# Snowflake Breach: Hacker Admits to Compromising 165 Accounts

*Published August 7, 2026*
*Source: [https://thehackernews.com/2026/08/snowflake-hacker-pleads-guilty-over.html](https://thehackernews.com/2026/08/snowflake-hacker-pleads-guilty-over.html)*

## Executive Summary

Connor Riley Moucka has pleaded guilty to charges related to the 2024 breach of 165 Snowflake customer accounts, impacting over 100 million people. The breach exploited outdated passwords and lacked multi-factor authentication, leading to significant financial and data losses.

## Article

In a significant development in the cybersecurity domain, Connor Riley Moucka, a 26-year-old from Kitchener, Ontario, has admitted guilt in a Seattle federal court to multiple charges including computer fraud, wire fraud, and aggravated identity theft. The charges stem from a 2024 breach that involved unauthorized access to 165 accounts of Snowflake customers, affecting over 100 million individuals. Moucka allegedly profited at least $495,000 from ransoms and data sales. His sentencing is scheduled for October 27, where he could face up to 30 years in prison for the charges, with a mandatory minimum of two years for identity theft.

The breach was facilitated by old passwords that had been compromised by infostealer malware years prior and not changed since. These accounts also lacked multi-factor authentication (MFA), making them vulnerable targets. Interestingly, no vulnerabilities or flaws in the Snowflake platform were exploited during the breach. The Justice Department has not publicly named the compromised company, though Snowflake and Mandiant, the security firm involved in the investigation, have identified Snowflake as the affected platform.

Moucka's tactics were described as calculated and predatory by FBI special agent W. Mike Herrington. In some cases, Moucka re-extorted victims by threatening further data exposure. Mandiant's investigation, which tracks Moucka as UNC5537, found that the breaches could be traced back to infostealer-harvested credentials, some dating back to November 2020. Over 79 percent of the compromised accounts had prior credential exposure, with no network allow lists in place.

The financial impact of these breaches is substantial, with victim companies incurring over $9.5 million in losses, excluding additional losses to their own customers. Sensitive data exposed included call and text histories, payroll records, and government-issued identification numbers. AT&T disclosed in July 2024 that call and text records for nearly all its cellular customers were compromised during this breach.

In response to these incidents, Snowflake has implemented MFA by default for new accounts since October 2024. However, the complete phase-out of password-only sign-ins is scheduled for completion between August and October 2026. This measure aims to strengthen security by eliminating passwords as the sole authentication factor for all users, except reader and trial accounts.
