Snowflake Breach: Hacker Pleads Guilty, Compromising Over 100 Million Records

Published:

Snowflake Breach: Hacker Pleads Guilty, Compromising Over 100 Million Records

Connor Riley Moucka has pleaded guilty in a Seattle federal court to multiple charges, including computer fraud and aggravated identity theft, linked to significant breaches of Snowflake customer accounts in 2024. The breaches affected at least 165 organizations and compromised the records of over 100 million individuals. Moucka, a 26-year-old from Kitchener, Ontario, reportedly gained at least $495,000 through ransom payments and data sales. This case underscores the vulnerabilities associated with outdated security practices, particularly the use of old passwords and the disabling of multi-factor authentication (MFA).

Snowflake Breach Details and Impact

The breaches attributed to Moucka involved the exploitation of old passwords harvested by infostealer malware. Many of these credentials had not been updated for years, and the accounts lacked multi-factor authentication, rendering them vulnerable. The Justice Department has not publicly named the affected company, referring to it only as a U.S. software-as-a-service (SaaS) provider, although Snowflake and Mandiant identified it in their investigations.

Prosecutors indicated that Moucka also attempted to extort at least one victim by threatening to disclose sensitive information, including data related to government officials and their families. The FBI’s Seattle field office described the tactics employed by Moucka as “calculated and predatory,” emphasizing the serious nature of the offenses.

Extent of the Data Compromise

The breaches resulted in the exposure of sensitive information, including call and text histories, payroll records, and personal identification numbers such as Social Security numbers. Victim companies reported losses exceeding $9.5 million, not accounting for the financial impact on their customers. The compromised data included records from major telecommunications providers, with AT&T confirming that data from nearly all its cellular customers was affected during the breach period.

According to Mandiant, which investigated the breaches, a staggering 79.7% of the accounts exploited had previously exposed credentials. The investigation revealed that many of these credentials had been valid for years, underscoring the risks associated with failing to rotate passwords regularly.

Legal Proceedings and Sentencing

Moucka is scheduled for sentencing on October 27, where he faces a mandatory minimum of two years for identity theft and up to 30 years for the other charges. His co-defendant, John Erin Binns, remains at large, while another individual linked to the case, Cameron John Wagenius, has already pleaded guilty in a related matter.

The evolving nature of the case has led to discrepancies in the reported number of affected organizations, with figures ranging from 150 to over 165. This inconsistency highlights the complexities involved in tracking the full extent of the breaches and their impact on various entities.

Future Security Measures

In response to the breaches, Snowflake has implemented mandatory multi-factor authentication for new accounts created since October 2024. However, password-only sign-ins are still permitted for existing accounts, with a phased rollout of enhanced security measures expected to conclude by October 2026. This initiative aims to mitigate the risks associated with credential theft and improve overall account security.

The case serves as a critical reminder of the importance of robust cybersecurity practices, including regular password updates and the implementation of multi-factor authentication to protect sensitive data.

Source: cyberwarriorsmiddleeast.com

For ongoing coverage and breaking updates, visit our Latest News section.

Published on 2026-08-06 16:21:00 • By the Editorial Desk

Share post:

[tds_leads title_text="Subscribe" input_placeholder="Email address" btn_horiz_align="content-horiz-center" pp_checkbox="yes" pp_msg="SSd2ZSUyMHJlYWQlMjBhbmQlMjBhY2NlcHQlMjB0aGUlMjAlM0NhJTIwaHJlZiUzRCUyMiUyMyUyMiUzRVByaXZhY3klMjBQb2xpY3klM0MlMkZhJTNFLg==" f_title_font_family="653" f_title_font_size="eyJhbGwiOiIyNCIsInBvcnRyYWl0IjoiMjAiLCJsYW5kc2NhcGUiOiIyMiJ9" f_title_font_line_height="1" f_title_font_weight="700" f_title_font_spacing="-1" msg_composer="success" display="column" gap="10" input_padd="eyJhbGwiOiIxNXB4IDEwcHgiLCJsYW5kc2NhcGUiOiIxMnB4IDhweCIsInBvcnRyYWl0IjoiMTBweCA2cHgifQ==" input_border="1" btn_text="I want in" btn_tdicon="tdc-font-tdmp tdc-font-tdmp-arrow-right" btn_icon_size="eyJhbGwiOiIxOSIsImxhbmRzY2FwZSI6IjE3IiwicG9ydHJhaXQiOiIxNSJ9" btn_icon_space="eyJhbGwiOiI1IiwicG9ydHJhaXQiOiIzIn0=" btn_radius="3" input_radius="3" f_msg_font_family="653" f_msg_font_size="eyJhbGwiOiIxMyIsInBvcnRyYWl0IjoiMTIifQ==" f_msg_font_weight="600" f_msg_font_line_height="1.4" f_input_font_family="653" f_input_font_size="eyJhbGwiOiIxNCIsImxhbmRzY2FwZSI6IjEzIiwicG9ydHJhaXQiOiIxMiJ9" f_input_font_line_height="1.2" f_btn_font_family="653" f_input_font_weight="500" f_btn_font_size="eyJhbGwiOiIxMyIsImxhbmRzY2FwZSI6IjEyIiwicG9ydHJhaXQiOiIxMSJ9" f_btn_font_line_height="1.2" f_btn_font_weight="700" f_pp_font_family="653" f_pp_font_size="eyJhbGwiOiIxMyIsImxhbmRzY2FwZSI6IjEyIiwicG9ydHJhaXQiOiIxMSJ9" f_pp_font_line_height="1.2" pp_check_color="#000000" pp_check_color_a="#ec3535" pp_check_color_a_h="#c11f1f" f_btn_font_transform="uppercase" tdc_css="eyJhbGwiOnsibWFyZ2luLWJvdHRvbSI6IjQwIiwiZGlzcGxheSI6IiJ9LCJsYW5kc2NhcGUiOnsibWFyZ2luLWJvdHRvbSI6IjM1IiwiZGlzcGxheSI6IiJ9LCJsYW5kc2NhcGVfbWF4X3dpZHRoIjoxMTQwLCJsYW5kc2NhcGVfbWluX3dpZHRoIjoxMDE5LCJwb3J0cmFpdCI6eyJtYXJnaW4tYm90dG9tIjoiMzAiLCJkaXNwbGF5IjoiIn0sInBvcnRyYWl0X21heF93aWR0aCI6MTAxOCwicG9ydHJhaXRfbWluX3dpZHRoIjo3Njh9" msg_succ_radius="2" btn_bg="#ec3535" btn_bg_h="#c11f1f" title_space="eyJwb3J0cmFpdCI6IjEyIiwibGFuZHNjYXBlIjoiMTQiLCJhbGwiOiIxOCJ9" msg_space="eyJsYW5kc2NhcGUiOiIwIDAgMTJweCJ9" btn_padd="eyJsYW5kc2NhcGUiOiIxMiIsInBvcnRyYWl0IjoiMTBweCJ9" msg_padd="eyJwb3J0cmFpdCI6IjZweCAxMHB4In0="]

Popular

More like this
Related

Microsoft enhances Copilot with code generation tool, Autopilot AI agent, and Office integration

Microsoft has announced significant enhancements to its Copilot application, introducing a new coding tool and an always-on AI agent, as reported by Emirates247. These updates aim to transform Copilot into a comprehensive solution for office workers, integrating essential Office applications…

Microsoft to invest over $10 billion in AI and cloud infrastructure across UAE and Gulf by 2030

Microsoft has announced plans to invest over $10 billion in artificial intelligence and cloud infrastructure across the UAE, Saudi Arabia, Qatar, and Kuwait by 2030. This significant investment aims to enhance digital resilience, cybersecurity, and workforce capabilities throughout the Gulf…

F5 highlights AI security innovations at events in Oman to support national digital initiatives

F5 has unveiled new enterprise AI security capabilities aimed at supporting the Omani government’s National Programme for Artificial Intelligence and Advanced Digital Technologies during two recent events in Muscat. The first event, F5 Academy Oman, focused on providing customers with…

Meta issues patch for Muse AI app following zero-day exploit discovery

Meta has released a patch for its Muse macOS application following the identification of a zero-day vulnerability that could potentially allow unauthorized users to take control of the AI agent. This flaw was discovered by security researcher Patrick Wardle, who…