Snowflake phases out legacy service-account passwords, pushing enterprises toward passwordless migration
Cloud data platform retires password auth for service accounts; Token Security highlights discovery and ownership as the real challenge

Key Takeaways
- Snowflake is ending password authentication for legacy service accounts, requiring migration to passwordless methods.
- Token Security highlights that identifying account usage, ownership, and required access is the harder part of the migration.
- No active exploitation has been reported; the change is a security improvement to reduce password-related risks.
Related Security News

JADEPUFFER-Linked Attackers Deploy Compromised Service Principals to Delete Azure Resources
Microsoft has attributed a series of destructive operations in early June 2026 to the threat actor tracked as JADEPUFFER, also known as Storm-3168. The attackers used compromised service principals to gain elevated privileges and delete Azure resources over a period of approximately 18 hours. Microsoft describes this activity as an evolution of the threat actor's tradecraft, leveraging identity-based attacks rather than traditional exploit chains.




_Dzmitry_Skazau_Alamy.jpg?width=720&quality=80&disable=upscale)