{"id":904,"date":"2026-08-06T11:40:47","date_gmt":"2026-08-06T06:10:47","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=904"},"modified":"2026-08-19T11:41:05","modified_gmt":"2026-08-19T06:11:05","slug":"snowflake-data-theft-case-guilty-plea-exposes-mfa-gaps","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/snowflake-data-theft-case-guilty-plea-exposes-mfa-gaps\/","title":{"rendered":"Snowflake Data Theft Case: Guilty Plea Exposes MFA Gaps"},"content":{"rendered":"<p>A federal guilty plea has confirmed the mechanics behind the Snowflake data theft campaign. On August 5, 2026, Connor Riley Moucka pleaded guilty to a hacking conspiracy that compromised more than <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/canadian-pleads-guilty-to-snowflake-cloud-data-theft-attacks\/?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=snowflake_data_theft\" target=\"_blank\" rel=\"noopener\">165 organizations<\/a>. The U.S. Department of Justice said the operation stole billions of sensitive records.<\/p>\n<p>The plea points to no flaw in Snowflake&#8217;s platform. Court documents show attackers used credentials stolen by infostealer malware to log into accounts that had no <a href=\"https:\/\/www.hexnode.com\/blogs\/reinforcing-cybersecurity-with-multi-factor-authentication-mfa\/\">MFA<\/a> enabled.<\/p>\n<p>This case shows cloud risk often starts on the endpoint, not the platform. Enterprises running SaaS and cloud data platforms should treat credential exposure on managed devices as a direct line into cloud data, not a separate concern.<\/p>\n<p><center>    \t\t<!-- button style scb20be917a3efc78059cf9961ee4e54284 -->\r\n    \t\t<style>\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284, a.scb20be917a3efc78059cf9961ee4e54284{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: #00868B;\r\n    \t\t\t}\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284:hover, a.scb20be917a3efc78059cf9961ee4e54284:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #32b8bd;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/\" class=\"ht-shortcodes-button scb20be917a3efc78059cf9961ee4e54284  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tUnify device security and management with Hexnode<\/a>\r\n    \t\t<\/center><\/p>\n<h2>What the guilty plea confirms<\/h2>\n<p>Moucka, 26, of Kitchener, Ontario, was arrested on October 30, 2024, months after the intrusions began in February 2024. He was extradited from Canada in July 2025 and pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy count.<\/p>\n<p>A co-conspirator, John Erin Binns, was also indicted in connection with the same campaign. Binns resided in Turkey during the attacks and was arrested there. A local court approved his extradition, though the ruling was contested. The FBI investigated the case as part of Operation Riptide, its campaign against <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-a-cybercrime-in-cyber-security\/\">cybercrime<\/a>, cyber-enabled crime, and fraud targeting Americans.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/threat-classification.jpeg?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>What is Threat Classification?<\/h4><p>Threat classification explained: severity, dimensions, and how Hexnode aids investigation.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/what-is-threat-classification\/\" aria-label=\"What is Threat Classification?\"><\/a><\/div><\/div><\/div>\n<h2>How attackers got in without breaching Snowflake&#8217;s platform<\/h2>\n<p>Attackers didn&#8217;t need to break Snowflake&#8217;s platform. Court documents cited by BleepingComputer show a simple sequence:<\/p>\n<ul>\n<li><strong>Credential source:<\/strong> Login credentials came from infostealer malware, not a flaw in Snowflake&#8217;s infrastructure.<\/li>\n<li><strong>Missing control:<\/strong> Targeted accounts had no MFA enrolled, so a correct username and password alone granted access.<\/li>\n<li><strong>Reconnaissance:<\/strong> Once inside, attackers ran custom software to identify valuable information in each tenant environment, including organization names, user roles, and IP addresses.<\/li>\n<\/ul>\n<p>This is a credential-access story, not a software-<a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-vulnerability-in-cybersecurity\/\">vulnerability<\/a> story. It shows why identity security and endpoint hygiene sit upstream of cloud data protection.<\/p>\n<h2>Snowflake data theft: From access to extortion<\/h2>\n<p>The group downloaded terabytes of data, including call and text history records, banking information, payroll records, DEA registration numbers, driver&#8217;s license and passport numbers, and Social Security numbers, then threatened victims with public disclosure.<\/p>\n<p>Beyond the reported $2.5 million in ransom payments, Moucka re-extorted one victim using data tied to a government officer and a former officer&#8217;s immediate family. The group also sold records on BreachForums, Exploit.in, XSS.is, and Telegram, netting Moucka $495,000 personally. That customer toll reached at least 100 million individuals, per the DOJ.<\/p>\n<table style=\"width: 100%;\">\n<thead>\n<tr>\n<th style=\"width: 23.9958%; text-align: left;\">Attack stage<\/th>\n<th style=\"width: 36.7865%; text-align: left;\">What happened<\/th>\n<th style=\"width: 38.1606%; text-align: left;\">Operational risk<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"width: 23.9958%;\">Initial Access<\/td>\n<td style=\"width: 36.7865%;\">Infostealer-sourced credentials used against accounts without MFA<\/td>\n<td style=\"width: 38.1606%;\">Password-only login lets stolen credentials bypass authentication entirely<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 23.9958%;\">Internal Reconnaissance<\/td>\n<td style=\"width: 36.7865%;\">Custom tooling identified organization names, user roles, and IP addresses inside each tenant<\/td>\n<td style=\"width: 38.1606%;\">Custom tooling helps attackers prioritize high-value data instead of searching manually<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 23.9958%;\">Exfiltration and Extortion<\/td>\n<td style=\"width: 36.7865%;\">Terabytes of PII downloaded and used for extortion or resale<\/td>\n<td style=\"width: 38.1606%;\">A credential breach converts directly into financial and legal exposure<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Snowflake&#8217;s post-breach authentication changes<\/h2>\n<p>Snowflake tightened authentication after the breaches came to light:<\/p>\n<ul>\n<li><strong>MFA by default:<\/strong> New accounts require human users to enroll in MFA starting October 2024.<\/li>\n<li><strong>Stronger passwords:<\/strong> Minimum password length rose to 14 characters for all new and changed passwords.<\/li>\n<li><strong>Password-only login retiring:<\/strong> Final enforcement runs between August and October 2026, eliminating password-only sign-in entirely.<\/li>\n<\/ul>\n<p>These changes close the MFA gap the Moucka case exploited. They don&#8217;t address how credentials were stolen, since infostealer malware operates at the endpoint, outside Snowflake&#8217;s platform boundary.<\/p>\n<h2>Closing the identity gap: Where Hexnode fits<\/h2>\n<p><a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-info-stealer\/\">Infostealer<\/a> malware runs on an endpoint long before stolen credentials ever reach a cloud platform. Hexnode addresses that earlier stage:<\/p>\n<ul>\n<li><strong>Endpoint hardening:<\/strong> <a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> enforces device compliance, application controls, and patch posture across Windows, macOS, Linux, and mobile endpoints, shrinking the exposure surface infostealer droppers rely on.<\/li>\n<li><strong>Endpoint investigation:<\/strong> <a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> investigates suspicious activity on managed endpoints, primarily Windows, giving admins visibility into potential post-compromise behavior.<\/li>\n<li><strong>Conditional access:<\/strong> For Microsoft Entra ID conditional access, Hexnode reports device compliance data for Android, iOS, and macOS (gating cloud access behind device health), while Windows compliance can be governed directly via integrated policies.<\/li>\n<\/ul>\n<p>Hexnode doesn&#8217;t detect activity within Snowflake or any SaaS application, and it doesn&#8217;t ingest identity provider telemetry beyond the documented integrations. It complements vendor-side MFA enforcement and cloud audit logging, not replaces them.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/introduction-to-hexnode-xdr-300x168-1.webp?format=webp\" class=\"resource-box__image\" alt=\"introduction-to-hexnode-xdr-300x168\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/introduction-to-hexnode-xdr-300x168-1.webp?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/introduction-to-hexnode-xdr-300x168-1-179x100.webp?format=webp 179w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" title=\"introduction-to-hexnode-xdr-300x168\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Introduction to Hexnode XDR\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Hexnode XDR unifies endpoint detection, UEM integration, and automated remediation for faster enterprise-wide threat response.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/introduction-to-hexnode-xdr\/'>\n                            DOWNLOAD\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Did the attackers exploit a vulnerability in Snowflake&#8217;s platform?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>No. No CVE or platform flaw has been identified in connection with this case; only stolen credentials were used against accounts without MFA.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What should organizations do if they suspect infostealer exposure?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Rotate affected passwords and API tokens, enforce MFA across all cloud accounts, and review endpoint logs for signs of credential-stealing malware.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Is Snowflake still allowing password-only logins?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>On some existing accounts, yes, but only during the current transition. Snowflake is actively enforcing mandatory MFA across remaining legacy accounts, with full retirement of password-only sign-ins concluding by October 2026.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n<h3>Conclusion<\/h3>\n<p>The Snowflake data theft case shows how far a single set of stolen credentials can travel when MFA is absent. What began as infostealer activity on an endpoint culminated in a breach affecting 165 organizations, extortion attempts, and losses exceeding $9.5 million.<\/p>\n<p>The practical response is straightforward: close MFA gaps across every SaaS platform, tighten credential hygiene at the endpoint, and route device compliance into access decisions wherever possible. Investigation and exposure management matter as much as the initial fix.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Stop stolen credentials at the endpoint <\/h5><p>See how device compliance and endpoint visibility reduce cloud account risk.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> SIGN UP NOW<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>A federal guilty plea has confirmed the mechanics behind the Snowflake data theft campaign. On&#8230;<\/p>\n","protected":false},"author":5,"featured_media":907,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[13,19],"class_list":["post-904","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-identity-abuse","category-cloud-and-saas","product_category-identity-provider","tab_group-identity-and-phishing"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Snowflake Data Theft: Guilty Plea Exposes MFA Gaps<\/title>\n<meta name=\"description\" content=\"A guilty plea in the Snowflake data theft case shows how infostealer credentials and missing MFA enabled a large-scale cloud data breach.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/snowflake-data-theft-case-guilty-plea-exposes-mfa-gaps\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Snowflake Data Theft: Guilty Plea Exposes MFA Gaps\" \/>\n<meta property=\"og:description\" content=\"A guilty plea in the Snowflake data theft case shows how infostealer credentials and missing MFA enabled a large-scale cloud data breach.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/snowflake-data-theft-case-guilty-plea-exposes-mfa-gaps\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-06T06:10:47+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-19T06:11:05+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/snowflake-data-theft.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sophia Hart\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sophia Hart\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/snowflake-data-theft-case-guilty-plea-exposes-mfa-gaps\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/snowflake-data-theft-case-guilty-plea-exposes-mfa-gaps\\\/\"},\"author\":{\"name\":\"Sophia Hart\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\"},\"headline\":\"Snowflake Data Theft Case: Guilty Plea Exposes MFA Gaps\",\"datePublished\":\"2026-08-06T06:10:47+00:00\",\"dateModified\":\"2026-08-19T06:11:05+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/snowflake-data-theft-case-guilty-plea-exposes-mfa-gaps\\\/\"},\"wordCount\":970,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/snowflake-data-theft-case-guilty-plea-exposes-mfa-gaps\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/snowflake-data-theft.jpeg?format=webp\",\"articleSection\":[\"Identity Abuse\",\"Cloud and SaaS\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/snowflake-data-theft-case-guilty-plea-exposes-mfa-gaps\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/snowflake-data-theft-case-guilty-plea-exposes-mfa-gaps\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/snowflake-data-theft-case-guilty-plea-exposes-mfa-gaps\\\/\",\"name\":\"Snowflake Data Theft: Guilty Plea Exposes MFA Gaps\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/snowflake-data-theft-case-guilty-plea-exposes-mfa-gaps\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/snowflake-data-theft-case-guilty-plea-exposes-mfa-gaps\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/snowflake-data-theft.jpeg?format=webp\",\"datePublished\":\"2026-08-06T06:10:47+00:00\",\"dateModified\":\"2026-08-19T06:11:05+00:00\",\"description\":\"A guilty plea in the Snowflake data theft case shows how infostealer credentials and missing MFA enabled a large-scale cloud data breach.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/snowflake-data-theft-case-guilty-plea-exposes-mfa-gaps\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/snowflake-data-theft-case-guilty-plea-exposes-mfa-gaps\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/snowflake-data-theft-case-guilty-plea-exposes-mfa-gaps\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/snowflake-data-theft.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/snowflake-data-theft.jpeg?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"snowflake data theft\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/snowflake-data-theft-case-guilty-plea-exposes-mfa-gaps\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Snowflake Data Theft Case: Guilty Plea Exposes MFA Gaps\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\",\"name\":\"Sophia Hart\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"caption\":\"Sophia Hart\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/sophia-hart\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Snowflake Data Theft: Guilty Plea Exposes MFA Gaps","description":"A guilty plea in the Snowflake data theft case shows how infostealer credentials and missing MFA enabled a large-scale cloud data breach.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/snowflake-data-theft-case-guilty-plea-exposes-mfa-gaps\/","og_locale":"en_US","og_type":"article","og_title":"Snowflake Data Theft: Guilty Plea Exposes MFA Gaps","og_description":"A guilty plea in the Snowflake data theft case shows how infostealer credentials and missing MFA enabled a large-scale cloud data breach.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/snowflake-data-theft-case-guilty-plea-exposes-mfa-gaps\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-08-06T06:10:47+00:00","article_modified_time":"2026-08-19T06:11:05+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/snowflake-data-theft.jpeg?format=webp","type":"image\/jpeg"}],"author":"Sophia Hart","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Sophia Hart","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/snowflake-data-theft-case-guilty-plea-exposes-mfa-gaps\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/snowflake-data-theft-case-guilty-plea-exposes-mfa-gaps\/"},"author":{"name":"Sophia Hart","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430"},"headline":"Snowflake Data Theft Case: Guilty Plea Exposes MFA Gaps","datePublished":"2026-08-06T06:10:47+00:00","dateModified":"2026-08-19T06:11:05+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/snowflake-data-theft-case-guilty-plea-exposes-mfa-gaps\/"},"wordCount":970,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/snowflake-data-theft-case-guilty-plea-exposes-mfa-gaps\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/snowflake-data-theft.jpeg?format=webp","articleSection":["Identity Abuse","Cloud and SaaS"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/snowflake-data-theft-case-guilty-plea-exposes-mfa-gaps\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/snowflake-data-theft-case-guilty-plea-exposes-mfa-gaps\/","url":"https:\/\/www.hexnode.com\/threat-watch\/snowflake-data-theft-case-guilty-plea-exposes-mfa-gaps\/","name":"Snowflake Data Theft: Guilty Plea Exposes MFA Gaps","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/snowflake-data-theft-case-guilty-plea-exposes-mfa-gaps\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/snowflake-data-theft-case-guilty-plea-exposes-mfa-gaps\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/snowflake-data-theft.jpeg?format=webp","datePublished":"2026-08-06T06:10:47+00:00","dateModified":"2026-08-19T06:11:05+00:00","description":"A guilty plea in the Snowflake data theft case shows how infostealer credentials and missing MFA enabled a large-scale cloud data breach.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/snowflake-data-theft-case-guilty-plea-exposes-mfa-gaps\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/snowflake-data-theft-case-guilty-plea-exposes-mfa-gaps\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/snowflake-data-theft-case-guilty-plea-exposes-mfa-gaps\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/snowflake-data-theft.jpeg?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/snowflake-data-theft.jpeg?format=webp","width":1340,"height":700,"caption":"snowflake data theft"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/snowflake-data-theft-case-guilty-plea-exposes-mfa-gaps\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Snowflake Data Theft Case: Guilty Plea Exposes MFA Gaps"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430","name":"Sophia Hart","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","caption":"Sophia Hart"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/sophia-hart\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/904","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=904"}],"version-history":[{"count":1,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/904\/revisions"}],"predecessor-version":[{"id":908,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/904\/revisions\/908"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/907"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=904"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=904"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}