snowflake’s chief information security officer, Brad Jones, said it was a “targeted campaign targeting users using single-factor authentication” and using credentials stolen from information-stealing malware or obtained through previous data breaches.
The lack of MFA appears to be causing cybercriminals to download massive amounts of data from Snowflake customer environments that weren’t protected by an extra layer of security.
Earlier this week, TechCrunch found lots of of Snowflake customer credentials stolen online by password-stealing malware that was infecting the computers of employees who had access to their employer’s Snowflake environment. The credential count suggests there’s a risk for Snowflake customers who haven’t yet modified their passwords or enabled MFA.
Over the course of the week, TechCrunch sent Snowflake greater than a dozen questions about the continuing incident affecting its customers as we proceed to report on this story. Snowflake refused to reply our questions a minimum of six times.
These are among the questions we ask ourselves and why.
It shouldn’t be yet known what number of Snowflake customers are affected or whether Snowflake already knows about it.
Snowflake said it has thus far notified “a limited number of Snowflake customers” that the corporate believes could have been affected. On its website, Snowflake says it has greater than 9,800 customers, including technology corporations, telecommunications corporations and health care providers.
Snowflake spokeswoman Danica Stańczak declined to say whether the variety of affected customers was within the tens, tens, lots of or more.
It’s likely that despite several customer breaches reported this week, we’re only just starting to know the dimensions of this incident.
Even for Snowflake, it might not be clear how many shoppers are affected, as the corporate will either should depend on its own data, equivalent to logs, or discover directly from the affected customer.
It is unclear how quickly Snowflake could have learned about the hacking of its customers’ accounts. In an announcement, Snowflake said it became aware of “threat activity” on May 23 – accessing customer accounts and downloading their content – but later found evidence of intrusions dating back to around mid-April, suggesting the corporate had some data on whom he can rely.
But that also leaves open the query of why Snowflake didn’t detect the exfiltration of huge amounts of customer data from its servers until much later in May, and if that’s the case, why Snowflake didn’t publicly notify its customers earlier.
Mandiant, an incident response company that Snowflake called to assist reach customers he told Bleeping Computer in late May that the corporate has been helping affected organizations for “several weeks.”
We still do not know what was in the previous Snowflake worker’s demo account and whether it’s related to customer data breaches.
A key line from Snowflake’s statement reads: “We found evidence that the threat actor obtained personal credentials and accessed demo accounts belonging to a former Snowflake employee. It did not contain sensitive data.”
An evaluation by TechCrunch shows that among the stolen customer credentials related to the information-stealing malware include data belonging to a then-Snowflake worker.
As we have previously noted, TechCrunch shouldn’t be naming the worker since it’s unclear whether he did anything improper. The indisputable fact that Snowflake was caught failing to implement MFA, allowing cybercriminals to download data from a then-employee’s “demo” account using only their username and password, highlights a fundamental problem in Snowflake’s security model.
However, it’s unclear what role, if any, this demo account plays within the theft of customer data, because it shouldn’t be yet known what data was stored on it or whether it contained data from other Snowflake customers.
Snowflake wouldn’t say what role, if any, the then-Snowflake worker’s demo account played within the recent customer security breaches. Snowflake reiterated that the demo account “did not contain sensitive data,” but repeatedly declined to say how the corporate defines what it considers “sensitive data.”
We asked whether Snowflake considers individuals’ personal information to be sensitive data. Snowflake declined to comment.
It is unclear why Snowflake didn’t proactively reset passwords or require and implement the usage of MFA on its customer accounts.
It’s commonplace for corporations to force password resets on their customers after a data breach. But if you happen to ask Snowflake, there isn’t a violation. And while this will be true within the sense that there was no apparent breach of central infrastructure, Snowflake customers are fairly often exposed to security breaches.
Snowflake advises his clients involves resetting and rotating Snowflake credentials and forcing MFA on all accounts. Snowflake previously told TechCrunch that its customers care about their very own security: “In Snowflake’s shared responsibility model, customers are responsible for enforcing MFA against their users.”
However, since Snowflake’s customer data thefts involve the usage of stolen usernames and passwords for accounts that will not be protected by MFA, it’s remarkable that Snowflake didn’t intervene on behalf of its customers to guard their accounts with a reset passwords or forced MFA.
This shouldn’t be unheard of. Last 12 months, cybercriminals deleted 6.9 million user records and genetic data from 23andMe accounts that weren’t protected with MFA. 23andMe fastidiously reset user passwords to forestall further scraping attacks after which required MFA for all of its user accounts.
We asked Snowflake if the corporate plans to reset passwords for its customer accounts to forestall possible further breaches. Snowflake declined to comment.
According to them, Snowflake appears to be moving towards implementing MFA by default Runtime technical news site, quoting Snowflake CEO Sridhar Ramaswamy in an interview this week. This was later confirmed by Snowflake’s CISO Jones in a Friday update.
“We are also developing a plan to require our customers to implement advanced security controls such as multi-factor authentication (MFA) or network policies, especially for privileged Snowflake customer accounts,” Jones said.
No timetable for the implementation of the plan was provided.
Technology
The signal is the number one application in the Netherlands. But why?

The application signal for sending a privacy -oriented message flew high in Dutch application stores last month, often sitting at the top as the most steadily downloaded free application for iOS and Android in all categories, for data from many application tracking platforms akin to the sensor tower.
The application has experienced popularity over the years, often in response to Changes in politics in rivals akin to WhatsApp Or Geopolitical events. This is because Signal has set a reputation as a more friendly privacy option-it is served by the non-profit foundation (though based in the USA), not a personal company focused on data earning data. In addition, the signal tracks minimal metadata.
In 2025, along with the recent US president, who strengthened the warm Big Tech hug, it is not surprising that digital privacy tools have a moment – especially in Europe, which attracted the anger of President Trump.
But this time, the meaning of the signal in one very specific place-Holandia is particularly eye-catching.
IN Interview with Dutch newspaper de Telelegraaf last week, President signal Meredith Whittaker He noticed that the number of “new registrations” in the Netherlands was 25 this 12 months, even though it is not clear what the exact comparative period for this data is.
Asked why the Netherlands recorded such development, Whittaker pointed to the combination of things: “growing awareness of privacy, distrust of large technology and political reality in which people realize how sensitive digital communication can be,” said Whittaker.
Data provided to TechCrunch from the application intelligence company Appfigures Increase in Signal Signal in the Netherlands. According to its data, the signal was 365. Among the applications apart from the iPhone in the Netherlands on January 1 and didn’t appear on the list of the most significant general applications. Then, from around January 5, he began to climb the rankings, reaching the highest position until February 2.
The signal immersed and comes out of the lead during weeks, spending around mid -February at the top – including every single day from February 22. By digging deeper into the data, the AppFigures estimates that the total download in Apple and Google Applets in total in December 2024 jumped to 99,000 in January and increased to 233,000 to February – 958%.
While a part of this height could be assigned to a lower saturation signal than other markets, a continuing application position at the top in comparison with neighboring markets of comparable size.
“No other markets are approaching the Netherlands in terms of growth between December and February,” said AppFigures Techcrunch.
For comparison, from December in Belgium, download increased by over 250%, Sweden by 153%and dishes by 95%.
So why the signal can experience what one redditor called “The moment of mass adoption“In the Netherlands?
Clear signal
Give ZengerSenior Policy Advisor at Dutch Digital Rights Foundation Fragments of freedomHe said that even though it is difficult to point one specific reason, he is not surprised.
The last changes in the US have seen Large platform suppliers Adapt with the recent Trump administration, and this has retained a major public and media debate. Relying Europe from the technology of big private American corporations has turn out to be the point of interest of this debate.
“The Dutch are, like many others, very dependent on the infrastructure provided by extremely dominant technology companies, mainly from the USA,” said Zenger. “What does this mean, and the risk that results from it has been nicely demonstrated in the last few weeks. As a result, the public debate in the Netherlands was relatively sharp. Where in the past this problem was discussed only at the level “:” I feel that we are now conducting a debate at the higher levels: “.
In this context, society can mix dominance with data protection abuse. Since corporations akin to meta are frequently studied and fined in the field of information privacy practices, the signal could appear to be less evil: it is based on the US, but supported by a non-profit organization, which ensures encryption of each the content of the message and around it.
Vincent BöhreDirector of the Dutch Organization of Privacy Privacy firstHe also pointed to increased media relationships and a wider change of public opinion.
“Since a few months ago he was re-elected in the United States, in the Dutch-and European media, which seem to support Trump, there were many” Elon) Muska. “Articles criticizing X (previously Twitter) and Meta appear everywhere in the Dutch media, which leads to a change in Dutch public opinion: even people who have never really known or cared for privacy and security in social media, suddenly became interested in” friendly privacy “alternative, in particular the signal.”
Signal of intentions

While the Netherlands is only one market of 18 million people in the European population over 700 million, its increase in adoption can signal a wider trend throughout the continent, especially when governments try to cut back privacy barriers.
For example, Apple has recently pulled out comprehensive encryption from iCloud in Great Britain to counteract government efforts to put in a backdoor.
Speech Fr. Rightcon 25 In Taiwan, this week, Whittaker confirmed the unwavering Signal attitude regarding privacy.
“Signal position on this subject is very clear- we will not walk, falsify or otherwise disturb the solid guarantees of privacy and security that people rely on” Said Whittaker. “Regardless of whether this disturbance or backdoor is called scanning on the client’s side or removing the protection of encryption against one or the other, the features similar to what Apple has been forced to do in Great Britain”
Separately, in Interview with Swedish public broadcaster, Whittaker said that Signal wouldn’t follow the proposed Swedish law requiring application to send messages for storage.
“In practice, this means asking us to break encryption, which is the basis of our entire activity,” said Whittaker. “Asking us to store data would undermine all our architecture and we would never do it. We would prefer to completely leave the Swedish market. “
TechCrunch contacted to signal a comment, but he didn’t hear during the publication.
(Tagstotranslat) signal of the Netherlands
Technology
Gayle King announces participation in the space mission of all women

Gayle King will join the thirty first Blue Origin civil flight into space.
Gayle King announced that he was going to space. The host of the talk show during the day provided messages CBS MORNINGS.
King revealed Her participation in the thirty first Blue Origin flights, NS-31. Before discussing the details of the mission, she and her co -lecturers presented the video editing, which described her long -term fascination with travel travel.
In one clip, King said: “I am excited to watch the premiere at home in my pajamas.”
Her enthusiasm led to an invite with Blue Origin. The television personality will disappear from Crew from the whole familyIncluding an award -winning journalist Lauren Sánchez, award -winning Grammy singer Katy Perry and astronaut Aish Bowe.
Soon the explorer of the space admitted that she was hesitating at first.
“I don’t know how to explain at the same time terrified and excited,” said King.
To make a choice, King turned to a gaggle of family members, including her children and a detailed friend, Oprah Winfrey. She said that when her most trusted confidants approved, she was ready.
“When Kirby, Will and Oprah were fine, I was fine,” said King. “I thought Oprah would say no. She said: “I feel that when you don’t do it, if you all come back and also you had the opportunity to do it, you’ll kick.” She is right. “
King is not going to be the first television host who wandered into space with blue origin. In 2021, then-Good morning America Coheat Michael Strahan took part in the third civil flight Blue Origin. The former NFL star and the sender was delighted after returning, expressing how this experience gave him a brand new “perspective” in the world.
“I want to come back,” said Strahan.
Blue origin, Founded by Amazon Billionaire Jeff Bezos in 2000 is a non-public aviation company that focuses on sharing space travels for civilians and developing technology to explore the space long.
The upcoming flight of the king New Shepard It will probably be part of Blue Origin’s constant efforts to normalize civil space travel.
Technology
Instagram can turn the rollers in a separate application

Meta is occupied with an independent application for brief movies, Information He informed, citing an anonymous source, which he heard the boss on Instagram Adam Mosseri talked about the personnel project.
The project is reportedly called RAY code, which goals to enhance recommendations for brand new users and existing users in the US and to conclude one other three minutes of movies, the report quoted the source.
The finish line didn’t answer immediately at the request for comment.
Last month, the company announced a video editing application called Edyta to compete with Capcut (belonging to Tiktok Matter Company Bytedance) since it was geared toward using the uncertain future Tiktok and Bytedance in the USA
Currently, the Instagram channel is a mixture of photos, movies (drums) and stories. However, many users imagine that the application has been cluttered since it incorporates movies and not persist with the roots as an application for sharing photos. If the company rotates in an independent application for brief movies, it can create a possibility for Instagram to emphasise other functions.
Instagram began at the starting of this yr paying creators To promote Instagram on other platforms, resembling Tiktok, Snapchat and YouTube. Apparently he also began to supply Big money for the creators Present only on roller skates.
(Tagstranslate) Instagram
-
Press Release11 months ago
CEO of 360WiSE Launches Mentorship Program in Overtown Miami FL
-
Press Release11 months ago
U.S.-Africa Chamber of Commerce Appoints Robert Alexander of 360WiseMedia as Board Director
-
Business and Finance9 months ago
The Importance of Owning Your Distribution Media Platform
-
Business and Finance11 months ago
360Wise Media and McDonald’s NY Tri-State Owner Operators Celebrate Success of “Faces of Black History” Campaign with Over 2 Million Event Visits
-
Ben Crump11 months ago
Another lawsuit accuses Google of bias against Black minority employees
-
Theater11 months ago
Telling the story of the Apollo Theater
-
Ben Crump12 months ago
Henrietta Lacks’ family members reach an agreement after her cells undergo advanced medical tests
-
Ben Crump12 months ago
The families of George Floyd and Daunte Wright hold an emotional press conference in Minneapolis
-
Theater11 months ago
Applications open for the 2020-2021 Soul Producing National Black Theater residency – Black Theater Matters
-
Theater9 months ago
Cultural icon Apollo Theater sets new goals on the occasion of its 85th anniversary