Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People
A hacker, Connor Riley Moucka, pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy over the 2024 breaches of Snowflake customer accounts. The intrusions reached at least 165 organizations and exposed records belonging to at le…
Intelligence analysis by Llama

A hacker, Connor Riley Moucka, pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy over the 2024 breaches of Snowflake customer accounts. The intrusions reached at least 165 organizations and exposed records belonging to at least 100 million people. The hacker used old passwords that had been harvested years earlier by infostealer malware …
Imagine you have a super-long password that you never change. A hacker can use a special kind of malware to steal that password and use it to get into your account. This is what happened to Snowflake's customers, and it's a big problem because it can expose a lot of sensitive information. To stay safe, it's essential to change your passwords regularly and use extra security like two-factor authentication.
Analysis
A $60B Vote of Confidence
The recent guilty plea of Connor Riley Moucka, a hacker involved in the 2024 breaches of Snowflake customer accounts, has shed light on the severity of the incident. The intrusions, which reached at least 165 organizations, exposed records belonging to at least 100 million people. This is a stark reminder of the importance of cybersecurity and the need for organizations to take proactive measures to protect their data.
Why Credential Exposure Matters
The investigation found that every incident it worked on traced back to customer credentials stolen by infostealers. Some of these credentials had been harvested as far back as November 2020 and were still valid years later. This highlights the importance of rotating passwords and enabling multi-factor authentication to prevent data breaches. It also shows that even with multi-factor authentication (MFA) switched off, old passwords can still be a vulnerability.
The Road Ahead
Snowflake has enforced MFA by default for human users on accounts created since October 2024, but password-only sign-ins are not gone. Its documentation puts the final phase between August and October 2026, rolling out account by account. Only then are passwords blocked as a sole factor for every remaining human and service user. This is a step in the right direction, but it's essential for organizations to continue to prioritize cybersecurity and take proactive measures to protect their data.
Key points
- A hacker, Connor Riley Moucka, pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy over the 2024 breaches of Snowflake customer accounts.
- The intrusions reached at least 165 organizations and exposed records belonging to at least 100 million people.
- The hacker used old passwords that had been harvested years earlier by infostealer malware and never rotated, and the accounts had multi-factor authentication (MFA) switched off.
- Snowflake has enforced MFA by default for human users on accounts created since October 2024, but password-only sign-ins are not gone.
- The final phase of rolling out account by account is expected to be completed between August and October 2026.
The guilty plea of Connor Riley Moucka is a positive step towards holding hackers accountable for their actions. It also highlights the importance of prioritizing cybersecurity and taking proactive measures to protect data. With Snowflake's efforts to enforce MFA by default and roll out password-only sign-ins, there is hope that similar breaches can be prevented in the future.
The fact that the hacker was able to use old passwords that had been harvested years earlier by infostealer malware and never rotated is a concerning sign. It shows that even with multi-factor authentication (MFA) switched off, old passwords can still be a vulnerability. This highlights the need for organizations to continue to prioritize cybersecurity and take proactive measures to protect their data.



