A Canadian hacker has pleaded guilty to charges tied to the 2024 breaches of more than 165 Snowflake customer environments, a campaign that exposed data belonging to at least 100 million people.
Connor Riley Moucka, 26, admitted to computer fraud, wire fraud, aggravated identity theft, and conspiracy in federal court in Seattle. The attacks relied on stolen login credentials and accounts without multi-factor authentication rather than a vulnerability in Snowflake’s platform.
For security teams, the case highlights how old credentials, missing MFA, and weak cloud access controls can turn compromised employee logins into large-scale data theft.
Stolen credentials opened the door
The Hacker News reported that credentials used in the attacks had previously been harvested by infostealer malware, in some cases years before the Snowflake campaign began. The passwords remained valid, while the targeted accounts did not have MFA enabled.
Mandiant, which tracked the threat actor as UNC5537, found that every incident it investigated involved compromised customer credentials. According to Mandiant and Snowflake, at least 79.7% of the accounts leveraged by the attackers had prior credential exposure. Affected accounts also lacked MFA, and investigators identified missing network allow lists as another recurring weakness.
According to SafeState, the attackers also developed custom software to survey breached environments, collecting information such as organization names, user roles, and IP addresses before choosing which data to target.
The campaign did not require a sophisticated software exploit. Valid credentials gave the attackers access, showing how exposed passwords can remain dangerous long after an initial malware infection.
Breaches exposed highly sensitive data
The attacks reached organizations across several industries and exposed a wide range of personal and business information.
Publicly linked victims included AT&T, Ticketmaster, LendingTree, Santander, Neiman Marcus, and Advance Auto Parts. TechCrunch said that AT&T alone had data belonging to more than 100 million customers stolen, including call and text records.
Other stolen information across the campaign included banking details, payroll records, driver’s license numbers, passport numbers, Social Security numbers, and Drug Enforcement Administration registration numbers.
Prosecutors said victim organizations suffered more than $9.5 million in direct losses.
TechCrunch also noted that Moucka and his accomplices received more than $2.5 million in ransom payments. Moucka personally received at least $495,000 through extortion and the sale of stolen information, according to the publication.
Extortion continued after data was stolen
The operation did not stop with account compromise and data theft.
Prosecutors said Moucka re-extorted at least one victim after an initial payment, threatening further disclosure of stolen information. The data included records related to a government officer and family members of a former government officer.
Moucka is scheduled to be sentenced Oct. 27. He faces a mandatory minimum of two years on the aggravated identity theft count and up to 30 years on the remaining charges.
Security teams should treat exposed credentials as compromised
The case reinforces the risks of allowing password-only authentication for sensitive cloud environments.
Snowflake has since moved toward stronger authentication requirements. The Hacker News said that MFA is enabled by default for human users on accounts created since October 2024, with a final rollout phase scheduled between August and October 2026 to block passwords as the sole authentication factor for remaining human and service users, with some account types exempt.
For defenders, the lesson extends beyond Snowflake. Organizations may reduce similar risks by enforcing MFA, rotating exposed credentials, monitoring infostealer activity, limiting network access, and reviewing cloud identities that may still be using old passwords.
Read more: Snowflake is among the services targeted by fake Claude Code sites that use malicious install commands to steal AI credentials, API keys, and cryptocurrency.





