← BACK TO FEED
data breachcredential stuffingSnowflakeinfostealercybercrime

Snowflake Breach Hacker Pleads Guilty: 100 Million Records, Stale Passwords, and No MFA

Connor Riley Moucka, 26, pleaded guilty to computer fraud, wire fraud, and identity theft charges related to the 2024 breaches of Snowflake customer accounts, which compromised at least 165 organizations and exposed records of over 100 million people. The attacks required no sophisticated exploits — attackers simply used old credentials harvested years earlier by infostealer malware on accounts with no multi-factor authentication enabled. Moucka faces a mandatory two-year minimum plus up to 30 years on additional charges and is due to be sentenced on October 27, 2025.

Connor Riley Moucka, 26, of Kitchener, Ontario, walked into a Seattle federal court on Wednesday and pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and conspiracy charges tied to last year's mass compromise of Snowflake customer accounts. The breaches hit at least 165 organisations and exposed records belonging to at least 100 million people. Moucka personally pocketed a minimum of $495,000 through ransoms and flogging stolen data.

Sentencing is set for October 27. He faces a mandatory two-year minimum on the identity theft count alone, with up to 30 years possible across the remaining charges.

So how did they get in? Old passwords. Credentials harvested years earlier by infostealer malware, sitting unchanged, on accounts with multi-factor authentication nowhere in sight. No zero-day, no clever exploit, no platform vulnerability. Just credential stuffing with keys that organisations had forgotten to change.

Mandiant, which investigated alongside Snowflake and tracks this crew as UNC5537, found that every single incident it worked on traced back to infostealer-stolen credentials. Some of those credentials had been lifted as far back as November 2020 and were still working years later. At least 79.7% of the accounts the group targeted had prior credential exposure on record. Not one of the compromised instances had network allow lists configured. Mandiant was blunt about what this operation was: not particularly novel, not particularly sophisticated. Just an enormous infostealer market and a lot of organisations that never got around to rotating passwords.

The Justice Department, in classic fashion, has declined to name the affected platform in either Wednesday's announcement or the October 2024 indictment, referring only to a U.S. SaaS provider. Snowflake and Mandiant named themselves in 2024, so the anonymisation is largely theatrical at this point.

Moucka also re-extorted at least one victim, prosecutors said, threatening to release data that included information about a government officer and members of a former government officer's family. The FBI's Seattle field office described the tactics as "calculated and predatory," which is accurate if understated.

The data that actually walked out the door is the kind that keeps compliance teams awake: call and text metadata, payroll records, DEA registration numbers, passport numbers, Social Security numbers. AT&T confirmed in July 2024 that records of calls and texts for nearly all its mobile customers over an 18-month period in 2022 were taken from a third-party cloud workspace. Victim organisations collectively suffered over $9.5 million in direct losses, and that figure doesn't account for what their own customers lost downstream.

The 165-organisation figure deserves a footnote. It started life in 2024 as a notification count, the number of organisations Mandiant and Snowflake told they might be exposed. Prosecutors are now using it to mean organisations actually compromised. Even within Wednesday's release the numbers wobble, with the body citing over 165 while the Assistant Attorney General's statement says over 150.

Of the three men charged in connection with these intrusions, only Moucka is in US custody. Co-defendant John Erin Binns remains beyond reach as of an August 4 case update. Cameron John Wagenius, a former Army soldier prosecutors linked to the same campaign, pleaded guilty in a related case in July 2025.

Snowflake has since made MFA the default for human users on accounts created after October 2024, which is a start. But password-only authentication hasn't been eliminated yet. According to Snowflake's own documentation, the final phase of the rollout is scheduled somewhere between August and October 2026, applied account by account. Until then, passwords remain a valid sole authentication factor for existing human and service accounts. Reader and trial accounts are exempt entirely.

The lesson here isn't complicated. Credentials age badly, infostealer logs circulate for years, and MFA isn't optional. The Snowflake campaign was effective not because the attackers were brilliant but because the basics were missing.

READ NEXT
River Bank Paid Ransomware Crew to Delete Stolen Data. Trust Them on That.ExfilSquad Claims Police Database Scalp as UK Public Sector Breach Spree ContinuesMeet Dolphin X: The Infostealer With an AI Profiler That Tells Crooks Which Victims Are Worth Robbing First