One compromised Snowflake access path let attackers fan out across unrelated customers. The standard one-breach, one-victim model breaks here, because the shared platform became the blast radius.
Connor Moucka pleaded guilty over the 2024 Snowflake breach spree that hit more than 165 customer environments and stole billions of records. Prosecutors say the group used stolen credentials, pulled data from companies including AT&T, Ticketmaster, Advance Auto Parts, and Santander, and collected about $2.5 million in extortion payments.
The case closes one chapter, but the risk pattern stays the same: if a shared data platform trusts a stolen login, a single compromise can expose many tenants at once and give extortionists repeat leverage from the same stolen data.