Snowflake Plea Locks In Identity-Layer Blast Radius

The breach was a login problem, not a software break. Once stolen customer credentials worked on Snowflake accounts without MFA, the attackers could act like legitimate users, reach cloud-hosted data, and extort the owners of those accounts; patching the platform would not change that the data had already been copied out. Connor Riley Moucka pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and conspiracy over a campaign that hit at least 165 organizations and drew more than $2.5 million in ransom payments. Court filings now tie the case to UNC5537 and say the stolen data affected more than 100 million people across targets including AT&T, Ticketmaster, Advance Auto Parts, Santander, Neiman Marcus, and others. The plea is a legal milestone, not a recovery point for the exposed records.

Part of the PlainSec briefing for 2026-08-07

Every edition of this story: Snowflake Plea Locks In Identity-Layer Blast Radius

Sources