


Perceptive Security
SOC/SIEM Consultancy

Canadian pleads guilty to Snowflake cloud data-theft attacks
Published:
5 augustus 2026 om 21:53:26
Alert date:
5 augustus 2026 om 22:02:16
Source:
bleepingcomputer.com
Cloud & Virtualization, Data Breach & Exfiltration, Identity & Access, Database & Storage
A Canadian man pleaded guilty to accessing cloud storage provider Snowflake's customer accounts and stealing data from at least 165 organizations. The scheme involved extorting millions of dollars from victim companies. The attacker gained unauthorized access to company accounts hosted on Snowflake's cloud platform. This case represents one of the largest cloud data theft and extortion campaigns in recent history. The guilty plea marks a significant legal milestone in prosecuting cloud-based cybercrime. The breach affected a wide range of organizations across multiple industries. Snowflake is a widely used cloud data warehousing and storage platform. The case highlights risks associated with credential-based attacks on cloud services.
Technical details
Between February and October 2024, threat actors Connor Riley Moucka (aka Alexander Moucka, Waifu) and John Erin Binns exploited Snowflake customer accounts that lacked multi-factor authentication (MFA) protection. Credentials used to access these accounts were obtained via infostealer malware. Once inside, the attackers used custom-developed software to enumerate and identify valuable data within cloud storage instances, including organization names, user roles, and IP addresses. The attackers exfiltrated terabytes of data from at least 165 organizations, stealing sensitive PII including call/text history records, banking and financial information, payroll records, DEA registration numbers, driver's license numbers, passport numbers, and Social Security numbers. Stolen data was advertised and sold on hacker forums for fiat currency and cryptocurrency. Victims were extorted with threats of data disclosure; at least one victim was re-extorted using data belonging to a government officer and their family members. The attackers obtained at least $2.5 million in bitcoin from at least three extorted victims, and an additional $495,000 from selling data on forums. Total victim losses exceeded $9.5 million, with more than 100 million individuals affected. Moucka was arrested on October 30, 2024, and pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and related conspiracy charges, facing a maximum sentence of 32 years.
Mitigation steps:
1. Enable multi-factor authentication (MFA) on all Snowflake accounts immediately — Snowflake has since announced enforcement of MFA for all accounts. 2. Enforce strong password policies; Snowflake now requires passwords to be at least 14 characters long. 3. Audit Snowflake account access logs for unauthorized logins, unusual IP addresses, and unexpected data enumeration or export activity. 4. Deploy infostealer malware defenses including endpoint detection and response (EDR) tools to prevent credential theft at the endpoint level. 5. Monitor dark web and hacker forums for stolen organizational credentials. 6. Rotate all Snowflake credentials, especially if employees may have been affected by infostealer malware. 7. Restrict access to Snowflake environments using IP allowlisting and least-privilege role assignments. 8. Implement network monitoring to detect large-scale data exfiltration from cloud storage environments.
Affected products:
Snowflake Cloud Storage Platform (customer accounts without MFA enabled)
Related links:
https://www.bleepingcomputer.com/news/security/suspect-behind-snowflake-data-theft-attacks-arrested-in-canada/
https://www.documentcloud.org/documents/25290989-snowflake-indc/
https://www.bleepingcomputer.com/news/security/us-indicts-snowflake-hackers-who-extorted-25-million-from-3-victims/
https://www.justice.gov/opa/pr/canadian-man-pleads-guilty-hacking-us-cloud-storage-provider-and-extorting-its-customers
https://www.bleepingcomputer.com/news/security/massive-atandt-data-breach-exposes-call-logs-of-109-million-customers/
https://www.bleepingcomputer.com/news/security/data-of-560-million-ticketmaster-customers-for-sale-after-alleged-breach/
https://www.bleepingcomputer.com/news/security/shinyhunters-claims-santander-breach-selling-data-for-30m-customers/
https://www.bleepingcomputer.com/news/security/pure-storage-confirms-data-breach-after-snowflake-account-hack/
https://www.bleepingcomputer.com/news/security/advance-auto-parts-confirms-data-breach-exposed-employee-information/
https://www.bleepingcomputer.com/news/security/los-angeles-unified-confirms-student-data-stolen-in-snowflake-account-hack/
https://techcrunch.com/2024/06/07/snowflake-ticketmaster-lendingtree-customer-data-breach/
https://www.bleepingcomputer.com/news/security/neiman-marcus-confirms-data-breach-after-snowflake-account-hack/
https://www.snowflake.com/en/blog/multi-factor-identification-default/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
