Snowflake Hacker Pleads Guilty After Breaches Exposed Data of at Least 100 Million People

A hacker tied to the 2024 Snowflake customer breaches pleaded guilty after attacks exposed data tied to at least 100 million people.

Written By
KJ
Kezia Jungco
Aug 7, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A Canadian hacker has pleaded guilty to charges tied to the 2024 breaches of more than 165 Snowflake customer environments, a campaign that exposed data belonging to at least 100 million people.

Connor Riley Moucka, 26, admitted to computer fraud, wire fraud, aggravated identity theft, and conspiracy in federal court in Seattle. The attacks relied on stolen login credentials and accounts without multi-factor authentication rather than a vulnerability in Snowflake’s platform.

For security teams, the case highlights how old credentials, missing MFA, and weak cloud access controls can turn compromised employee logins into large-scale data theft.

Stolen credentials opened the door

The Hacker News reported that credentials used in the attacks had previously been harvested by infostealer malware, in some cases years before the Snowflake campaign began. The passwords remained valid, while the targeted accounts did not have MFA enabled.

Mandiant, which tracked the threat actor as UNC5537, found that every incident it investigated involved compromised customer credentials. According to Mandiant and Snowflake, at least 79.7% of the accounts leveraged by the attackers had prior credential exposure. Affected accounts also lacked MFA, and investigators identified missing network allow lists as another recurring weakness.

According to SafeState, the attackers also developed custom software to survey breached environments, collecting information such as organization names, user roles, and IP addresses before choosing which data to target.

The campaign did not require a sophisticated software exploit. Valid credentials gave the attackers access, showing how exposed passwords can remain dangerous long after an initial malware infection.

Breaches exposed highly sensitive data

The attacks reached organizations across several industries and exposed a wide range of personal and business information.

Publicly linked victims included AT&T, Ticketmaster, LendingTree, Santander, Neiman Marcus, and Advance Auto Parts. TechCrunch said that AT&T alone had data belonging to more than 100 million customers stolen, including call and text records.

Other stolen information across the campaign included banking details, payroll records, driver’s license numbers, passport numbers, Social Security numbers, and Drug Enforcement Administration registration numbers.

Advertisement

Prosecutors said victim organizations suffered more than $9.5 million in direct losses.

TechCrunch also noted that Moucka and his accomplices received more than $2.5 million in ransom payments. Moucka personally received at least $495,000 through extortion and the sale of stolen information, according to the publication.

Extortion continued after data was stolen

The operation did not stop with account compromise and data theft.

Prosecutors said Moucka re-extorted at least one victim after an initial payment, threatening further disclosure of stolen information. The data included records related to a government officer and family members of a former government officer.

Moucka is scheduled to be sentenced Oct. 27. He faces a mandatory minimum of two years on the aggravated identity theft count and up to 30 years on the remaining charges.

Security teams should treat exposed credentials as compromised

The case reinforces the risks of allowing password-only authentication for sensitive cloud environments.

Snowflake has since moved toward stronger authentication requirements. The Hacker News said that MFA is enabled by default for human users on accounts created since October 2024, with a final rollout phase scheduled between August and October 2026 to block passwords as the sole authentication factor for remaining human and service users, with some account types exempt.

For defenders, the lesson extends beyond Snowflake. Organizations may reduce similar risks by enforcing MFA, rotating exposed credentials, monitoring infostealer activity, limiting network access, and reviewing cloud identities that may still be using old passwords.

Read more: Snowflake is among the services targeted by fake Claude Code sites that use malicious install commands to steal AI credentials, API keys, and cryptocurrency. 

KJ

Kezia Jungco is a technology writer and researcher specializing in artificial intelligence, data analytics, CRM software, cloud infrastructure, cybersecurity, and emerging business technologies. With more than five years of experience evaluating software platforms and technology solutions, she helps business leaders understand the tools and trends shaping the future of work. Kezia has extensive hands-on experience testing and analyzing generative AI platforms, chatbots, natural language processing (NLP) tools, CRM systems, and business software. Her work focuses on translating complex technologies into practical insights that help organizations make informed decisions about technology adoption, operational efficiency, and digital transformation. As a staff writer for TechnologyAdvice, Kezia covers AI innovation, business applications of machine learning, data-driven technologies, cloud computing, cybersecurity, and sales technology. Her background in journalism, research, and education enables her to combine rigorous analysis with clear, accessible reporting for both enterprise and consumer audiences. Kezia holds a bachelor's degree in Development Communication with a major in Development Journalism from the University of the Philippines Los Baños. She has also completed professional training in artificial intelligence, data privacy, and information security. Her work has been featured in TechnologyAdvice, TechRepublic, eWeek, Datamation, and Selling Signals, where she helps readers navigate a rapidly evolving technology landscape with practical, research-driven guidance.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.