The Snowflake attacker pleaded guilty, two years after stale credentials did the work
Connor Riley Moucka pleaded guilty in Seattle federal court on August 6, 2026 to computer fraud, wire fraud, aggravated identity theft, and conspiracy over the 2024 Snowflake customer breaches, which reached at least 165 organizations and 100 million people.
Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty in Seattle federal court on August 6, 2026 to computer fraud, wire fraud, aggravated identity theft, and conspiracy over the 2024 Snowflake customer breaches. At least 165 organizations were compromised and records on at least 100 million people exposed, including nearly all AT&T cellular customers for a six-month window in 2022. There was no Snowflake platform vulnerability. The credentials came from infostealer logs harvested years earlier, the accounts had MFA disabled, and some passwords had gone unrotated for four years. Prosecutors put Moucka's personal proceeds at 495,000 dollars and victim losses above 9.5 million.
Why it matters
The plea closes the loop on the cleanest case study in identity security. No exploit, no zero-day, no clever technique: infostealer logs bought or scraped, credentials that still worked years after theft, and tenants where MFA was optional and nobody enforced it. Sentencing is set for October 27, 2026, with a two-year mandatory minimum on the identity theft count. The durable lesson is about the shelf life of a stolen credential. A password taken in 2020 that still authenticates in 2024 is not a breach of the platform, it is a governance failure at the customer. Enforce MFA on every data-platform account including service accounts, rotate on a schedule you actually verify, and monitor infostealer dumps for your own domains. Full teardown: Snowflake 2024.
Source: The Hacker News
Related on Start with Identity
- BlogMcKesson breach started with vishing against Okta SSO, then reached Salesforce and Snowflake
ShinyHunters social-engineered McKesson employees from a lookalike domain, took their Okta credentials, and used the SSO session to reach Salesforce and Snowfla
- BlogCisco FMC shipped with hardcoded credentials, and attackers found them before the patch did
CVE-2026-20316 is a low-privileged account with credentials hardcoded into Cisco Secure Firewall Management Center, giving unauthenticated remote attackers acce
- BlogA two-finger gesture let anyone holding a locked Android phone send SMS through Gemini, no PIN needed
A multi-touch gesture on Android 16's lock screen let anyone with physical access to a phone bypass the PIN prompt Gemini shows before sending SMS or WhatsApp m
- GlossaryClient Credentials Grant
An OAuth 2.0 flow where an application authenticates as itself, with no user present, to obtain an access token. The standard pattern for machine-to-machine acc
- GlossaryDecentralized Identifier (DID)
A W3C standard identifier that a subject controls without a central registry, resolvable to a document with keys and endpoints. A building block of decentralize
- StandardDecentralized Identifiers (DID)
Decentralized Identifiers are identifiers a subject controls without a central registry, resolving to a document of public keys and endpoints. They anchor the t