CyberSecurityBoardThreat Intel · CVEs · Products
Cyber News

Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People

August 6, 2026

Connor Riley Moucka, a 26-year-old Canadian national, pleaded guilty in Seattle federal court to computer fraud, wire fraud, aggravated identity theft, and conspiracy charges related to the 2024 Snowflake customer data breaches. The attacks compromised at least 165 organizations and exposed records of over 100 million individuals. Moucka personally profited at least $495,000 from ransoms and data sales. He faces a mandatory minimum of two years for identity theft and up to 30 years for other charges, with sentencing scheduled for October 27.

The breaches were enabled by stolen credentials harvested by infostealer malware, some as early as November 2020, which were never rotated. Accounts lacked multi-factor authentication (MFA) and network allow lists. Mandiant, which investigated with Snowflake and tracks the actor as UNC5537, found no novel exploitation—only the scale of the infostealer market and poor credential hygiene. At least 79.7% of accounts had prior credential exposure.

Prosecutors noted Moucka re-extorted at least one victim, threatening to leak data of a government officer and a former officer’s family. The Justice Department did not name the victim company, but Snowflake and Mandiant identified it as a U.S. SaaS provider. Victim losses exceeded $9.5 million, excluding downstream customer impact. Exfiltrated data included call and text records, payroll, DEA registration numbers, passport and Social Security numbers. AT&T confirmed in July 2024 that call records for nearly all its cellular customers were taken from a third-party cloud workspace.

Co-defendant John Erin Binns remains outside U.S. custody, while Cameron John Wagenius pleaded guilty in a related case in July 2025. Snowflake has enforced MFA by default for new accounts since October 2024, with password-only sign-ins being phased out by August–October 2026. This case underscores the critical importance of credential rotation and MFA enforcement.

CVEs: CVE-2026-50522

Attack groups: UNC5537

Malware: infostealer

Companies: Snowflake, Mandiant, AT&T