Snowflake hacker pleads guilty over 165 breaches

The man behind the 2024 wave of break-ins at Snowflake customers has pleaded guilty. Connor Riley Moucka, 26, of Kitchener, Ontario, admitted four counts in federal court in Seattle: computer fraud, wire fraud, aggravated identity theft and a related conspiracy.

The Justice Department says the conspiracy ran between February and October 2024, compromised more than 165 victim organizations and led to the theft of billions of sensitive customer records, with terabytes of data downloaded. It puts the victim companies' actual losses at over $9.5 million, a figure the department notes does not include losses suffered by those companies' own customers, totaling at least 100 million individuals.

What was taken

The stolen material went well beyond email addresses. According to the department, it included non-content call and text history records, banking and other financial information, payroll records, Drug Enforcement Administration registration numbers, driver's license numbers, passport numbers and social security numbers. Victims were then extorted with the threat of publication. The conspirators received over $2.5 million in ransom payments, of which Moucka personally obtained at least $495,000. The department says he also advertised victims' data for sale on the cybercrime forums BreachForums, Exploit.in and XSS.is, and on Telegram, and in at least one case re-extorted a victim with threats of further disclosure.

No vulnerability required

The detail defenders should sit with is how ordinary the access was. Snowflake's own platform was not broken into. The attackers simply logged in to customer accounts using valid credentials, many of them harvested years earlier by infostealer malware and never changed since. In its weekly threat roundup, SentinelOne notes that every Snowflake account the group reached had multi-factor authentication switched off, that more than three-quarters of the compromised accounts had prior credential exposure, and that none had network allow lists in place.

That combination, an old password sitting in a stealer log, no second factor, and no restriction on where a login can arrive from, is the same one that keeps turning up in current intrusion data. Cisco Talos found that phishing now starts most intrusions and attackers routinely get past MFA, and cloud extortion crews are working through service accounts for the same reason. On a cloud data platform, the credential is the perimeter.

What happens next

Moucka is due to be sentenced on 27 October. He faces a two year mandatory minimum on the aggravated identity theft count and a maximum of 30 years on the remaining counts. The case was prosecuted by trial attorneys Louisa K. Becker and George S. Brown of the Justice Department's Computer Crime and Intellectual Property Section, with assistant US attorney Sok Tea Jiang for the Western District of Washington.

What you should do

If you run anything on a cloud data platform, the plea reads as a checklist of what was missing. Enforce multi-factor authentication on every account, including the service and machine identities that are usually exempted. Rotate any credential that has ever appeared in a stealer log, and treat "we do not know" as a yes. Restrict logins to known network ranges so that a stolen password on its own is not enough to get in. None of this is new advice; it is simply what 165 organizations did not have in place at the same time.

The department's announcement of the plea is on justice.gov, and SentinelOne's weekly roundup carries a summary of the case.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions