Snowflake Hacker Pleads Guilty in Massive Data Breach Case
A Canadian man has pleaded guilty for his role in a series of cyberattacks that compromised customer accounts on the cloud platform Snowflake in 2024. The attacks affected more than 165 organizations and exposed the personal information of at least 100 million people. Prosecutors say 26-year-old Connor Riley Moucka earned nearly $500,000 by demanding ransom payments and selling stolen data online. He is scheduled to be sentenced on October 27 and could face decades in prison.
Investigators determined that the attacks were not caused by a flaw in Snowflake’s systems. Instead, the hackers gained access by using old usernames and passwords that had been stolen years earlier by malicious software. Many of the affected accounts had not changed their passwords for several years and did not have multi-factor authentication (MFA) enabled, making it much easier for attackers to log in.
According to investigators, the hackers targeted organizations whose login credentials had already been exposed in previous cybercrime campaigns. Once inside, they stole sensitive information and, in some cases, demanded money from victims to prevent the data from being released. Prosecutors also said Moucka threatened to reveal personal information belonging to government officials and their family members as part of an extortion attempt.
The stolen information included payroll records, passport numbers, Social Security numbers, Drug Enforcement Administration (DEA) registration numbers, and phone call and text message records. One of the most significant victims was AT&T, which confirmed that records involving nearly all of its wireless customers from a six-month period in 2022 had been accessed through its third-party cloud environment.
The investigation found that the success of the attacks was largely due to poor account security rather than advanced hacking techniques. Many organizations continued using passwords that had already been stolen years earlier, and most of the compromised accounts lacked additional security protections. Researchers concluded that the widespread availability of stolen login credentials, combined with weak account security practices, allowed the attackers to compromise a large number of organizations.
Since the attacks, Snowflake has strengthened its security requirements by enabling multi-factor authentication by default for newly created user accounts. The company is also gradually eliminating password-only logins, a process expected to be completed during 2026 for most users. These changes are designed to make it much more difficult for attackers to gain access using stolen passwords alone.
The case serves as a reminder that strong passwords, regular password updates, and multi-factor authentication remain some of the most effective ways to protect online accounts. Even without exploiting software vulnerabilities, cybercriminals can cause significant damage when organizations fail to secure their login credentials.







