Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Six npm Packages Read C2 Addresses From Ethereum Wallet

August 11, 2026

Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People

August 11, 2026

Cursor Security Bug Allowed Repositories to Execute Commands Pre Trust

August 11, 2026
Facebook X (Twitter) Instagram
Tuesday, August 11
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People
News

Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People

Team-CWDBy Team-CWDAugust 11, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy over the 2024 breaches of Snowflake customer accounts.

The intrusions reached at least 165 organizations and exposed records belonging to at least 100 million people. Moucka, 26, of Kitchener, Ontario, personally took at least $495,000 from ransoms and data sales.

He is due to be sentenced on October 27 and faces a two-year mandatory minimum on the identity theft count and up to 30 years on the rest.

What got the attackers in was old passwords. The credentials had been harvested years earlier by infostealer malware and never rotated, and the accounts had multi-factor authentication (MFA) switched off. No exploit, no flaw in the platform.

The Justice Department has never named the company, in Wednesday’s announcement or in the October 2024 indictment, identifying the victim only as a U.S. software-as-a-service (SaaS) provider. Snowflake and Mandiant named the platform themselves in 2024.

Moucka also re-extorted at least one victim, prosecutors said, threatening further disclosure using the stolen data of a government officer and members of a then-former government officer’s immediate family.

The department named neither. W. Mike Herrington, special agent in charge of the FBI’s Seattle field office, called the tactics “calculated and predatory.”

Mandiant, which investigated alongside Snowflake and tracks the actor as UNC5537, found that every incident it worked traced back to customer credentials stolen by infostealers. Some had been harvested as far back as November 2020 and were still valid years later. At least 79.7% of the accounts the group used had prior credential exposure, and the compromised instances had no network allow lists.

The campaign, the firm wrote, “is not the result of any particularly novel or sophisticated tool, technique, or procedure.” It put the reach down to the size of the infostealer market and to credentials left unrotated for as long as four years.

The 165 figure has changed meaning since 2024. It began as a notification count, the number of organizations Mandiant and Snowflake notified as potentially exposed; prosecutors now use it for customers actually compromised.

The release does not settle on one figure either, citing over 165 organizations in the body while Assistant Attorney General A. Tysen Duva’s statement says over 150. Victim companies suffered more than $9.5 million in actual losses, a figure that excludes losses to their own customers.

What went out included non-content call and text history, payroll records, Drug Enforcement Administration (DEA) registration numbers, passport and Social Security numbers. AT&T confirmed in July 2024 that records of calls and texts for nearly all its cellular customers between May 1 and October 31, 2022 were taken from its workspace on a third-party cloud platform.

Of the two men charged in 2024, only Moucka is in U.S. custody. Co-defendant John Erin Binns remains outside it as of the court’s August 4 case update. Cameron John Wagenius, the former Army soldier prosecutors have tied to the same intrusions, pleaded guilty in a related case in July 2025.

Snowflake has enforced MFA by default for human users on accounts created since October 2024, but password-only sign-ins are not gone. Its documentation, checked by The Hacker News on August 6, puts the final phase between August and October 2026, rolling out account by account. Only then are passwords blocked as a sole factor for every remaining human and service user. Reader and trial accounts are exempt.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCursor Security Bug Allowed Repositories to Execute Commands Pre Trust
Next Article Six npm Packages Read C2 Addresses From Ethereum Wallet
Team-CWD
  • Website

Related Posts

News

Six npm Packages Read C2 Addresses From Ethereum Wallet

August 11, 2026
News

Suisan City, California, Responds to Cyber Incident Amid Wave of US Lo

August 11, 2026
News

OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes

August 11, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

July 11, 20268 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

What’s at stake if your employees post too much online

December 1, 2025

Beware of Winter Olympics scams and other cyberthreats

February 2, 2026

‘What happens online stays online’ and other cyberbullying myths, debunked

September 11, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.