A Canadian man admitted guilt Wednesday in Seattle federal court to orchestrating breaches of Snowflake customer accounts that reached at least 165 organizations and exposed records belonging to at least 100 million people. Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and conspiracy charges tied to the 2024 intrusions. The attacks exploited old credentials harvested by infostealer malware years earlier, never changed by victims, and used on accounts with multi-factor authentication turned off.
Moucka personally collected at least $495,000 from ransoms and data sales, according to prosecutors. He faces sentencing on October 27, with a mandatory minimum of two years on the identity theft charge and up to 30 years on the remaining counts. Victim companies suffered more than $9.5 million in actual losses, a figure that doesn't include losses to their own customers. Stolen information included non-content call and text history, payroll records, Drug Enforcement Administration registration numbers, and passport and Social Security numbers. AT&T confirmed in July 2024 that records of calls and texts for nearly all its cellular customers between May 1 and October 31, 2022 were taken from its workspace on a third-party cloud platform. Prosecutors say Moucka also re-extorted at least one victim, threatening further disclosure using stolen data of a government officer and members of a then-former government officer's immediate family.
Mandiant, which investigated alongside Snowflake and tracks the perpetrator as UNC5537, determined that every incident it worked traced back to customer credentials stolen by infostealers. Some had been harvested as far back as November 2020 and remained valid years later. At least 79.7% of the accounts the group used had prior credential exposure, and the compromised instances had no network allow lists. The firm wrote that the campaign "is not the result of any particularly novel or sophisticated tool, technique, or procedure," attributing the reach to the size of the infostealer market and to credentials left unrotated for as long as four years. W. Mike Herrington, special agent in charge of the FBI's Seattle field office, called the tactics "calculated and predatory." The Justice Department has never named Snowflake in its announcements, identifying the victim only as a U.S. software-as-a-service provider; Snowflake and Mandiant named the platform themselves in 2024.
What allowed the breaches wasn't a technical flaw or exploit in Snowflake's platform. The attackers got in because customers hadn't rotated passwords that infostealer malware had captured years earlier, and because multi-factor authentication was disabled on the accounts. No vulnerability in the software existed—the weakness was in how customers managed access. Of the two men charged in 2024, only Moucka is in U.S. custody; co-defendant John Erin Binns remains outside it as of the court's August 4 case update. Cameron John Wagenius, a former Army soldier prosecutors tied to the same intrusions, pleaded guilty in a related case in July 2025. Snowflake has enforced MFA by default for human users on accounts created since October 2024, but password-only sign-ins aren't gone. Its documentation, checked by The Hacker News on August 6, puts the final phase between August and October 2026, rolling out account by account, when passwords will be blocked as a sole factor for every remaining human and service user; reader and trial accounts are exempt. The incident exposes how credential hygiene failures compound over time when paired with the sprawl of stolen credentials circulating on underground markets. Organizations relying on shared cloud platforms face asymmetric risk when access controls lag behind the threat environment.

