discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People

A hacker, Connor Riley Moucka, pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy over the 2024 breaches of Snowflake customer accounts. The intrusions reached at least 165 organizations and exposed records belonging to at le…

By Swati Khandelwal·Aug 6·thehackernews.com·2 min read

Intelligence analysis by Llama

Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People
Image: thehackernews.com

A hacker, Connor Riley Moucka, pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy over the 2024 breaches of Snowflake customer accounts. The intrusions reached at least 165 organizations and exposed records belonging to at least 100 million people. The hacker used old passwords that had been harvested years earlier by infostealer malware …

Why it matters

This story matters because it highlights the importance of rotating passwords and enabling multi-factor authentication to prevent data breaches. It also shows the consequences of not taking cybersecurity seriously, with at least 100 million people affected by the breaches.

Imagine you have a super-long password that you never change. A hacker can use a special kind of malware to steal that password and use it to get into your account. This is what happened to Snowflake's customers, and it's a big problem because it can expose a lot of sensitive information. To stay safe, it's essential to change your passwords regularly and use extra security like two-factor authentication.

Analysis

A $60B Vote of Confidence

The recent guilty plea of Connor Riley Moucka, a hacker involved in the 2024 breaches of Snowflake customer accounts, has shed light on the severity of the incident. The intrusions, which reached at least 165 organizations, exposed records belonging to at least 100 million people. This is a stark reminder of the importance of cybersecurity and the need for organizations to take proactive measures to protect their data.

Why Credential Exposure Matters

The investigation found that every incident it worked on traced back to customer credentials stolen by infostealers. Some of these credentials had been harvested as far back as November 2020 and were still valid years later. This highlights the importance of rotating passwords and enabling multi-factor authentication to prevent data breaches. It also shows that even with multi-factor authentication (MFA) switched off, old passwords can still be a vulnerability.

The Road Ahead

Snowflake has enforced MFA by default for human users on accounts created since October 2024, but password-only sign-ins are not gone. Its documentation puts the final phase between August and October 2026, rolling out account by account. Only then are passwords blocked as a sole factor for every remaining human and service user. This is a step in the right direction, but it's essential for organizations to continue to prioritize cybersecurity and take proactive measures to protect their data.

Key points

  • A hacker, Connor Riley Moucka, pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy over the 2024 breaches of Snowflake customer accounts.
  • The intrusions reached at least 165 organizations and exposed records belonging to at least 100 million people.
  • The hacker used old passwords that had been harvested years earlier by infostealer malware and never rotated, and the accounts had multi-factor authentication (MFA) switched off.
  • Snowflake has enforced MFA by default for human users on accounts created since October 2024, but password-only sign-ins are not gone.
  • The final phase of rolling out account by account is expected to be completed between August and October 2026.
The Upside

The guilty plea of Connor Riley Moucka is a positive step towards holding hackers accountable for their actions. It also highlights the importance of prioritizing cybersecurity and taking proactive measures to protect data. With Snowflake's efforts to enforce MFA by default and roll out password-only sign-ins, there is hope that similar breaches can be prevented in the future.

The Downside

The fact that the hacker was able to use old passwords that had been harvested years earlier by infostealer malware and never rotated is a concerning sign. It shows that even with multi-factor authentication (MFA) switched off, old passwords can still be a vulnerability. This highlights the need for organizations to continue to prioritize cybersecurity and take proactive measures to protect their data.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagscybercrimelaw-enforcementmalwaredata-breachidentity-theftcloud-securitysaaas-security

Author

Swati Khandelwal

Intelligence analysis by

Llama

Published

Aug 6, 2026

Source

thehackernews.com

Share

Topics

cybercrimelaw-enforcementmalwaredata-breachidentity-theftcloud-securitysaaas-security

Related

More from this desk

Aug 6·thehackernews.com

Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells

Vulnerability in Chinese-made routers from Zbtlink detected with backdoors that can be remotely accessed without authentication.

Aug 6·thehackernews.com

Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service

A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison for creating and running Ransom Cartel, the ransomware-as-a-service operation he stood up in 2021.

Aug 5·wired.com

A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide

A security researcher, Vangelis Stykas, gained access to North Korean systems and found evidence of 1,640 companies across 57 countries being impacted by the country's hacking operations. Among these, around 700 to 800 organizations had 'really damaging' intrusions.

Aug 5·bleepingcomputer.com

Ransom Cartel ransomware creator sentenced to 16 years in prison

Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide.