Sophia
Hart

Snowflake Data Theft Case: Guilty Plea Exposes MFA Gaps

Sophia Hart

Aug 6, 2026

5 min read

snowflake data theft

TL; DR

  • Moucka pleaded guilty on August 5, 2026, to four counts in the 165-organization Snowflake breach. He faces an Oct. 27 sentencing, a two-year minimum, and up to 30 years.
  • Attackers used infostealer-stolen credentials against Snowflake accounts lacking MFA. Snowflake now enforces MFA by default and is enforcing mandatory MFA and phasing out password-only logins completely by October 2026.
  • Stolen data included Social Security, driver’s license, passport, banking, payroll, and DEA registration records.
  • Victims lost $9.5 million; conspirators collected $2.5 million in extortion, affecting over 100 million individuals.

A federal guilty plea has confirmed the mechanics behind the Snowflake data theft campaign. On August 5, 2026, Connor Riley Moucka pleaded guilty to a hacking conspiracy that compromised more than 165 organizations. The U.S. Department of Justice said the operation stole billions of sensitive records.

The plea points to no flaw in Snowflake’s platform. Court documents show attackers used credentials stolen by infostealer malware to log into accounts that had no MFA enabled.

This case shows cloud risk often starts on the endpoint, not the platform. Enterprises running SaaS and cloud data platforms should treat credential exposure on managed devices as a direct line into cloud data, not a separate concern.

Unify device security and management with Hexnode

What the guilty plea confirms

Moucka, 26, of Kitchener, Ontario, was arrested on October 30, 2024, months after the intrusions began in February 2024. He was extradited from Canada in July 2025 and pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy count.

A co-conspirator, John Erin Binns, was also indicted in connection with the same campaign. Binns resided in Turkey during the attacks and was arrested there. A local court approved his extradition, though the ruling was contested. The FBI investigated the case as part of Operation Riptide, its campaign against cybercrime, cyber-enabled crime, and fraud targeting Americans.

How attackers got in without breaching Snowflake’s platform

Attackers didn’t need to break Snowflake’s platform. Court documents cited by BleepingComputer show a simple sequence:

  • Credential source: Login credentials came from infostealer malware, not a flaw in Snowflake’s infrastructure.
  • Missing control: Targeted accounts had no MFA enrolled, so a correct username and password alone granted access.
  • Reconnaissance: Once inside, attackers ran custom software to identify valuable information in each tenant environment, including organization names, user roles, and IP addresses.

This is a credential-access story, not a software-vulnerability story. It shows why identity security and endpoint hygiene sit upstream of cloud data protection.

Snowflake data theft: From access to extortion

The group downloaded terabytes of data, including call and text history records, banking information, payroll records, DEA registration numbers, driver’s license and passport numbers, and Social Security numbers, then threatened victims with public disclosure.

Beyond the reported $2.5 million in ransom payments, Moucka re-extorted one victim using data tied to a government officer and a former officer’s immediate family. The group also sold records on BreachForums, Exploit.in, XSS.is, and Telegram, netting Moucka $495,000 personally. That customer toll reached at least 100 million individuals, per the DOJ.

Attack stage What happened Operational risk
Initial Access Infostealer-sourced credentials used against accounts without MFA Password-only login lets stolen credentials bypass authentication entirely
Internal Reconnaissance Custom tooling identified organization names, user roles, and IP addresses inside each tenant Custom tooling helps attackers prioritize high-value data instead of searching manually
Exfiltration and Extortion Terabytes of PII downloaded and used for extortion or resale A credential breach converts directly into financial and legal exposure

Snowflake’s post-breach authentication changes

Snowflake tightened authentication after the breaches came to light:

  • MFA by default: New accounts require human users to enroll in MFA starting October 2024.
  • Stronger passwords: Minimum password length rose to 14 characters for all new and changed passwords.
  • Password-only login retiring: Final enforcement runs between August and October 2026, eliminating password-only sign-in entirely.

These changes close the MFA gap the Moucka case exploited. They don’t address how credentials were stolen, since infostealer malware operates at the endpoint, outside Snowflake’s platform boundary.

Closing the identity gap: Where Hexnode fits

Infostealer malware runs on an endpoint long before stolen credentials ever reach a cloud platform. Hexnode addresses that earlier stage:

  • Endpoint hardening: Hexnode UEM enforces device compliance, application controls, and patch posture across Windows, macOS, Linux, and mobile endpoints, shrinking the exposure surface infostealer droppers rely on.
  • Endpoint investigation: Hexnode XDR investigates suspicious activity on managed endpoints, primarily Windows, giving admins visibility into potential post-compromise behavior.
  • Conditional access: For Microsoft Entra ID conditional access, Hexnode reports device compliance data for Android, iOS, and macOS (gating cloud access behind device health), while Windows compliance can be governed directly via integrated policies.

Hexnode doesn’t detect activity within Snowflake or any SaaS application, and it doesn’t ingest identity provider telemetry beyond the documented integrations. It complements vendor-side MFA enforcement and cloud audit logging, not replaces them.

introduction to hexnode xdr
Featured resource

Introduction to Hexnode XDR

Hexnode XDR unifies endpoint detection, UEM integration, and automated remediation for faster enterprise-wide threat response.

DOWNLOAD

FAQs

No. No CVE or platform flaw has been identified in connection with this case; only stolen credentials were used against accounts without MFA.

Rotate affected passwords and API tokens, enforce MFA across all cloud accounts, and review endpoint logs for signs of credential-stealing malware.

On some existing accounts, yes, but only during the current transition. Snowflake is actively enforcing mandatory MFA across remaining legacy accounts, with full retirement of password-only sign-ins concluding by October 2026.

Conclusion

The Snowflake data theft case shows how far a single set of stolen credentials can travel when MFA is absent. What began as infostealer activity on an endpoint culminated in a breach affecting 165 organizations, extortion attempts, and losses exceeding $9.5 million.

The practical response is straightforward: close MFA gaps across every SaaS platform, tighten credential hygiene at the endpoint, and route device compliance into access decisions wherever possible. Investigation and exposure management matter as much as the initial fix.

Share

Sophia Hart

A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions—without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable—politely.