- What: Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty in Seattle federal court to computer fraud, wire fraud, aggravated identity theft and conspiracy over the 2024 breaches of Snowflake customer accounts.
- Impact: At least 165 organizations were compromised and records on at least 100 million people were exposed, with victim companies reporting more than $9.5 million in actual losses, excluding losses to their own customers.
- Fix / mitigation: Snowflake has enforced MFA by default for human users on accounts created since October 2024 and its documentation puts the final phase, blocking passwords as a sole factor for remaining human and service users, between August and October 2026, with reader and trial accounts exempt.
- Who's at risk: Any organization running a SaaS or cloud data platform where credentials predate the current MFA policy, service accounts sign in with passwords alone, and no network allow list constrains where logins can originate.
On Wednesday, in a federal courtroom in Seattle, a 26-year-old from Kitchener, Ontario named Connor Riley Moucka pleaded guilty to computer fraud, wire fraud, aggravated identity theft and a related conspiracy. The case covers the 2024 breaches of Snowflake customer accounts: at least 165 organizations compromised, records belonging to at least 100 million people exposed, and $495,000 that Moucka personally took from ransoms and data sales. Sentencing is set for October 27. He faces a two-year mandatory minimum on the identity theft count and up to 30 years on the rest.
Strip away the courtroom and the case is uncomfortable for a different reason. There was no exploit. There was no flaw in the platform. What got the attackers in was old passwords, harvested years earlier by infostealer malware, never rotated, protecting accounts that had multi-factor authentication switched off.
A half-million-dollar crime with no zero-day in it
Mandiant, which investigated alongside Snowflake and tracks the actor as UNC5537, found that every incident it worked traced back to customer credentials stolen by infostealers. Some of those credentials had been harvested as far back as November 2020 and were still valid years later. At least 79.7% of the accounts the group used had prior credential exposure. The compromised instances had no network allow lists, so a valid password from anywhere on the internet was a valid password.
Mandiant's own assessment is blunt: the campaign "is not the result of any particularly novel or sophisticated tool, technique, or procedure." The firm attributed the reach to two things — the sheer size of the infostealer market, and credentials left unrotated for as long as four years. That is the entire tradecraft. Buy or scrape a credential dump, try the logins, find the tenants where nobody turned MFA on, and pull the warehouse.
A credential stolen in November 2020 was still working in 2024. That is not an intrusion detection failure. It is a credential lifecycle failure, and no EDR product on your network would have caught it, because the login was legitimate.
The 165 number has quietly changed meaning
Worth flagging for anyone citing this case in a board deck. The figure 165 began life in 2024 as a notification count — the number of organizations Mandiant and Snowflake notified as potentially exposed. Prosecutors now use the same number for customers actually compromised. The Justice Department's own release does not settle on one figure either, citing over 165 organizations in the body while Assistant Attorney General A. Tysen Duva's statement says over 150.
The financial number is firmer and more useful: victim companies suffered more than $9.5 million in actual losses. That figure excludes losses to their own customers, which is where the bulk of the harm from a 100-million-person exposure actually lands.
What actually walked out
The stolen data was not marketing lists. It included non-content call and text history, payroll records, Drug Enforcement Administration registration numbers, passport numbers and Social Security numbers. AT&T confirmed in July 2024 that records of calls and texts for nearly all its cellular customers between May 1 and October 31, 2022 were taken from its workspace on a third-party cloud platform.
Prosecutors also said Moucka re-extorted at least one victim, threatening further disclosure using the stolen data of a government officer and members of a then-former government officer's immediate family. The department named neither. W. Mike Herrington, special agent in charge of the FBI's Seattle field office, called the tactics "calculated and predatory."
The RedEye take
The Justice Department has never named Snowflake — not in Wednesday's announcement, not in the October 2024 indictment. The victim is identified only as a U.S. software-as-a-service provider. Snowflake and Mandiant named the platform themselves in 2024, which is to the vendor's credit and worth remembering: the company that got publicly attached to this campaign is the one that chose transparency, and it was not the one with the vulnerability, because there was no vulnerability.
That framing matters because the shared-responsibility line in this case is not ambiguous. Snowflake shipped a platform that supported MFA. Customers left it off. Customers left credentials in place for four years. Customers did not configure network allow lists. Every one of those is a tenant-side control. If your cloud security program is built on the assumption that the provider's security posture is your security posture, this case is the counterexample with 100 million names attached to it.
The harder read is on defaults. Snowflake has enforced MFA by default for human users on accounts created since October 2024, but password-only sign-ins are not gone. Its documentation, checked by The Hacker News on August 6, puts the final phase between August and October 2026, rolling out account by account. Only then are passwords blocked as a sole factor for every remaining human and service user. Reader and trial accounts are exempt. Read that timeline again: the industry spent two years knowing exactly how this happened, and the last password-only login on the affected platform closes roughly four months from now, at best. Secure defaults arriving two years after the breach that proved they were necessary is the actual scandal in this story.
What defenders should learn
- Treat infostealer exposure as an inventory problem, not an incident. 79.7% of the accounts used in this campaign had prior credential exposure. Feed stealer-log monitoring into your identity system and force rotation on match — do not wait for an alert to correlate.
- Service accounts are the gap the MFA mandate does not close. Snowflake's rollout blocks passwords as a sole factor for human and service users only in the final phase between August and October 2026. Audit every non-human identity in your SaaS tenants now and move them to key-pair or OAuth before the vendor forces it.
- Network allow lists are the control nobody enabled and everybody had. The compromised instances had none. A tenant-level IP restriction would have made a stolen password useless from a residential VPN, and it costs nothing but a change ticket.
- Credential age is a metric you can actually report. Some of these passwords were harvested in November 2020 and still worked in 2024. Track maximum credential age per SaaS tenant the way you track patch latency, and set a hard ceiling.
- Check the exemptions in your vendor's security rollout, not just the headline. Reader and trial accounts sit outside Snowflake's password ban. Every default-on announcement has a carve-out list, and that list is your remaining attack surface.
undefined
Of the two men charged in 2024, only Moucka is in U.S. custody. Co-defendant John Erin Binns remains outside it as of the court's August 4 case update. Cameron John Wagenius, the former Army soldier prosecutors have tied to the same intrusions, pleaded guilty in a related case in July 2025. Moucka's sentencing on October 27 will close one file in a campaign that is still not fully accounted for.
Source: The Hacker News, "Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People," Swati Khandelwal, August 6, 2026 — https://thehackernews.com/2026/08/snowflake-hacker-pleads-guilty-over.html
Questions about your exposure?
RedEye Security provides assessments for organizations that need to understand their real risk.
Talk to us