‍Midnight Blizzard, Snowflake Incidents Underscore the Need for Stronger Identity Security, MFA Coverage

As the pace of cyberattacks continues to increase, companies simply can’t afford to have unintended access or gaps in MFA coverage.

Key Takeaways
  • The Midnight Blizzard attack on Microsoft and the Snowflake customer breach cluster both used valid credentials against accounts without MFA; Snowflake customers with MFA enforced were not breached, directly proving MFA coverage determines breach outcomes in credential-based attack scenarios.
  • IBM reports a 71% year-over-year increase in identity-related attacks, yet most organizations cannot produce a real-time view of MFA enforcement across their SaaS estate without a manual application-by-application audit.
  • Oleria's Trustfusion platform normalizes MFA status across all connected SaaS applications into a single continuously updated view, identifying accounts with no MFA and those using weak factors like SMS OTP that remain vulnerable to SIM-swapping even when MFA is technically enabled.
  • With 80% of all breaches involving compromised identities, MFA coverage gaps are not an edge case risk but the primary attack surface that threat actors actively scan for before selecting targets.

This summary was created with AI and reviewed by an editor.

Thick black downward-pointing chevron arrow with rounded ends.
Media contact
For media inquiries, contact pr@oleria.com

See adaptive, automated
identity security in action