>samit_hota
Back to security news

Security News · SN-2026-317

HIGHRESOLVED

Snowflake Hacker Connor Moucka Pleads Guilty to Extorting 165 Organizations

Affected: Snowflake tenant accounts · AT&T · Ticketmaster · Santander · Neiman Marcus · Advance Auto Parts · LendingTree

Samit Hota·
#news#vulnerability-disclosure#snowflake

Connor Riley Moucka, a 26-year-old Canadian national from Kitchener, Ontario, has pleaded guilty in a Washington state federal court to computer fraud, wire fraud, aggravated identity theft, and conspiracy charges for his central role in the 2024 Snowflake data breach campaign. Extradited to the United States in July 2025 following his November 2024 arrest in Canada, Moucka now faces up to 32 years in federal prison, with formal sentencing scheduled for October 27. The systemic campaign compromised at least 165 corporate cloud data warehouse environments between February and October 2024, resulting in the theft of billions of sensitive records, multi-million dollar extortion schemes, and significant operational disruption.

Mechanism of the Snowflake Account Compromises

While early reports sparked fears of a zero-day vulnerability or architectural flaw within Snowflake’s cloud platform, forensic investigations conducted by Google’s Mandiant unit confirmed that Snowflake’s core software infrastructure was never breached. Instead, the threat actor group—operating out of North America with a collaborator in Turkey—executed an extensive credential-driven attack using stolen, still-valid administrative and user credentials dating back as far as 2020.

The vulnerability class in this campaign was pure identity and authentication abuse, exploiting tenant environments that failed to enforce Multi-Factor Authentication (MFA) or Single Sign-On (SSO) restrictions. The compromised login details were harvested over several years by malware operators using infostealers such as RedLine, Lumma, and Vidar. Because cloud data warehouse architecture aggregates raw databases, telemetry logs, and customer datastores into a single central interface, attackers using tools like SnowSQL were able to authenticate directly as legitimate users, exfiltrating massive volumes of structured data without raising software-level security alerts.

Mandiant’s analysis linked the operation to North American threat actors collaborating with Turkish national John Erin Binns, who was detained by Turkish authorities in 2024 after being indicted for his involvement in a previous intrusion targeting telecom giant T-Mobile.

Scale of Data Theft and Impacted Organizations

The attack targeted high-profile enterprises across retail, finance, entertainment, and telecommunications, resulting in one of the largest combined data exposure events of recent years. The stolen datasets included customer banking records, financial transactions, Social Security numbers, driver’s license details, passport numbers, and Drug Enforcement Administration (DEA) registration numbers.

The victim list and record counts confirmed in court proceedings include:

  • AT&T: Call and text interaction logs corresponding to more than 100 million mobile customers.
  • Ticketmaster: Extensive customer database records affecting approximately 560 million users.
  • Additional High-Profile Victims: Santander Bank, luxury retailer Neiman Marcus, automotive supplier Advance Auto Parts, financial service provider LendingTree, and one of the largest public school districts in the United States.

Court filings show that the overall monetary damage inflicted on victim companies reached approximately $9.5 million in mitigation and operational recovery expenses.

Extortion, Re-Extortion, and Forum Sales

Following the exfiltration of bulk database files, Moucka and his co-conspirators initiated a double-extortion strategy, threatening to leak sensitive corporate records unless high ransoms were paid. The threat group successfully obtained roughly $2.5 million in ransom payments from victim entities.

Demonstrating the predatory nature of the campaign, Moucka engaged in secondary extortion against at least one victim company that had already been targeted. In that re-extortion attempt, prosecutors noted that Moucka personally weaponized stolen personal data belonging to a government official and members of the official’s immediate family to force compliance.

Beyond direct extortion, Moucka accrued an additional $495,000 by advertising and selling exfiltrated enterprise databases on cybercrime trading hubs, specifically BreachForums and XSS.is. Prior to his arrest, Moucka gave an interview to the technology outlet 404Media, where he admitted that he anticipated his imminent detainment and claimed to be actively destroying digital evidence and storage media.

Mitigating Identity Exposure in Cloud Warehouses

The Snowflake breaches highlight the severe blast radius associated with centralized cloud storage when single-factor authentication is permitted on administrative or database user accounts. Because data lakes collect heterogeneous enterprise data into a single queryable environment, a single compromised set of legacy credentials can result in complete data loss across an enterprise.

To mitigate this attack surface, cloud infrastructure administrators must:

  1. Enforce mandatory, network-level or WebAuthn/FIDO2 multi-factor authentication across all tenant accounts, disallowing local password-only authentication.
  2. Implement strict Snowflake Network Policies and Network Rules to restrict platform access strictly to authorized corporate IP ranges or VPN gateways.
  3. Audit and purge stale user credentials, legacy service accounts, and session tokens that may exist in historical infostealer log repositories.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call