Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Snowflake Breach Mastermind Admits Guilt in Mega Hack

Snowflake Breach Mastermind Admits Guilt in Mega Hack

Posted on August 6, 2026 By CWS

Connor Riley Moucka, a 26-year-old from Kitchener, Ontario, entered a guilty plea in a Seattle federal court on Wednesday. The charges against him include computer fraud, wire fraud, aggravated identity theft, and conspiracy. These charges stem from his involvement in the 2024 breaches of customer accounts belonging to the U.S. software-as-a-service provider Snowflake.

The breaches affected at least 165 organizations and compromised data of over 100 million individuals. Moucka reportedly gained at least $495,000 through ransoms and data sales. His sentencing is scheduled for October 27, where he faces a mandatory minimum of two years for identity theft and up to 30 years for the other charges.

Details of the Cyber Intrusion

The cyber attackers exploited old credentials that had been collected by infostealer malware and never updated. Additionally, the compromised accounts had multi-factor authentication (MFA) turned off, allowing easy access despite the absence of any platform vulnerabilities. The Justice Department did not name the victim company in its announcements, but Snowflake and Mandiant identified themselves in 2024.

Beyond the initial breach, Moucka was involved in re-extorting at least one victim by threatening further data exposure. The FBI’s Seattle field office special agent, W. Mike Herrington, described these actions as “calculated and predatory.”

Investigation Insights

The cybersecurity firm Mandiant, in collaboration with Snowflake, discovered that all incidents involved customer credentials previously stolen by infostealer malware. These credentials, some dating back to November 2020, were still active. A significant 79.7% of the compromised accounts had a history of credential exposure, and the affected systems lacked network allow lists.

Mandiant emphasizes that these breaches did not involve any new or sophisticated cyber tools or techniques. Instead, the widespread impact was attributed to the neglected rotation of credentials and the vast infostealer market.

Impact and Future Measures

The breaches resulted in more than $9.5 million in losses for the affected companies, excluding their customers’ losses. Compromised data included sensitive information such as call and text history, payroll records, DEA numbers, and Social Security numbers. AT&T confirmed in 2024 that call and text records for nearly all its cellular customers were accessed via a third-party cloud platform.

Following the breaches, Snowflake has implemented MFA by default for all new human user accounts since October 2024. However, password-only logins have not been entirely phased out. The final phase of eliminating password-only access is planned between August and October 2026, with exceptions for reader and trial accounts.

While Moucka is in U.S. custody, his accomplices, including John Erin Binns, remain at large. Another individual, Cameron John Wagenius, pleaded guilty in a related case in July 2025. These developments underscore the ongoing challenges in cybersecurity and the importance of robust authentication measures.

The Hacker News Tags:Connor Moucka, Cybercrime, data breach, FBI, identity theft, infostealer malware, Mandiant, MFA, SaaS, Snowflake

Post navigation

Previous Post: Phishing-as-a-Service Kits Bypass MFA for M365 Breaches
Next Post: JetBrains TeamCity Vulnerability Exploited by Hackers

Related Posts

WhatsApp Warns 200 Users of Fake iOS App Spyware WhatsApp Warns 200 Users of Fake iOS App Spyware The Hacker News
GitHub OAuth Tokens Vulnerable to One-Click Attack GitHub OAuth Tokens Vulnerable to One-Click Attack The Hacker News
Mitigating Onboarding Risks: Secure Password Practices Mitigating Onboarding Risks: Secure Password Practices The Hacker News
Hackers Exploit Adform Script to Alter Crypto Wallets Hackers Exploit Adform Script to Alter Crypto Wallets The Hacker News
How Ineffective Triage Heightens Business Risks How Ineffective Triage Heightens Business Risks The Hacker News
ClickFix Attacks Expand Using Fake CAPTCHAs, Microsoft Scripts, and Trusted Web Services ClickFix Attacks Expand Using Fake CAPTCHAs, Microsoft Scripts, and Trusted Web Services The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cisco Urges Immediate Update for Critical IOS XE Vulnerabilities
  • Meta AI’s Uncontrolled Cybersecurity Test Breach
  • Security Flaws in AWS, Google, and Vercel Exposed
  • Meta’s AI Breach: Internet Access and System Exploitation
  • Belarusian Ransomware Leader Sentenced to 16 Years

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cisco Urges Immediate Update for Critical IOS XE Vulnerabilities
  • Meta AI’s Uncontrolled Cybersecurity Test Breach
  • Security Flaws in AWS, Google, and Vercel Exposed
  • Meta’s AI Breach: Internet Access and System Exploitation
  • Belarusian Ransomware Leader Sentenced to 16 Years

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark