Moucka pleaded guilty on August 5, 2026, to four counts in the 165-organization Snowflake breach. He faces an Oct. 27 sentencing, a two-year minimum, and up to 30 years.
Attackers used infostealer-stolen credentials against Snowflake accounts lacking MFA. Snowflake now enforces MFA by default and is enforcing mandatory MFA and phasing out password-only logins completely by October 2026.
Stolen data included Social Security, driver’s license, passport, banking, payroll, and DEA registration records.
Victims lost $9.5 million; conspirators collected $2.5 million in extortion, affecting over 100 million individuals.
A federal guilty plea has confirmed the mechanics behind the Snowflake data theft campaign. On August 5, 2026, Connor Riley Moucka pleaded guilty to a hacking conspiracy that compromised more than 165 organizations. The U.S. Department of Justice said the operation stole billions of sensitive records.
The plea points to no flaw in Snowflake’s platform. Court documents show attackers used credentials stolen by infostealer malware to log into accounts that had no MFA enabled.
This case shows cloud risk often starts on the endpoint, not the platform. Enterprises running SaaS and cloud data platforms should treat credential exposure on managed devices as a direct line into cloud data, not a separate concern.
Moucka, 26, of Kitchener, Ontario, was arrested on October 30, 2024, months after the intrusions began in February 2024. He was extradited from Canada in July 2025 and pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy count.
A co-conspirator, John Erin Binns, was also indicted in connection with the same campaign. Binns resided in Turkey during the attacks and was arrested there. A local court approved his extradition, though the ruling was contested. The FBI investigated the case as part of Operation Riptide, its campaign against cybercrime, cyber-enabled crime, and fraud targeting Americans.
What is Threat Classification?
Threat classification explained: severity, dimensions, and how Hexnode aids investigation.
How attackers got in without breaching Snowflake’s platform
Attackers didn’t need to break Snowflake’s platform. Court documents cited by BleepingComputer show a simple sequence:
Credential source: Login credentials came from infostealer malware, not a flaw in Snowflake’s infrastructure.
Missing control: Targeted accounts had no MFA enrolled, so a correct username and password alone granted access.
Reconnaissance: Once inside, attackers ran custom software to identify valuable information in each tenant environment, including organization names, user roles, and IP addresses.
This is a credential-access story, not a software-vulnerability story. It shows why identity security and endpoint hygiene sit upstream of cloud data protection.
Snowflake data theft: From access to extortion
The group downloaded terabytes of data, including call and text history records, banking information, payroll records, DEA registration numbers, driver’s license and passport numbers, and Social Security numbers, then threatened victims with public disclosure.
Beyond the reported $2.5 million in ransom payments, Moucka re-extorted one victim using data tied to a government officer and a former officer’s immediate family. The group also sold records on BreachForums, Exploit.in, XSS.is, and Telegram, netting Moucka $495,000 personally. That customer toll reached at least 100 million individuals, per the DOJ.
Attack stage
What happened
Operational risk
Initial Access
Infostealer-sourced credentials used against accounts without MFA
Custom tooling identified organization names, user roles, and IP addresses inside each tenant
Custom tooling helps attackers prioritize high-value data instead of searching manually
Exfiltration and Extortion
Terabytes of PII downloaded and used for extortion or resale
A credential breach converts directly into financial and legal exposure
Snowflake’s post-breach authentication changes
Snowflake tightened authentication after the breaches came to light:
MFA by default: New accounts require human users to enroll in MFA starting October 2024.
Stronger passwords: Minimum password length rose to 14 characters for all new and changed passwords.
Password-only login retiring: Final enforcement runs between August and October 2026, eliminating password-only sign-in entirely.
These changes close the MFA gap the Moucka case exploited. They don’t address how credentials were stolen, since infostealer malware operates at the endpoint, outside Snowflake’s platform boundary.
Closing the identity gap: Where Hexnode fits
Infostealer malware runs on an endpoint long before stolen credentials ever reach a cloud platform. Hexnode addresses that earlier stage:
Endpoint hardening:Hexnode UEM enforces device compliance, application controls, and patch posture across Windows, macOS, Linux, and mobile endpoints, shrinking the exposure surface infostealer droppers rely on.
Endpoint investigation:Hexnode XDR investigates suspicious activity on managed endpoints, primarily Windows, giving admins visibility into potential post-compromise behavior.
Conditional access: For Microsoft Entra ID conditional access, Hexnode reports device compliance data for Android, iOS, and macOS (gating cloud access behind device health), while Windows compliance can be governed directly via integrated policies.
Hexnode doesn’t detect activity within Snowflake or any SaaS application, and it doesn’t ingest identity provider telemetry beyond the documented integrations. It complements vendor-side MFA enforcement and cloud audit logging, not replaces them.
Featured resource
Introduction to Hexnode XDR
Hexnode XDR unifies endpoint detection, UEM integration, and automated remediation for faster enterprise-wide threat response.
Did the attackers exploit a vulnerability in Snowflake’s platform?
No. No CVE or platform flaw has been identified in connection with this case; only stolen credentials were used against accounts without MFA.
What should organizations do if they suspect infostealer exposure?
Rotate affected passwords and API tokens, enforce MFA across all cloud accounts, and review endpoint logs for signs of credential-stealing malware.
Is Snowflake still allowing password-only logins?
On some existing accounts, yes, but only during the current transition. Snowflake is actively enforcing mandatory MFA across remaining legacy accounts, with full retirement of password-only sign-ins concluding by October 2026.
Conclusion
The Snowflake data theft case shows how far a single set of stolen credentials can travel when MFA is absent. What began as infostealer activity on an endpoint culminated in a breach affecting 165 organizations, extortion attempts, and losses exceeding $9.5 million.
The practical response is straightforward: close MFA gaps across every SaaS platform, tighten credential hygiene at the endpoint, and route device compliance into access decisions wherever possible. Investigation and exposure management matter as much as the initial fix.
Stop stolen credentials at the endpoint
See how device compliance and endpoint visibility reduce cloud account risk.
A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions—without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable—politely.