Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Disney agrees deal to let TikTokers use its characters in videos

    August 6, 2026

    Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells

    August 6, 2026

    Crypto project shutdowns as banks build controlled rails

    August 6, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Disney agrees deal to let TikTokers use its characters in videos
    • Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
    • Crypto project shutdowns as banks build controlled rails
    • Jute loses ground to plastic despite Bangladesh’s packaging law
    • Offshore substation, export cable works completed at Taiwan’s Fengmiao 1 OWF
    • Rebecca Cooke’s money machine, delayed disclosure shape Wisconsin’s tightest House race • OpenSecrets
    • Should I try the ‘18 summers’ parenting trend? Only if I want to ruin the school holidays | Emma Brockes
    • Tarun Tejpal: Journalist who founded Tehelka magazine convicted in rape case
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, August 6
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 6, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalAug 06, 2026Cybercrime / Law Enforcement

    Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy over the 2024 breaches of Snowflake customer accounts.

    The intrusions reached at least 165 organizations and exposed records belonging to at least 100 million people. Moucka, 26, of Kitchener, Ontario, personally took at least $495,000 from ransoms and data sales.

    He is due to be sentenced on October 27 and faces a two-year mandatory minimum on the identity theft count and up to 30 years on the rest.

    What got the attackers in was old passwords. The credentials had been harvested years earlier by infostealer malware and never rotated, and the accounts had multi-factor authentication (MFA) switched off. No exploit, no flaw in the platform.

    The Justice Department has never named the company, in Wednesday’s announcement or in the October 2024 indictment, identifying the victim only as a U.S. software-as-a-service (SaaS) provider. Snowflake and Mandiant named the platform themselves in 2024.

    Cybersecurity

    Moucka also re-extorted at least one victim, prosecutors said, threatening further disclosure using the stolen data of a government officer and members of a then-former government officer’s immediate family.

    The department named neither. W. Mike Herrington, special agent in charge of the FBI’s Seattle field office, called the tactics “calculated and predatory.”

    Mandiant, which investigated alongside Snowflake and tracks the actor as UNC5537, found that every incident it worked traced back to customer credentials stolen by infostealers. Some had been harvested as far back as November 2020 and were still valid years later. At least 79.7% of the accounts the group used had prior credential exposure, and the compromised instances had no network allow lists.

    The campaign, the firm wrote, “is not the result of any particularly novel or sophisticated tool, technique, or procedure.” It put the reach down to the size of the infostealer market and to credentials left unrotated for as long as four years.

    The 165 figure has changed meaning since 2024. It began as a notification count, the number of organizations Mandiant and Snowflake notified as potentially exposed; prosecutors now use it for customers actually compromised.

    The release does not settle on one figure either, citing over 165 organizations in the body while Assistant Attorney General A. Tysen Duva’s statement says over 150. Victim companies suffered more than $9.5 million in actual losses, a figure that excludes losses to their own customers.

    Cybersecurity

    What went out included non-content call and text history, payroll records, Drug Enforcement Administration (DEA) registration numbers, passport and Social Security numbers. AT&T confirmed in July 2024 that records of calls and texts for nearly all its cellular customers between May 1 and October 31, 2022 were taken from its workspace on a third-party cloud platform.

    Of the two men charged in 2024, only Moucka is in U.S. custody. Co-defendant John Erin Binns remains outside it as of the court’s August 4 case update. Cameron John Wagenius, the former Army soldier prosecutors have tied to the same intrusions, pleaded guilty in a related case in July 2025.

    Snowflake has enforced MFA by default for human users on accounts created since October 2024, but password-only sign-ins are not gone. Its documentation, checked by The Hacker News on August 6, puts the final phase between August and October 2026, rolling out account by account. Only then are passwords blocked as a sole factor for every remaining human and service user. Reader and trial accounts are exempt.

    Affecting Breaches guilty Hacker Million People pleads Snowflake
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells

    Why security validation must follow the attack path

    Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports

    Canadian pleads guilty to Snowflake cloud data-theft attacks

    Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt

    Security validation should begin where attackers begin

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Disney agrees deal to let TikTokers use its characters in videos

    August 6, 2026

    Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells

    August 6, 2026

    Crypto project shutdowns as banks build controlled rails

    August 6, 2026

    Jute loses ground to plastic despite Bangladesh’s packaging law

    August 6, 2026
    Latest Posts

    Can you identify Taylor Farms products by codes beginning with ‘TF’ printed on bags?

    July 23, 2026

    The Guardian view on Britain’s uninhabitable homes: as temperatures rise, a new approach is needed | Editorial

    July 23, 2026

    Can Wisconsin voters void a returned absentee ballot?

    July 23, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Disney agrees deal to let TikTokers use its characters in videos

    August 6, 2026

    Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells

    August 6, 2026

    Crypto project shutdowns as banks build controlled rails

    August 6, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.