Snowflake Plea Locks In Identity-Layer Blast Radius
The breach was a login problem, not a software break. Once stolen customer credentials worked on Snowflake accounts without MFA, the attackers could act like legitimate users, reach cloud-hosted data, and extort the owners of those accounts; patching the platform would not change that the data had already been copied out.
Connor Riley Moucka pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and conspiracy over a campaign that hit at least 165 organizations and drew more than $2.5 million in ransom payments. Court filings now tie the case to UNC5537 and say the stolen data affected more than 100 million people across targets including AT&T, Ticketmaster, Advance Auto Parts, Santander, Neiman Marcus, and others. The plea is a legal milestone, not a recovery point for the exposed records.
Hacker pleads guilty to stealing data from more than 165 Snowflake customers | TechCrunch
Connor Moucka pled guilty to hacking and stealing data from more than 165 Snowflake customers, which net him and his accomplices more than $2.5 million in ransom payments.
Canadian Man Pleads Guilty in Snowflake Extortions
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud provider Snowflake.