Connor Riley Moucka, known as the Snowflake hacker, paid the price for his actions in federal court in Seattle, where he pleaded guilty to computer fraud, wire fraud, identity theft and conspiracy in connection with the massive breaches of Snowflake in 2024. Those attacks affected at least 165 organizations and exposed data belonging to at least 100 million people, making the case one of the largest cybercrime cases of the past decade.
See also: Snowflake makes MFA mandatory on all accounts

Moucka , 26, of Kitchener , Ontario , personally collected at least $495,000 from ransom payments and the sale of stolen data. The overall extortion campaign generated more than $2.5 million in ransom payments, while the victim companies recorded actual losses of more than $9.5 million , not including losses to their own customers. He is scheduled to be sentenced on Oct. 27 and faces a mandatory minimum sentence of two years for the identity theft count and up to 30 years on the other counts.
What makes the case particularly significant from a technical perspective is that no vulnerability in Snowflake. The attackers used old passwords that had been collected years earlier by the infostealer malware and had never been changed, and multi-factor authentication (MFA) was disabled. Snowflake and Mandiant, which conducted the investigation in parallel, confirmed that there was no bug or misconfiguration in the product itself.
How the Snowflake hacker exploited stolen credentials
Mandiant , which tracks the perpetrator as UNC5537 , found that each incident was traced back to customer credentials stolen by infostealers . Some credentials had been collected as early as November 2020 and remained valid years later. At least 79.7% of the accounts used had a prior credential leak, and the compromised instances did not have network allow lists. The campaign did not rely on any particularly original or sophisticated tool — its scale was due to the size of the infostealer market and the credentials remaining unchanged for up to four years .
The stolen data included call and text history, banking information, payroll records, Drug Enforcement Administration (DEA), passport numbers, Social Security numbers, and other personal information. AT&T confirmed in July 2024 that call and text records of nearly all of its mobile customers for the period May 1 to October 31, 2022, were removed from its workspace to a third-party cloud platform. The stolen data was advertised and sold on BreachForums, Exploit.in, XSS.is , and Telegram.
Moucka didn’t stop with the initial blackmail. He re-extorted at least one victim, threatening further disclosure using stolen data from a government official and family members of a former government official. W. Mike Herrington , special agent in charge of the FBI ’s Seattle office , called the tactics “ calculated and predatory .”
See also: USA: Charges against “Snowflake hackers”

Snowflake hacker: The consequences and responsibility for cloud security
The case highlights a critical issue in the shared responsibility modelofcloud platforms. Snowflake, CrowdStrike and Mandiant stressed that the activity was not caused by a vulnerability, misconfiguration or malicious activity within Snowflake. There was also no evidence that the activity was caused by compromised credentials of current or former Snowflake. The message is clear: cloud platforms can be compromised when customers do not adequately protect their accounts with strong MFA, credential hygiene and monitoring.
Of the two men charged in 2024, only Moucka is in U.S. custody. Co-defendant John Erin Binns remains out of custody , according to an August 4 case update . Cameron John Wagenius , a former U.S. Army soldier linked to the same hacks, pleaded guilty in a related case in July 2025. Snowflake has enforced MFA as the default for human users on accounts created since October 2024 , but password-only logins have not been completely eliminated. The final phase is expected to be completed between August and October 2026 .
The case is part of a broader pattern of identity-based cloud, where valid credentials, session tokens, or weak authentication are exploited instead of software vulnerabilities. This pattern is a growing threat to organizations worldwide, including Greek businesses that use cloud data storage services. This campaign demonstrates that even without a zero-day exploit, the scale of the damage can be enormous when credentials remain exposed for years.
Practical recommendations for protection against Snowflake hacker attacks
To protect against similar attacks, organizations should take immediate action. First, enforcing phishing-resistant MFA on all cloud and administrative accounts is absolutely essential, especially for data platforms and SSO. Second, regularly rotating and auditing credentials for service accounts, API keys, and human users is critical, especially if there is a potential for reuse across multiple services. This particular attack relied solely on stolen login credentials that remained intact for up to four years.
Additionally, monitoring for unusual access and bulk exports from cloud data warehouses — including high query volumes, non-standard IP addresses, impossible travel, and after-hours access — is crucial. Implementing a least privilege approachandseparating access to sensitive datasets ensures that a single account breach cannot expose entire customer databases. Finally, maintaining robust loggingandresponding quickly to incidents allows for early detection of credential abuse and preservation of evidence for law enforcement.
See also: Snowflake breach: Suspect arrested for attacks

Moucka ’s guilty plea is a major milestone in the prosecution of cybercriminals targeting cloud infrastructure. However, the real victory for cybersecurity will only come when organizations seriously address third-party and employee credential exposure as a primary risk — because this case proves that it doesn’t take a CVE to cause a catastrophic data breach .
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
