2 min read

Snowflake attacker pleads guilty in massive data theft

A Canadian man pleaded guilty to Snowflake data theft affecting over 100 million people after attackers used stolen credentials against accounts without MFA.

Image: BleepingComputer

A Canadian man has pleaded guilty to helping access Snowflake customer accounts and steal data from at least 165 organizations, in a campaign that extorted millions of dollars from victims and affected more than 100 million people.

Connor Riley Moucka, 26, also known as Alexander Moucka and Waifu, was arrested on October 30, 2024. Between February and October 2024, he and co-defendant John Erin Binns accessed Snowflake accounts that lacked multi-factor authentication (MFA), using usernames and passwords stolen by infostealer malware.

How the Snowflake attacks worked

Without MFA, the attackers needed only valid credentials to enter customer accounts. They used custom software to identify valuable details inside cloud storage environments, including organization names, user roles, and IP addresses.

Moucka and Binns then stole terabytes of data and attempted to extort multiple companies. The stolen information included:

Recommended reading

AI agent frameworks exposed by 11 old-school flaws

  • Call and text history records, excluding message content
  • Banking, financial, and payroll records
  • Drug Enforcement Administration registration numbers
  • Driver’s license, passport, and Social Security numbers
  • Other personally identifiable information

The attackers obtained at least $2.5 million in bitcoin from at least three victims. Moucka also earned at least $495,000 by advertising stolen data on hacker forums for sale in fiat currency or cryptocurrency.

The U.S. Department of Justice said Moucka used stolen data belonging to a government officer and members of a former government officer’s immediate family in an attempt to re-extort a victim.

“In at least one instance, Moucka re-extorted a victim with threats of further disclosure of the victim’s stolen data.”

U.S. Department of Justice

The DOJ says victim companies suffered more than $9.5 million in losses. The affected organizations include AT&T, Ticketmaster, Santander, Pure Storage, Advance Auto Parts, Los Angeles Unified, QuoteWizard/LendingTree, and Neiman Marcus.

Guilty plea and security changes

Moucka pleaded guilty to four counts: computer fraud, wire fraud, aggravated identity theft, and a related conspiracy. He is scheduled to be sentenced on October 27 and faces a maximum sentence of 32 years in prison.

Binns, who lived in Turkey during the attacks, was arrested there. A local court approved a U.S. extradition request, but Binns contested it.

After the breaches, Snowflake announced that it would enforce MFA and require passwords to contain at least 14 characters. The case puts a concrete limit on Snowflake’s previously reported trust-and-data defenses: stolen credentials remained enough to unlock customer environments when MFA was absent.

Article image
Article image
Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

via BleepingComputer

/ Keep reading