Start with Identity
← Blog
News

The Snowflake attacker pleaded guilty, two years after stale credentials did the work

Connor Riley Moucka pleaded guilty in Seattle federal court on August 6, 2026 to computer fraud, wire fraud, aggravated identity theft, and conspiracy over the 2024 Snowflake customer breaches, which reached at least 165 organizations and 100 million people.

By SWI Community TeamAug 6, 2026Updated Aug 29, 2026

Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty in Seattle federal court on August 6, 2026 to computer fraud, wire fraud, aggravated identity theft, and conspiracy over the 2024 Snowflake customer breaches. At least 165 organizations were compromised and records on at least 100 million people exposed, including nearly all AT&T cellular customers for a six-month window in 2022. There was no Snowflake platform vulnerability. The credentials came from infostealer logs harvested years earlier, the accounts had MFA disabled, and some passwords had gone unrotated for four years. Prosecutors put Moucka's personal proceeds at 495,000 dollars and victim losses above 9.5 million.

Why it matters

The plea closes the loop on the cleanest case study in identity security. No exploit, no zero-day, no clever technique: infostealer logs bought or scraped, credentials that still worked years after theft, and tenants where MFA was optional and nobody enforced it. Sentencing is set for October 27, 2026, with a two-year mandatory minimum on the identity theft count. The durable lesson is about the shelf life of a stolen credential. A password taken in 2020 that still authenticates in 2024 is not a breach of the platform, it is a governance failure at the customer. Enforce MFA on every data-platform account including service accounts, rotate on a schedule you actually verify, and monitor infostealer dumps for your own domains. Full teardown: Snowflake 2024.

Source: The Hacker News

Last reviewed By SWI Community TeamSuggest a correctionHow we research
Independent analysis. No vendor sponsorship.