Security1 distinct publisher2 min readPublished
Phase 3 hard-blocks password login for machine accounts by late 2026. Snowflake can tell you which credentials still work, not who owns them or what breaks when they stop.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Snowflake can hand you two of the three answers this cleanup needs, and no more. Its ACCOUNT_USAGE schema lists every user by type, and the login history retains the client and source IP of each authentication attempt for 365 days [10]. Join those and you have the accounts still signing in with a password, when each last did, and from where. What no Snowflake table holds is who requested the account, which system depends on it, or who to call when it stops answering [11]. That lives in someone's memory, a 2022 ticket, or nowhere.
The 365-day retention is also the ceiling on the method. A login-history query run when enforcement bites reaches back only to about October 2025, so any service account idle longer than a year sits in the user list with no login record beside it, and that is exactly the account whose breakage you cannot predict from telemetry [15]. The rollout was staged to leave these for last. Human users got second-factor enforcement in Snowsight first, from September 2025 into January 2026 [6]; then, from May to July 2026, every newly created nonhuman user was forced onto the passwordless SERVICE type [7]; only after that do the legacy accounts move. What remains is the oldest cohort by construction, with the most time for credentials to leak and go unrotated and for owners to change teams [9].
Ownership is where this stops being a query. A named owner, in the author's framing, is whoever accepts the alert when the account fails and carries responsibility for retiring it, not a row in a spreadsheet [17]. Where no name attaches, the recommended path is a controlled disable window: switch the account off, watch for failures, restore it if something breaks, and decommission it only after its dependencies check out [18].
Worth noting who is making the case: the article is bylined by Ido Shlomo, co-founder and CTO of Token Security, which sells non-human identity discovery [13]. The deadline is Snowflake's and real regardless; the tooling pitch rides on it.
Ranked by verification strength, evidence, and original report placement.
The campaign exposed a familiar identity failure: credentials remained valid long after their exposure, the affected accounts lacked a second factor, and network restrictions were often absent.
Connor Moucka did not exploit a vulnerability in Snowflake; he and co-conspirators used valid customer credentials, many of them years old, to log in and reached more than 165 Snowflake customer organizations.
The intruders stole billions of records, including the call and text records of nearly all of AT&T's wireless customers.
Moucka pleaded guilty on August 5 to computer fraud, wire fraud, aggravated identity theft, and conspiracy.
In Phase 3 of its authentication rollout, Snowflake is migrating legacy service users to the SERVICE user type, which cannot store a password, and the LEGACY_SERVICE type is being fully deprecated.
From September 2025 to January 2026, human users had to present a second factor in Snowsight, while service users were untouched.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Checkable platform mechanics, single interested source
The mechanical claims are specific and independently checkable against Snowflake documentation (user types, four passwordless methods, ACCOUNT_USAGE user list, 365-day login history), and the criminal case and Mandiant/Snowflake exposure statistic are concrete. But the cluster contains exactly one item, written by a vendor that sells the remedy, and nothing in the supplied material corroborates the phase dates, the account-specific Phase 3 enforcement mechanism, or the governance prescriptions. The derived 365-day visibility gap follows logically from two stated facts but is reasoning rather than observation.
Platform-forced rollout underway, migration progress unmeasured
Adoption of the change itself is real and non-optional: the article reports that two of three enforcement phases have already closed and that new nonhuman users must already be type SERVICE, and that Snowflake recognizes a distinct SERVICE_AGENT identity type. What is entirely absent is any measure of customer-side completion — no count of remaining legacy service accounts, affected customers, migrated estates, or organizations that have built the recommended inventory and ownership records. The score reflects a mandated rollout in progress with no evidence of practitioner uptake of the prescribed governance work.
Modest overstatement from vendor framing
The factual spine is not inflated: the deadline, user types, auth methods, and breach precedent are stated soberly and are checkable. The overstatement is in framing and scope — a criminal credential-abuse campaign is used to make an unmeasured governance thesis feel urgent, the 'real challenge is ownership' claim is asserted rather than demonstrated, and the AI-agent extension projects a much larger problem with no supporting measurement, all in service of the author's product. Positive but small, because a customer facing an account-specific enforcement date genuinely does have to act.
Vendor-authored content with direct commercial ask
The item is bylined by the co-founder and CTO of Token Security, a company selling non-human identity discovery and lifecycle enforcement, and the body contains an in-line product pitch plus a closing 'Book a technical demo' call to action for identifying ownerless identities and hidden dependencies — precisely the gap the article defines as the hard part. It is published on a security news outlet, which lends third-party framing to what is functionally vendor content, and no independent voice in the cluster offsets it.
Verifiable mechanics, one interested publisher
Confidence is moderate. The platform-mechanics and timeline claims are precise and internally consistent, and the breach precedent is a matter of public record, so the story is unlikely to be wrong on its factual spine. It is capped by the single-publisher, single-vendor-author structure, the absence of any migration-progress data, and reliance on the author's characterization of Snowflake's own position and of the Mandiant finding.
build
A UDP packet is now enough: IKEEXT RCE moves from patch queue to fire drill1 distinct publisher
build
A cleanup commit deleted the sanitizer. Five days later a scanner cashed it in.1 distinct publisher
security
Mandiant found 100 high-severity bugs in two days. Plan for the other side doing the same.1 distinct publisher
product
The AI-wrote-it claim died in eight hours. The Actions injection pattern did not.1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 26, 2026