Canadian pleads guilty to Snowflake cloud data-theft attacks
A Canadian man pleaded guilty to accessing Snowflake cloud storage accounts and stealing data from at least 165 organizations. The attackers exploited accounts without multi-factor authentication (MFA) by using stolen credentials obtained via infostealer malware. They stole terabytes of sensitive data, including personally identifiable information and financial records, and extorted victims for millions of dollars in cryptocurrency. Snowflake has since enforced MFA and stronger password requirements to mitigate such attacks.
AI Analysis
Technical Summary
Between February and October 2024, Connor Riley Moucka and an accomplice accessed Snowflake customer accounts lacking MFA by using stolen usernames and passwords obtained through infostealer malware. They extracted valuable information from cloud storage instances using custom software and stole data from at least 165 organizations, affecting over 100 million individuals. The stolen data included call/text history, banking information, payroll records, government registration numbers, and various forms of personally identifiable information. The attackers extorted victims for millions of dollars in bitcoin and sold stolen data on hacker forums. Following these breaches, Snowflake mandated MFA and minimum 14-character passwords for all accounts.
Potential Impact
The unauthorized access led to the theft of sensitive data from hundreds of millions of individuals and caused financial losses exceeding $9.5 million to victim companies. The attackers successfully extorted at least $2.5 million in bitcoin and obtained additional funds through selling stolen data. The breach exposed critical personal and financial information, increasing the risk of identity theft and further extortion. The attacks also included re-extortion attempts targeting government officers using stolen data.
Mitigation Recommendations
Snowflake has implemented mandatory multi-factor authentication and requires passwords to be at least 14 characters long to prevent unauthorized access via stolen credentials. Organizations using Snowflake should ensure MFA is enabled on all accounts and enforce strong password policies. Since the attacks exploited accounts without MFA, enabling MFA is a critical defense. No additional vendor advisories or patches are indicated; the vendor manages remediation through these security policy changes.
Canadian pleads guilty to Snowflake cloud data-theft attacks
Description
A Canadian man pleaded guilty to accessing Snowflake cloud storage accounts and stealing data from at least 165 organizations. The attackers exploited accounts without multi-factor authentication (MFA) by using stolen credentials obtained via infostealer malware. They stole terabytes of sensitive data, including personally identifiable information and financial records, and extorted victims for millions of dollars in cryptocurrency. Snowflake has since enforced MFA and stronger password requirements to mitigate such attacks.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Between February and October 2024, Connor Riley Moucka and an accomplice accessed Snowflake customer accounts lacking MFA by using stolen usernames and passwords obtained through infostealer malware. They extracted valuable information from cloud storage instances using custom software and stole data from at least 165 organizations, affecting over 100 million individuals. The stolen data included call/text history, banking information, payroll records, government registration numbers, and various forms of personally identifiable information. The attackers extorted victims for millions of dollars in bitcoin and sold stolen data on hacker forums. Following these breaches, Snowflake mandated MFA and minimum 14-character passwords for all accounts.
Potential Impact
The unauthorized access led to the theft of sensitive data from hundreds of millions of individuals and caused financial losses exceeding $9.5 million to victim companies. The attackers successfully extorted at least $2.5 million in bitcoin and obtained additional funds through selling stolen data. The breach exposed critical personal and financial information, increasing the risk of identity theft and further extortion. The attacks also included re-extortion attempts targeting government officers using stolen data.
Defensive Guidance
Snowflake has implemented mandatory multi-factor authentication and requires passwords to be at least 14 characters long to prevent unauthorized access via stolen credentials. Organizations using Snowflake should ensure MFA is enabled on all accounts and enforce strong password policies. Since the attacks exploited accounts without MFA, enabling MFA is a critical defense. No additional vendor advisories or patches are indicated; the vendor manages remediation through these security policy changes.
Technical Details
- Classification
- {"confidence":0.75,"severitySource":"heuristic","classifier":"rss-v2"}
Threat ID: 6a73b17dbf8831d53984723f
Added to database: 08/05/2026, 21:56:13 UTC
Last enriched: 08/05/2026, 21:56:23 UTC
Last updated: 08/06/2026, 02:16:04 UTC
Views: 31
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.