[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fwaaxHPjU_0bJiX4ojbAXhVdNsoLOUuEzBcpIZEvAyXA":3},{"article":4,"iocs":56},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"b94230bb-dd9a-4ec9-85cb-944ca7b7c5ff","Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People","snowflake-hacker-pleads-guilty-over-breaches-affecting-at-least-100-million-peop-b41d69","Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy over the 2024 breaches of Snowflake customer accounts. The intrusions reached at least 165 organizations and exposed records belonging to at least 100 million people. Moucka, 26, of Kitchener, Ontario, personally took at least $495,000 from","Connor Riley Moucka has pleaded guilty to multiple charges related to the 2024 breaches of Snowflake customer accounts, which impacted at least 165 organizations and exposed data of over 100 million individuals. The attacks exploited old, unrotated passwords harvested by infostealer malware, with multi-factor authentication disabled on compromised accounts. Moucka personally profited at least $495,000 from ransoms and data sales.","Snowflake hacker pleads guilty to computer fraud over 2024 breaches affecting 100M+ people.","Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People Swati KhandelwalAug 06, 2026Cybercrime \u002F Law Enforcement Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy over the 2024 breaches of Snowflake customer accounts. The intrusions reached at least 165 organizations and exposed records belonging to at least 100 million people. Moucka, 26, of Kitchener, Ontario, personally took at least $495,000 from ransoms and data sales. He is due to be sentenced on October 27 and faces a two-year mandatory minimum on the identity theft count and up to 30 years on the rest. What got the attackers in was old passwords. The credentials had been harvested years earlier by infostealer malware and never rotated, and the accounts had multi-factor authentication (MFA) switched off. No exploit, no flaw in the platform. The Justice Department has never named the company, in Wednesday's announcement or in the October 2024 indictment, identifying the victim only as a U.S. software-as-a-service (SaaS) provider. Snowflake and Mandiant named the platform themselves in 2024. Moucka also re-extorted at least one victim, prosecutors said, threatening further disclosure using the stolen data of a government officer and members of a then-former government officer's immediate family. The department named neither. W. Mike Herrington, special agent in charge of the FBI's Seattle field office, called the tactics \"calculated and predatory.\" Mandiant, which investigated alongside Snowflake and tracks the actor as UNC5537, found that every incident it worked traced back to customer credentials stolen by infostealers. Some had been harvested as far back as November 2020 and were still valid years later. At least 79.7% of the accounts the group used had prior credential exposure, and the compromised instances had no network allow lists. The campaign, the firm wrote, \"is not the result of any particularly novel or sophisticated tool, technique, or procedure.\" It put the reach down to the size of the infostealer market and to credentials left unrotated for as long as four years. The 165 figure has changed meaning since 2024. It began as a notification count, the number of organizations Mandiant and Snowflake notified as potentially exposed; prosecutors now use it for customers actually compromised. The release does not settle on one figure either, citing over 165 organizations in the body while Assistant Attorney General A. Tysen Duva's statement says over 150. Victim companies suffered more than $9.5 million in actual losses, a figure that excludes losses to their own customers. What went out included non-content call and text history, payroll records, Drug Enforcement Administration (DEA) registration numbers, passport and Social Security numbers. AT&T confirmed in July 2024 that records of calls and texts for nearly all its cellular customers between May 1 and October 31, 2022 were taken from its workspace on a third-party cloud platform. Of the two men charged in 2024, only Moucka is in U.S. custody. Co-defendant John Erin Binns remains outside it as of the court's August 4 case update. Cameron John Wagenius, the former Army soldier prosecutors have tied to the same intrusions, pleaded guilty in a related case in July 2025. Snowflake has enforced MFA by default for human users on accounts created since October 2024, but password-only sign-ins are not gone. Its documentation, checked by The Hacker News on August 6, puts the final phase between August and October 2026, rolling out account by account. Only then are passwords blocked as a sole factor for every remaining human and service user. Reader and trial accounts are exempt. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Authentication Security, Cloud security, Cybercrime, data breach, identity theft, law enforcement, Malware, SaaS Security ⚡ Top Stories This Week New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable ⭐ Featured Resources [Webinar] How Militaries Can Trust the Data Behind Autonomous Missions Download the 5-Step Action Plan for AI-Speed Exploitation Get the Checklist for Gaining Control of AI Use Across Your Organization Get the 2026 CISO Benchmark Report Based on 600 Security Leaders","https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fsnowflake-hacker-pleads-guilty-over.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEimtSQSbHZnqrcub_RlfzViiiKRKyucYCIYf0nqt0aWqcYJgY122xGjIRDGnvpYukopZM9DuEPjN6Lax97qyYIghxfFb_faULxhabuOJHBOVbyycVBNUVHAbb5Z8LRfnG_5xrwH__9Jbs6qmPEdopvRysLduoAn0hoANFRnNd2g24zqBTfCUK4WXtDx7eg\u002Fs1600\u002Fsnowflake-hacker.jpg","2026-08-06T06:04:30+00:00","2026-08-06T08:00:10.317806+00:00",9,[18,21,24,27,29,31],{"name":19,"type":20},"UNC5537","threat_actor",{"name":22,"type":23},"Snowflake","vendor",{"name":25,"type":26},"Snowflake customer accounts","product",{"name":28,"type":20},"Connor Riley Moucka",{"name":30,"type":20},"John Erin Binns",{"name":32,"type":20},"Cameron John Wagenius","2e06f76c-d5b9-4f54-9eef-4d3447b10730",{"id":33,"icon":35,"name":36,"slug":37},null,"Breaches","breaches",[39,44,46,51],{"category":40},{"id":41,"icon":35,"name":42,"slug":43},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":45},{"id":33,"icon":35,"name":36,"slug":37},{"category":47},{"id":48,"icon":35,"name":49,"slug":50},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":52},{"id":53,"icon":35,"name":54,"slug":55},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[57],{"type":50,"value":58,"context":59},"infostealer","Malware used to harvest credentials for the Snowflake breaches."]