Skip to content
Beveiligingsnieuws

Snowflake breach: hacker pleads guilty over huge impact

Snowflake incident

A hacker has pleaded guilty in federal court in Seattle over the 2024 intrusions that prosecutors say exposed records tied to at least 100 million people. The case, now formally moving toward sentencing, centers on how attackers gained access to customer accounts—without exploiting a platform vulnerability.

Connor Riley Moucka, 26, of Kitchener, Ontario, entered his plea on Wednesday to charges including computer fraud, wire fraud, aggravated identity theft, and conspiracy connected to the breaches of customer accounts at a U.S. software-as-a-service provider. The court process is expected to culminate later this year.

Why the Snowflake breach happened

According to federal filings and statements tied to the case, investigators traced the intrusions back to credentials that were already sitting in the wrong hands. Prosecutors say old account passwords had been harvested years earlier by infostealer malware and were never rotated.

Just as important, the affected accounts reportedly had multi-factor authentication (MFA) switched off. In other words, the attackers relied on stolen login details rather than finding a novel weakness in the service itself.

Mandiant, which investigated alongside the platform and tracks the actor under the identifier UNC5537, described the overall campaign as not stemming from an especially innovative or complex technique. The “reach” was largely enabled by scale: many organizations had credentials exposed and left unchanged for a long time.

Scale of exposure: organizations and people

Prosecutors allege the activity reached at least 165 organizations, with records belonging to at least 100 million people. While that headline number has evolved since 2024, the pattern remains the same: stolen credentials were used repeatedly across many customer environments.

In 2024, the figure referred to organizations notified as potentially affected. In the current court release, the prosecutors use the number to describe customers actually compromised.

There is also some variation in the way the numbers are presented across documents. The court-related release references more than 165 organizations, while a Justice Department statement describes over 150. The case also notes that victim companies experienced more than $9.5 million in actual losses, excluding losses suffered by those companies’ own customers.

What attackers took and how it was used

The information exposed in the intrusions went beyond generic account data. Prosecutors list non-content call and text history, payroll records, Drug Enforcement Administration (DEA) registration numbers, and personal identifiers including passport and Social Security numbers.

One widely reported example involves AT&T confirming in July 2024 that records of calls and texts for nearly all its cellular customers between May 1 and October 31, 2022 were taken from its workspace on a third-party cloud platform.

Moucka was also accused of re-extorting at least one victim. Prosecutors say he threatened further disclosure by leveraging stolen data tied to a government officer and members of the officer’s immediate family. Authorities characterized the approach as calculated and predatory.

Connection to infostealer malware and credential reuse

Investigators’ central point is that compromised credentials were reused long after they were first stolen. Mandiant found that many of the accounts used in this campaign had prior credential exposure, and some were reportedly harvested as far back as November 2020.

In the incidents Mandiant worked on, a key operational gap was the absence of network allow lists. That meant once attackers had valid credentials, there was little friction to stop or limit where they could go inside the customer environment.

Mandiant also reported that at least 79.7% of the accounts used by the actor had prior credential exposure. This supports a broader theme seen in many breach cases: attackers often do not need to “break in” creatively when identities are already compromised.

Charges, sentencing outlook, and potential penalties

Moucka faces sentencing on October 27. Prosecutors say the aggravated identity theft count carries a mandatory minimum sentence of two years. Other charges could increase exposure significantly, with up to 30 years on the remaining counts.

The court materials also state that Moucka personally took at least $495,000 from ransom payments and data sales.

Two men were charged in the broader case in 2024, but their custody situations differ. As of an August 4 case update, only Moucka is in U.S. custody; his co-defendant, John Erin Binns, remains outside U.S. custody. A third individual, Cameron John Wagenius, previously linked by prosecutors to the same intrusions, pleaded guilty in a related matter in July 2025.

What the platform has changed since the incidents

While prosecutors did not describe a flaw in the service as the root cause, the case also highlights steps the platform has taken to reduce risk going forward—especially around MFA enforcement and login policy.

For human users on accounts created since October 2024, MFA has been enforced by default. However, the rollout is not described as “fully complete” for everyone. Password-only sign-ins were not immediately eliminated across all account types.

Documentation reviewed as part of the court-reporting timeline indicates a final phase is planned between August and October 2026. The approach described is gradual, rolling out restrictions account by account until passwords cannot be used as the sole authentication factor for every remaining human and service user. Reader and trial accounts are noted as exceptions.

Why disabling MFA and not rotating passwords still matters

The Snowflake breach case is a reminder that credential hygiene can be as decisive as technical defenses. Even strong security controls at the platform level may not help if customer accounts leave MFA turned off or if exposed passwords continue to function for years.

Here, investigators point to a combination of two recurring problems: passwords harvested by infostealer malware that were never rotated, and MFA settings that did not provide a second layer of verification.

For organizations, the practical takeaway is clear—monitor exposure, rotate credentials quickly after any suspicion of compromise, and ensure MFA is enabled and enforced. The court record underscores that attackers can cause widespread damage without “inventing” new exploits when they have valid logins and time to reuse them.

Conclusion

The Snowflake breach case is moving into its sentencing phase after Connor Riley Moucka pleaded guilty to federal offenses tied to the 2024 intrusions. Prosecutors and investigators describe a scenario built on stolen credentials, long-standing password reuse, and MFA disabled—rather than a single platform vulnerability.

As sentencing approaches on October 27 and rollout changes continue through 2026, the case will likely remain a stark example of how attackers leverage infostealer-driven credential theft at scale, and how quickly organizations can be exposed when access protections are left incomplete.

Source: https://thehackernews.com/2026/08/snowflake-hacker-pleads-guilty-over.html