Hacker Pleads Guilty in Massive Snowflake Data Breach
Connor Riley Moucka admitted his role in stealing data from over 165 Snowflake customers, exposing records of at least 100 million people and netting over $2.5 million in ransom.
✨ This content was summarized and interpreted by AI; it may contain errors — please verify accuracy with the original sources. Learn more
Listen to this story

Connor Riley Moucka's guilty plea in Seattle federal court to charges of computer fraud, wire fraud, aggravated identity theft, and conspiracy marks a significant milestone in one of the most impactful cloud data breaches of 2024. The 26-year-old Canadian, also known by the aliases "Waifu" and "Judische," admitted to his role in stealing data from more than 165 Snowflake customers, an intrusion that exposed records belonging to at least 100 million people and netted him and his accomplices over $2.5 million in ransom payments. Moucka personally received at least $495,000 from these illicit activities, which included selling stolen data on cybercrime forums like BreachForums and XSS.is, and even attempting to re-extort at least one victim by leveraging sensitive information about a government official's family. Sentencing is scheduled for October 27, where Moucka faces a mandatory minimum of two years for aggravated identity theft and up to 30 years for the other counts.
This case is a stark reminder that the weakest link in cloud security often lies not within the sophisticated infrastructure of providers like Snowflake, but in the security practices of their customers. Investigations by Mandiant (Google's cybersecurity unit) and Snowflake consistently found no evidence of vulnerabilities or breaches within Snowflake's platform itself. Instead, the attackers, tracked as UNC5537, exploited customer accounts through stolen credentials, many of which were harvested years earlier by infostealer malware (such as Vidar, RISEPRO, and LummaC2) and had multi-factor authentication (MFA) switched off. Some of these compromised credentials dated back as far as November 2020 and remained valid years later. The campaign was characterized not by novel or sophisticated techniques, but by the opportunistic use of readily available stolen credentials and the absence of basic security hygiene like MFA and network allow lists on the customer side.
The impact of this breach on users and the industry is profound and multi-layered. For the affected organizations, including high-profile entities like AT&T, Ticketmaster, Santander Bank, and Advance Auto Parts, the consequences extend far beyond the direct financial losses, which authorities estimate exceeded $9.5 million. These companies faced significant reputational damage, regulatory scrutiny, customer notification obligations, and potential litigation from affected individuals whose sensitive data—including financial information, Social Security numbers, passport numbers, and even Drug Enforcement Administration (DEA) registration numbers—was exfiltrated. The sheer volume of exposed personal records, with AT&T alone accounting for approximately 110 million and Ticketmaster/Live Nation around 560 million, underscores the massive scale of potential identity theft and fraud.
For the broader cloud data warehousing industry, this incident highlights a persistent tension within the shared responsibility model of cloud security. While cloud providers invest heavily in securing their core infrastructure, the ultimate protection of customer data often hinges on the customer's adherence to security best practices. Snowflake, for its part, has since taken steps to enforce MFA by default for human users on accounts created since October 2024, with a full rollout for existing accounts expected between August and October 2026. This shift reflects a growing industry trend where providers are increasingly pushing for stronger default security configurations to mitigate user-side vulnerabilities. The breaches also fueled a critical re-evaluation of cloud security more broadly, prompting renewed conversations about the necessity of robust identity and access management (IAM) controls, including strong authentication, privileged access management (PAM), and continuous monitoring.
Comparing this attack to previous generations reveals a shift in attacker methodology. While direct exploitation of platform vulnerabilities once dominated, the modern threat landscape is heavily influenced by credential theft and social engineering. Credential stuffing, where attackers use previously leaked credentials from other breaches to gain access, has become a pervasive and low-cost, high-impact method. Reports indicate a dramatic surge in credential theft attacks, with some sources noting a 300% spike compared to previous years, making it a preferred attack vector. This underscores that even with advanced platform security, the human element—poor password hygiene, lack of MFA adoption, and susceptibility to infostealer malware—remains a critical vulnerability. Moreover, while not directly applicable to this specific credential-stuffing attack, the evolving sophistication of MFA bypass techniques, including AI-powered phishing and Adversary-in-the-Middle (AiTM) attacks, demonstrates that even MFA is not an impenetrable shield if not implemented and managed carefully.
Looking ahead, the fallout from this high-profile conviction will likely accelerate several trends in cloud security. Regulatory bodies are expected to intensify scrutiny on organizations' data protection practices, potentially leading to more stringent fines and legal actions for negligence in safeguarding sensitive information. The global average cost of a data breach reached $5 million last year, increasing 12% from 2025, with healthcare and finance seeing even higher costs. This financial pressure will drive greater investment in proactive security measures. We can anticipate a stronger emphasis on "secure by design" principles, where security is not an afterthought but an inherent part of system architecture and user onboarding. This includes universal MFA enforcement, comprehensive identity governance, and the adoption of Zero Trust security models that verify every access request regardless of origin. AI will play a dual role, both as an enabler for more sophisticated attacks and as a crucial tool for defenders in threat detection, behavioral analytics, and automated incident response. The ongoing collaboration between law enforcement and cybersecurity firms, exemplified by Moucka's arrest and the pursuit of his accomplices like John Erin Binns, signals a continued global effort to deter cybercriminals through prosecution. This case serves as a powerful testament to the enduring reality that in the digital age, robust security is a shared, continuous responsibility, demanding vigilance from both providers and their customers.