Cloud Hacker Pleads Guilty in Massive Snowflake Breach Affecting 165 Organizations
A Canadian national has pleaded guilty to orchestrating a significant cyberattack against **Snowflake** customer accounts, impacting at least 165 organizations and exposing data belonging to over 100 million individuals. The breaches, attributed to previously compromised credentials and disabled multi-factor authentication, highlight the persistent threat of credential stuffing and the critical need for robust security hygiene.

**Connor Riley Moucka**, 26, of Kitchener, Ontario, has admitted guilt in a Seattle federal court, facing charges of computer fraud, wire fraud, aggravated identity theft, and related conspiracy. The charges stem from the 2024 breaches of **Snowflake** customer accounts, which **Moucka** personally profited from by at least $495,000 through ransoms and data sales.
Sentencing for **Moucka** is scheduled for October 27, where he faces a mandatory minimum of two years for identity theft and up to 30 years for the remaining counts.
## The Modus Operandi: Old Passwords and No MFA
The intrusions were not the result of a sophisticated exploit or a flaw within the **Snowflake** platform itself. Instead, attackers leveraged old passwords that had been harvested years prior by infostealer malware. Critically, the compromised accounts often lacked multi-factor authentication (MFA), making them easy targets.
The **Justice Department** initially withheld the name of the victim company, referring to it only as a U.S. software-as-a-service (SaaS) provider. However, both **Snowflake** and **Mandiant** publicly identified the platform in 2024.
Prosecutors also revealed that **Moucka** engaged in re-extortion, threatening further data disclosure using sensitive information belonging to a government officer and their immediate family members.
## Mandiant's Findings: UNC5537 and Credential Stuffing
**Mandiant**, which investigated the breaches alongside **Snowflake** and tracks the threat actor as **UNC5537**, confirmed that every incident examined traced back to customer credentials stolen by infostealers. Some of these credentials dated back to November 2020 and remained valid for years. The firm noted that at least 79.7% of the accounts used by **UNC5537** had prior credential exposure, and the compromised instances lacked network allow lists.
**Mandiant** emphasized that the campaign's success was not due to particularly novel techniques but rather the widespread availability of infostealer-harvested credentials and the failure to rotate passwords for extended periods.
## Impact and Data Exposed
The breaches affected at least 165 organizations, a figure that now refers to actually compromised customers, not just those notified of potential exposure. Victim companies sustained over $9.5 million in direct losses, excluding subsequent damages to their own customers.
Exposed data included non-content call and text history, payroll records, **Drug Enforcement Administration (DEA)** registration numbers, passport information, and Social Security numbers. In July 2024, **AT&T** confirmed that call and text records for nearly all its cellular customers between May 1 and October 31, 2022, were taken from its workspace on a third-party cloud platform, believed to be **Snowflake**.
## Ongoing Investigations and Security Measures
Of the two individuals charged in 2024, only **Moucka** is currently in U.S. custody. Co-defendant **John Erin Binns** remains at large. Separately, **Cameron John Wagenius**, a former Army soldier linked to the same intrusions, pleaded guilty in a related case in July 2025.
In response to these incidents, **Snowflake** has enforced MFA by default for human users on accounts created since October 2024. However, password-only sign-ins are not entirely eliminated. The company's documentation indicates a phased rollout of mandatory MFA, with the final phase expected between August and October 2026, when passwords will be blocked as a sole authentication factor for all remaining human and service users, with reader and trial accounts being exempt.
This case serves as a stark reminder for IT security professionals and privacy-conscious users about the critical importance of strong, unique passwords, ubiquitous multi-factor authentication, and regular credential rotation to defend against credential stuffing attacks, even against robust cloud platforms.