By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Snowflake Hacker Pleads Guilty to 2024 Data Breaches

Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to charges including computer fraud, wire fraud, aggravated identity theft, and conspiracy, stemming from the 2024 breaches of Snowflake customer accounts. These intrusions impacted at least 165 organizations and compromised the data of a minimum of 100 million individuals. Moucka, a 26-year-old resident of Kitchener, Ontario, personally obtained at least $495,000 through these illicit activities. The plea agreement details Moucka's involvement in exploiting vulnerabilities within Snowflake's cloud data platform to access sensitive customer information. The breaches, which came to light in late April and May 2024, prompted widespread concern among businesses and consumers regarding the security of their data stored on the platform. Snowflake, a cloud-based data warehousing company, offers services that allow organizations to store, process, and analyze vast amounts of data. The company itself was not directly breached, but rather, attackers exploited compromised customer credentials to gain unauthorized access to customer accounts hosted on Snowflake's infrastructure. This distinction is crucial as it highlights the shared responsibility in cloud security, where both the provider and the customer must implement robust security measures. The investigation into these breaches involved multiple law enforcement agencies, including the Federal Bureau of Investigation (FBI), which worked to identify and apprehend those responsible. Moucka's guilty plea marks a significant development in the ongoing efforts to hold perpetrators accountable for large-scale cybercrimes. The financial gains reported by Moucka, exceeding $495,000, underscore the lucrative nature of such attacks. The legal proceedings are expected to continue as authorities assess the full scope of the damage and identify any potential accomplices. The incident has intensified scrutiny on cloud security practices and the effectiveness of credential management protocols for businesses relying on third-party data storage solutions. Experts have long warned about the risks associated with weak password policies and the inadequate use of multi-factor authentication, which can leave systems vulnerable to credential stuffing attacks and other forms of unauthorized access. The Snowflake breaches serve as a stark reminder of these ongoing threats and the critical need for continuous vigilance in the cybersecurity landscape. The legal ramifications for Moucka are substantial, with potential prison sentences and significant financial penalties associated with the charges he has admitted to. The case also brings to the forefront the challenges faced by law enforcement in prosecuting cybercriminals who operate across international borders, as indicated by Moucka's Canadian residency. The ongoing investigation aims to uncover the full extent of the network of individuals involved in these sophisticated attacks and to recover any stolen data or funds.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.